Warmstart — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Warmstart (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Stop your AI agent from relearning your repo every session.
Every coding agent — Claude Code, Cursor, Codex, Copilot — pays the same tax on every repo, every session: it burns its first several turns guessing the test command, the build incantation, the package manager, the entry point, and stepping on gotchas the last session already figured out and threw away.
warmstart ends that. One command discovers your repo's real dev-loop, runs the commands to prove they work, and writes a committed AGENTS.md plus a live MCP server — so any agent reads the verified truth in one shot instead of fumbling.
npx warmstart initwarmstart demo
Watch an agent waste 8 turns finding the test command → watch it read `AGENTS.md` and nail it in 1.
A hand-written AGENTS.md rots the moment a command changes, so agents don't trust it and re-verify by trial anyway. warmstart keeps itself honest: every command carries a precise, scoped stamp of what was actually proven.
| Stamp | Meaning |
|---|---|
✓ passed — darwin/arm64, v20, 2026-06-22 | Ran and exited 0 — here, then. Not a portability promise. |
~ flaky (2/3 passes) | Non-deterministic across repeated runs. |
⚠ unverified (env-missing — command may be correct) | Failed for a likely environmental reason (missing secret/service). |
⚠ unverified (not-run: destructive) | Matched a dangerous pattern — never auto-run. |
⚠ unverified (timeout) / ✗ failed | Recorded with a redacted, distilled reason. |
The stamp states what was proven, where, and when — never a bare "verified."
package.json scripts, Makefile targets, and pyproject.toml for candidate commands.AGENTS.md (never clobbering your prose) and registers a warmstart serve MCP server for Claude Code.AGENTS.mdAlready have a hand-written AGENTS.md? warmstart never overwrites it and never errors — it appends a single delimited block and leaves everything else untouched. Your file ends up with two zones that coexist:
# My Project
Hand-written notes you care about. ← yours forever, never touched
## Gotchas
- Never run migrations on Friday.
<!-- warmstart:start -->
verified dev-loop commands ← warmstart owns / refreshes only this
<!-- warmstart:end -->AGENTS.md.bak, then appends the block.Curated human knowledge above, machine-verified commands below — kept honest and current without stepping on your work.
deploy, publish, rm -rf, git push, drop, and similar are listed but never executed.cross-spawn with tokenized args — no shell-injection surface, and Windows .cmd shims work correctly.AGENTS.md.AGENTS.md is backed up and preserved; only a delimited block is managed..warmstartrc.json or .warmstartrc.yaml){
"timeoutMs": 120000,
"flakyRuns": 1,
"network": false,
"disable": ["make deploy"],
"env": {}
}warmstart init — scan, verify (with consent), emit AGENTS.md + register MCP. --yes for non-interactive/CI.warmstart serve — run the MCP server exposing the manifest.warmstart doctor — check toolchain availability.Now: package.json (+ pnpm/yarn/npm/bun detection), Makefile, pyproject.toml. Planned: justfile, Taskfile.yml, tox.ini, CI workflows (as hint sources), passive observation, staleness re-verification, CI-stamped manifests.
MIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.