tour — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited tour (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
You are giving the user a guided tour of their Memory Kit. Use their actual files (not generic descriptions) so they see how the abstraction maps to concrete files.
Open and read aloud the first few lines. Say: "This is my brain. I read it on every session start. It says who I am for this project, how to talk to you."
Open context/next-session-prompt.md and, if multi-project mode, projects/<active>/BACKLOG.md. Say: "This is yesterday-me's note (NSP) and today's plan (backlog). It's the first thing I read so I know where we left off."
Open .claude/memory/MEMORY.md. Say: "This is my hot cache. Date-tagged one-liners of patterns from recent sessions. Updates often — sometimes mid-session when I notice something worth keeping."
List any .claude/rules/*.md files. If folder is empty (only _example.md.disabled), say: "This is where hard project rules live. 'Don't use X', 'always check Y'. They auto-load by keyword. Empty for now — they'll appear when you start dictating rules and I propose them on /close-day."
List knowledge/concepts/*.md. Say: "Deep memory with facts. 'What's our typography scale', 'what we know about SEO for AI'. Reference articles. Empty now — I write them during /close-day when enough daily observations stack up around a topic."
Show daily/. Say: "Chronological session logs. The agent writes these via /close-day — you don't open them. Just ask me 'what did we do last Tuesday?' and I read them back."
List projects/*/. Say: "Each client or initiative gets a folder. BACKLOG.md for tasks, drop in any PDF or md as reference. Say 'we're working on <name>' and I switch context to that one."
Mention .claude/hooks/ exists but don't deep-dive. Say: "Five safety hooks run silently. They make sure state survives — block compaction until saved, log session lifecycle, periodic state-save prompts."
List the two default operators: /close-day and /tour. Say: "Type either to invoke. /close-day is the most important — that's the daily audit ritual where I propose what should be remembered, and it also catches up any days you forgot to close. There are a few power-user commands (search, hygiene, usage stats) parked in .kit/advanced/ if you ever want them — but you don't need them to start."
Ask: "Anything you want to drill into deeper? Or should we start with a real task — name your first project?"
Target 10-15 minutes total. If user is engaged and asks questions, fine — go longer. If user seems impatient, compress to 5 minutes by collapsing stops 4-7 into one "and these are the on-trigger layers" sweep.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.