memory — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited memory (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use npx ai-devkit@latest memory ... as the durable knowledge layer.
npx ai-devkit@latest memory search --query "<task, subsystem, error, or convention>" --limit 5For broad or risky tasks, search multiple angles: subsystem, error text, framework, command, and task intent.
npx ai-devkit@latest memory search --query "<knowledge to store>" --tableBefore storing, all must be true:
Store:
Do not store:
npx ai-devkit@latest memory search \
--query "<query>" \
--tags "<tags>" \
--scope "<scope>" \
--limit 5Use --table to get IDs for updates:
npx ai-devkit@latest memory search --query "<query>" --tableOptions: --query/-q required; --tags; --scope/-s; --limit/-l from 1-20; --table.
npx ai-devkit@latest memory store \
--title "<actionable title, 10-100 chars>" \
--content "<context, guidance, evidence, exceptions>" \
--tags "<lowercase,tags>" \
--scope "<global|project:name|repo:org/repo>"Use this content shape when helpful:
Context: Where this applies.
Guidance: What to do.
Evidence: File, command, test, or user instruction.
Exceptions: When not to apply it.Find the ID with search --table, then update only changed fields:
npx ai-devkit@latest memory update \
--id "<memory-id>" \
--title "<updated title>" \
--content "<updated content>" \
--tags "<replacement,tags>" \
--scope "<updated scope>"--tags replaces all existing tags.
Use the narrowest useful scope:
repo:<org/repo> for one repository.project:<name> for one app, product, or workspace.global only for knowledge that applies across unrelated projects.If unsure, use a narrower scope.
npx ai-devkit@latest --version.--limit range.~/.ai-devkit/memory.db; project config can override it automatically.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.