devcheck — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited devcheck (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
bun run devcheck runs a broader check suite than just lint + types. By default it includes local hygiene checks, MCP definition linting, Biome, TypeScript, and slow dependency/security checks unless --fast is passed. Tests are opt-in via --test.
| Check | Tool | Notes |
|---|---|---|
| TODOs / FIXMEs | git grep | Fails on tracked TODO/FIXME markers outside excluded files |
| Tracked secrets | git ls-files | Flags tracked .env, keys, credentials, and similar sensitive files |
| MCP definitions | bun run scripts/lint-mcp.ts | Validates tool/resource/prompt definitions against framework rules |
| Biome | biome check | Unified lint + format — read-only by default |
| TypeScript | tsc --noEmit | Full project type check |
| Unused dependencies | depcheck | Runs by default; network-free but slower on large repos |
| Security audit | bun audit | Runs by default unless --fast or --no-audit |
| Outdated dependencies | bun outdated | Runs by default unless --fast or --no-deps |
| Tests | vitest run | Off by default; enable with bun run devcheck --test |
To auto-fix lint/format issues, run bun run format.
bun run devcheckbun run devcheck until cleanbun run devcheck --test or bun run test| Check | Error Type | Typical Fix |
|---|---|---|
| TODOs / FIXMEs | Tracked work markers | Resolve or remove the marker before committing |
| Tracked secrets | Sensitive files in git | Add to .gitignore and remove from the index |
| MCP definitions | Definition lint errors | Fix schema/name/annotation issues reported by lint-mcp |
| Biome | Lint/format errors | Run bun run format to auto-fix, or address the flagged rule manually |
| TypeScript | Type errors | Fix type mismatches, missing properties, incorrect generics |
| Security audit | Vulnerabilities in direct deps | Update or replace the affected dependency |
| Outdated deps | Stale package versions | Run bun update or allowlist intentionally pinned packages |
bun run devcheck exits with no errorsbun run devcheck --test or bun run test)~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.