typegpu — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited typegpu (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
TypeGPU schemas, typed buffers/textures, shader functions, pipelines, WebGPU capability checks, and CPU/GPU resource ownership.
Use this skill as a compact router plus domain checklist. Load references only when the current task matches their condition. Do not cite local scrape paths, machine cache paths, or hidden source locations. Verify API details against the target repo's installed package versions before editing.
local design tokens, accessibility policy, and existing motion patterns.
excerpts.
bundled notes are version-sensitive.
<!-- skill-resources:start -->
references/typegpu-codex-playbook.md - Codex workflow for TypeGPU tasks. Read before writing TypeGPU app code, shader functions, or compute/render pipelines.references/shader-resource-boundaries.md - Shader/resource ownership rules. Read when code mixes CPU buffers, GPU resources, schemas, bind groups, and shader functions.references/webgpu-runtime-validation.md - Browser WebGPU validation and fallbacks. Read for secure context, adapter/device, unsupported browser, reduced motion, and teardown proof.references/browser-capability-and-adapter-selection.md - Browser capability and adapter selection. Read before creating TypeGPU roots, requesting WebGPU adapters/devices, or designing fallbacks.references/compute-vs-render-pipeline-design.md - Compute versus render pipeline design. Read when choosing TypeGPU compute, render, storage buffer, texture, or shader-function patterns.references/matrices.md - Copied source excerpt. Load only when exact upstream wording or API detail is needed.references/pipelines.md - Copied source excerpt. Load only when exact upstream wording or API detail is needed.references/setup.md - Copied source excerpt. Load only when exact upstream wording or API detail is needed.references/shaders.md - Copied source excerpt. Load only when exact upstream wording or API detail is needed.references/textures.md - Copied source excerpt. Load only when exact upstream wording or API detail is needed.references/types.md - Copied source excerpt. Load only when exact upstream wording or API detail is needed.references/advanced.md - Copied source excerpt. Load only when exact upstream wording or API detail is needed.references/noise.md - Copied source excerpt. Load only when exact upstream wording or API detail is needed.references/sdf.md - Copied source excerpt. Load only when exact upstream wording or API detail is needed.references/index.md - Complete reference inventory and routing summary.references/source-ledger.md - Source list, checked date, and copy policy.references/provenance.json - Machine-readable source and local-resource metadata.scripts/audit.mjs - Self-contained audit CLI; run doctor before scan when setup is unclear.assets/templates/typegpu-audit-report.md - Audit response/report template.assets/templates/typegpu-review-checklist.md - Manual review checklist.assets/examples/typegpu-starter.ts - Starter fixture/example for this skill.evals/trigger-queries.json - Trigger/near-miss eval set for description tuning.evals/evals.json - Task-quality evals with assertions.<!-- skill-resources:end -->
node scripts/audit.mjs doctor --root . --format json
node scripts/audit.mjs scan --root . --format markdown
node scripts/audit.mjs scan --root . --format json --output typegpu-audit.jsonTreat script findings as leads. Verify every finding against current code before changing behavior or reporting it as valid.
Before finalizing, run the repo's focused validation command, this skill's audit CLI when relevant, and any browser/device/manual proof required by the changed surface. Report commands run, findings fixed, findings skipped with reasons, and residual risk.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.