staleness-gate — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited staleness-gate (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Ensures the codemunch index is fresh before any query runs. This skill is called automatically — users never invoke it directly.
1. Does .claude/codemunch/index.json exist?
NO → First-run: run detect-lsp skill, then full index skill → done
YES → Continue to step 2
2. Get index timestamp from index.json "generated" field
3. Find files changed since index was built:
git diff --name-only --diff-filter=ACMRD $(git log -1 --format=%H --before="$GENERATED_TIMESTAMP") HEAD
Also check for untracked source files:
git ls-files --others --exclude-standard
4. Filter to source files only (exclude non-code files like .md, .txt, images, etc.)
5. Are there changed source files?
NO → Index is fresh, proceed with query
YES → Run incremental re-index (step 6)
6. Incremental re-index:
- For each changed/added file: re-extract symbols using the best available engine
- For each deleted file: remove its symbols from the index
- Update the "generated" timestamp
- Update the "file_hashes" manifest
- Report: "Auto-updated index: +N symbols, -M symbols, K files re-indexed"# Check for index
if [ -f .claude/codemunch/index.json ]; then
echo "INDEX_EXISTS"
else
echo "NO_INDEX"
fiIf NO_INDEX:
.claude/codemunch/config.json exists — if not, run the detect-lsp skill first# Extract the generated timestamp from index
python3 -c "
import json
with open('.claude/codemunch/index.json') as f:
idx = json.load(f)
print(idx.get('generated', ''))
" 2>/dev/null || jq -r '.generated' .claude/codemunch/index.jsonGENERATED="2026-03-11T02:14:00Z"
# Find the commit closest to when the index was built
BASE_COMMIT=$(git log -1 --format=%H --before="$GENERATED" 2>/dev/null)
if [ -z "$BASE_COMMIT" ]; then
# No commit found before timestamp — index predates all commits, do full re-index
echo "FULL_REINDEX_NEEDED"
else
# Get changed files since that commit
git diff --name-only --diff-filter=ACMRD "$BASE_COMMIT" HEAD 2>/dev/null
fi
# Also check untracked files (new files not yet committed)
git ls-files --others --exclude-standard 2>/dev/nullOnly consider files with these extensions (adjust per detected languages in config):
.ts .tsx .js .jsx .mjs .cjs
.py .pyi
.go
.rs
.rb .rake
.java .kt .kts
.cs
.php
.swift
.c .h .cpp .hpp .cc
.lua .zig .sh .bashExclude:
package-lock.json, Cargo.lock, go.sum, etc.).claude/codemunch/config.json exclude patterns).md, .txt, .json, .yaml, .yml, .toml, images, etc.)CHANGED_COUNT=$(echo "$CHANGED_FILES" | grep -c '.')
if [ "$CHANGED_COUNT" -eq 0 ]; then
echo "INDEX_FRESH"
else
echo "INDEX_STALE:$CHANGED_COUNT files changed"
fiIf fresh: proceed silently — no output to the user.
For each changed file, re-extract symbols using the same engine logic as the index skill:
generated timestamp, file_hashes, stats# Remove symbols for changed files
python3 -c "
import json, sys
changed_files = sys.stdin.read().strip().split('\n')
with open('.claude/codemunch/index.json') as f:
idx = json.load(f)
# Remove symbols from changed files
idx['symbols'] = [s for s in idx['symbols'] if s['file'] not in changed_files]
print(json.dumps(idx))
" <<< "$CHANGED_FILES"Then run the index skill's engine pipeline (LSP → ctags → rg) on only the changed files, and append the new symbols.
Report (brief, inline — not a full index report):
🔄 Auto-updated index: 3 files re-indexed, +12 symbols, -8 symbols (1,251 total)git diff + one JSON field read~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.