web-lottie — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited web-lottie (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
lottie-web, dotLottie web components, animation JSON/dotLottie assets, player lifecycle, cleanup, renderer choice, accessibility, and asset validation.
Use this skill as a compact router plus domain checklist. Load references only when the current task matches their condition. Do not cite local scrape paths, machine cache paths, or hidden source locations. Verify API details against the target repo's installed package versions before editing.
local design tokens, accessibility policy, and existing motion patterns.
excerpts.
bundled notes are version-sensitive.
<!-- skill-resources:start -->
references/lottie-player-lifecycle.md - lottie-web player lifecycle. Read when creating, updating, or destroying lottie-web animation instances.references/dotlottie-web-component.md - dotLottie web component and worker notes. Read when using .lottie assets, dotLottie players, workers, or web components.references/asset-accessibility-security.md - Asset accessibility and security review. Read before accepting remote assets, canvas-only output, autoplay loops, or URL actions.references/authoring-and-export-compatibility.md - Authoring and export compatibility. Read when accepting designer-authored Lottie JSON/dotLottie assets or debugging mismatch between After Effects preview and runtime output.references/runtime-event-contracts.md - Runtime events, markers, and playback contracts. Read when code controls Lottie playback, segments, markers, events, or synchronization with app state.references/docs-dotlottie-web.md - Copied source excerpt. Load only when exact upstream wording or API detail is needed.references/docs-lottie-web-load-animation-options.md - Copied source excerpt. Load only when exact upstream wording or API detail is needed.references/docs-lottie-web-readme.md - Copied source excerpt. Load only when exact upstream wording or API detail is needed.references/implementation-notes.md - Copied source excerpt. Load only when exact upstream wording or API detail is needed.references/index.md - Complete reference inventory and routing summary.references/source-ledger.md - Source list, checked date, and copy policy.references/provenance.json - Machine-readable source and local-resource metadata.scripts/audit.mjs - Self-contained audit CLI; run doctor before scan when setup is unclear.assets/templates/web-lottie-audit-report.md - Audit response/report template.assets/templates/web-lottie-review-checklist.md - Manual review checklist.assets/examples/web-lottie-starter.tsx - Starter fixture/example for this skill.evals/trigger-queries.json - Trigger/near-miss eval set for description tuning.evals/evals.json - Task-quality evals with assertions.<!-- skill-resources:end -->
node scripts/audit.mjs doctor --root . --format json
node scripts/audit.mjs scan --root . --format markdown
node scripts/audit.mjs scan --root . --format json --output web-lottie-audit.jsonTreat script findings as leads. Verify every finding against current code before changing behavior or reporting it as valid.
Before finalizing, run the repo's focused validation command, this skill's audit CLI when relevant, and any browser/device/manual proof required by the changed surface. Report commands run, findings fixed, findings skipped with reasons, and residual risk.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.