ctags — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited ctags (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use Universal ctags to build a symbol index when LSP is not available.
# Universal ctags has --output-format=json — we need this
ctags --version 2>&1 | grep -i universal
# If not universal ctags, basic ctags won't have JSON output
# Fall back to parsing classic ctags format insteaduniversal-ctags \
--recurse=yes \
--output-format=json \
--fields=+n+e+K+S+Z \
--extras=+q+r \
--exclude=node_modules \
--exclude=.git \
--exclude=target \
--exclude=__pycache__ \
--exclude=.claude/codemunch \
--exclude=dist \
--exclude=build \
--exclude=vendor \
-f - \
. 2>/dev/nulln — line numbere — end lineK — kind (long form: "function", "class", etc.)S — signatureZ — scope (container class/module)ctags JSON output per line:
{"_type":"tag","name":"validateToken","path":"src/auth/tokens.ts","pattern":"/^async function validateToken/","kind":"function","line":142,"end":163,"signature":"(token: string): Promise<User | null>","scope":"AuthService","scopeKind":"class"}Filter noise kinds: Skip noise kinds: constant, property, variable, enumerator. These inflate the index 15x without adding useful navigation value. Only keep symbols where kind is one of: function, method, class, interface, type, enum, namespace.
Map each kept symbol to codemunch format:
{
"name": "validateToken",
"kind": "function",
"file": "src/auth/tokens.ts",
"start_line": 142,
"end_line": 163,
"signature": "(token: string): Promise<User | null>",
"container": "AuthService",
"engine": "ctags"
}If only basic/exuberant ctags is available (no JSON support):
ctags -R --fields=+iaS --extra=+q -f .claude/codemunch/tags .Parse the tab-separated .claude/codemunch/tags file:
# format: name TAB file TAB pattern TAB kind TAB extensions...
validateToken src/auth/tokens.ts /^async function validateToken/ f line:142End line is not available in classic ctags — use the rg-fallback skill's brace-counting heuristic.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.