native-rive — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited native-rive (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Rive React Native/Nitro runtime, .riv assets, state machines, inputs, asset loading, platform compatibility, accessibility, and iOS/Android proof.
Use this skill as a compact router plus domain checklist. Load references only when the current task matches their condition. Do not cite local scrape paths, machine cache paths, or hidden source locations. Verify API details against the target repo's installed package versions before editing.
local design tokens, accessibility policy, and existing motion patterns.
excerpts.
bundled notes are version-sensitive.
<!-- skill-resources:start -->
references/rive-native-state-machines.md - Native Rive state-machine contract. Read when binding inputs, triggers, or state machine names.references/rive-native-asset-loading.md - Rive native asset loading and lifecycle. Read for .riv bundling, runtime setup, and cleanup.references/nitro-platform-validation.md - Nitro/platform validation notes. Read before closing native build/runtime changes.references/rive-file-caching-and-assets.md - Native Rive file caching and asset loading. Read when .riv files are bundled, cached, loaded remotely, reused across views, or include out-of-band assets.references/state-machine-input-protocol.md - Native Rive state-machine input protocol. Read when app state drives boolean, number, or trigger inputs in a native Rive state machine.references/docs-rive-react-native.md - Copied source excerpt. Load only when exact upstream wording or API detail is needed.references/docs-rive-state-machine.md - Copied source excerpt. Load only when exact upstream wording or API detail is needed.references/index.md - Complete reference inventory and routing summary.references/source-ledger.md - Source list, checked date, and copy policy.references/provenance.json - Machine-readable source and local-resource metadata.scripts/audit.mjs - Self-contained audit CLI; run doctor before scan when setup is unclear.assets/templates/native-rive-audit-report.md - Audit response/report template.assets/templates/native-rive-review-checklist.md - Manual review checklist.assets/examples/native-rive-starter.tsx - Starter fixture/example for this skill.evals/trigger-queries.json - Trigger/near-miss eval set for description tuning.evals/evals.json - Task-quality evals with assertions.<!-- skill-resources:end -->
node scripts/audit.mjs doctor --root . --format json
node scripts/audit.mjs scan --root . --format markdown
node scripts/audit.mjs scan --root . --format json --output native-rive-audit.jsonTreat script findings as leads. Verify every finding against current code before changing behavior or reporting it as valid.
Before finalizing, run the repo's focused validation command, this skill's audit CLI when relevant, and any browser/device/manual proof required by the changed surface. Report commands run, findings fixed, findings skipped with reasons, and residual risk.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.