gsd:spike — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited gsd:spike (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
<objective> Spike an idea through experiential exploration — build focused experiments to feel the pieces of a future app, validate feasibility, and produce verified knowledge for the real build. Spikes live in .planning/spikes/ and integrate with GSD commit patterns, state tracking, and handoff workflows.
Two modes:
Does not require /gsd:new-project — auto-creates .planning/spikes/ if needed. </objective>
<execution_context> @${CLAUDE_PLUGIN_ROOT}/workflows/spike.md @${CLAUDE_PLUGIN_ROOT}/references/ui-brand.md </execution_context>
<runtime_note> Copilot (VS Code): Use vscode_askquestions wherever this workflow calls AskUserQuestion. </runtime_note>
<context> Idea: $ARGUMENTS
Available flags:
--quick — Skip decomposition/alignment, jump straight to building. Use when you already know what to spike.--text — Use plain-text numbered lists instead of AskUserQuestion (for non-Claude runtimes).</context>
<process> Execute the spike workflow from @${CLAUDE_PLUGIN_ROOT}/workflows/spike.md end-to-end. Preserve all workflow gates (prior spike check, decomposition, research, risk ordering, observability assessment, verification, MANIFEST updates, commit patterns). </process>
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.