bm-checkpoint — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited bm-checkpoint (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Create a durable handoff note for current Codex work. Use this when the user asks to checkpoint, wrap up, hand off, remember the state of the work, or before a long context transition.
Read .codex/basic-memory.json if present:
primaryProject, default omittedcaptureFolder, default codex-sessionsplacementConventions, optionalGather repo evidence:
git status --shortDo not claim a test passed unless you ran it or the user supplied the result.
Write a note to Basic Memory:
title: Codex checkpoint - <short topic>directory: configured captureFoldertags: ["codex", "checkpoint"]type: codex_sessionstatus: openproject: <primaryProject if known>cwd: <current cwd>capture: deliberateUse sections:
Observations should include at least one [next_step] line. Add relations to existing tasks, decisions, specs, issues, or PRs when the thread has obvious ones.
Reply with the permalink and the one next action the checkpoint preserves.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.