prime-sync — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited prime-sync (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Ultrathink.
Detect operating mode before anything else:
VERSION file exists in CWD → push mode (CWD is the prime repo).claude/.prime-version exists in CWD → pull mode (CWD is a target project)Source = CWD (prime repo). Target = resolved project path.
State file: .claude/prime-projects.json
Tracks known target paths, last sync time, and version. Shape:
{ "projects": [{ "path": "/absolute/path", "lastSynced": "2025-12-30T10:30:00Z", "version": "1.4.2" }] }Create as { "projects": [] } if missing.
Resolution flow:
State file management:
.claude/ only if you need to persist the state fileSource = cloned prime repo. Target = CWD.
Flow:
.claude/.prime-version in CWDdate +%Y%m%d%H%M%Sgit clone https://github.com/avibebuilder/claude-prime.git /tmp/claude-prime-sync-<timestamp>//tmp/claude-prime-sync-<timestamp>/, target = CWD/tmp/claude-prime-sync-<timestamp>/ after sync completes (success or failure)No state file in pull mode — the target project is self-contained.
.claude/ is appropriate.claude/.prime-version) and prime (VERSION)If the path fails those checks, abort and explain why.
Change Detection:
.claude/ based on the target's recorded version stateHEAD and include uncommitted changes; warn if the tag is missingStack Detection (only if skills or starter-skills changed): check target for stack indicators relevant to each changed skill/starter.
File Comparison: compare each changed file with target. Detect: NEW, UPDATE, IDENTICAL, CONFLICT.
Aggregate results and present:
CHANGED (will sync): ...
IDENTICAL (skip): ...
CONFLICTS (will ask): ...
IRRELEVANT (skip, wrong stack): ...GATE: User approves sync plan.
For each conflict, show the relevant diff and ask the user how to proceed:
.claude/ in target if needed.claude/starter-skills/ in target.prime-version with prime's VERSIONSync complete! (prime vX.X.X)
Updated: ...
Skipped: ...
Version: X.X.X → written to .prime-versionPush mode only: update state file (lastSynced timestamp + version). Pull mode only: clean up /tmp/claude-prime-sync-* clone directory.
<target-path>$ARGUMENTS</target-path>
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.