init — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited init (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Self-healing setup. Goal: 30 seconds, two user actions max (install plugin, type /init). Default backend is local memory — no local model, no API key, no prompts. Local model and Anthropic key are opt-in upgrades documented in /help.
Run in order. Stop and report at the first failure that needs human attention. Otherwise, push through automatically.
Bash: curl -fsS -m 1 http://127.0.0.1:7878/api/healthDetect whether the origin CLI is on PATH:
Bash: command -v origin >/dev/null 2>&1 && echo present || echo absentIf absent, run the installer (no human prompts):
Bash: curl -fsSL https://raw.githubusercontent.com/7xuanlu/origin/v0.6.1/install.sh | bashThen add it to PATH for the current session and configure local memory non-interactively:
Bash: export PATH="$HOME/.origin/bin:$PATH" && origin setup --basic && origin installIf present (CLI exists, daemon down), just install + start:
Bash: origin setup --basic 2>/dev/null || true; origin installorigin setup --basic is idempotent — safe to re-run. origin install writes the launchd plist and starts the daemon.
Bash: for i in 1 2 3 4 5; do curl -fsS -m 1 http://127.0.0.1:7878/api/health && break; sleep 1; doneIf the daemon still isn't reachable after ~5s, surface the error and stop. Likely cause: launchd plist load failure, port 7878 occupied by another process, or macOS Tahoe Metal init issue (daemon degrades but still binds — check lsof -ti :7878).
Call the origin MCP server's doctor tool:
doctor()Expected: local memory configured (no model, no key). Capture the mode string for the final report.
context()Pass → continue. Fail → MCP not wired. Tell user: "origin-mcp didn't respond. Restart Claude Code so the plugin's .mcp.json re-spawns the server."
Print:
Origin ready.
Daemon: up on 127.0.0.1:7878
Mode: <mode from doctor()>
MCP: connected
Data: ~/.origin/ (pages, sessions, db symlink)
Try: /brief, /capture <thing>, /recall <query>, /helpIf this was the first /init invocation in the session, dispatch /help once so the user sees the verb cheat-sheet without asking.
Mention these in the ready report only if the user explicitly asks for "richer features" or asks about model-backed extraction:
origin model install — local Qwen for distill cycles.origin key set anthropic — Anthropic for stronger synthesis.Default flow ignores both. Storage, search, recall, and MCP memory all work in local memory mode.
/plugin install origin@7xuanlu./brief instead.origin doctor or settings file directly.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.