workspace-audit — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited workspace-audit (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A periodic health check for any WorkOS-style workspace. Catches drift before it costs token usage or output quality.
Five checks, then a single grouped report. Never writes changes without explicit approval.
CLAUDE.md (should move to MEMORY.md) and prescriptive entries in MEMORY.md (should move to CLAUDE.md).MEMORY.md entries that look historical or stale and should move to ARCHIVE.md.CLAUDE.md target 200–250, max 300; MEMORY.md max 150).MEMORY.md entries longer than two sentences.MEMORY.md that should live in a deeper-level MEMORY.md.Find the WorkOS root dynamically. Look for a CLAUDE.md with a Routing Map section in the mounted workspace. That's the root.
If the user named a specific project to audit (e.g., "audit my Email HQ project"), audit that one instead of the root.
If you can't find a root, stop and tell the user — don't invent structure.
For the chosen scope, read:
CLAUDE.mdMEMORY.mdARCHIVE.md (if it exists)If ARCHIVE.md doesn't exist at the root level, flag that as the first finding before running any other check — the WorkOS isn't fully set up and several other checks depend on its existence.
For each entry in CLAUDE.md:
MEMORY.md.For each entry in MEMORY.md:
CLAUDE.md.For each entry in MEMORY.md:
Check the Memory hygiene / Memory System section in CLAUDE.md for the workspace's specific rules on what stays vs. archives. Different WorkOS instances may define "current-state content" differently — don't impose a generic rule.
Skip entries that match a "stays regardless of age" rule (often: active projects, contacts, working conventions, identity facts).
Report current line counts as a table:
CLAUDE.md: actual / target 200–250 / max 300MEMORY.md: actual / max 150ARCHIVE.md: actual (no ceiling)If either is over target, note it but don't propose specific cuts here — that's what the other checks are for. Once the user applies findings from checks A, B, D, and E, ceilings often come back under target naturally.
For each bullet or entry in MEMORY.md:
For each entry in root MEMORY.md:
MEMORY.md?MEMORY.md exists, propose moving the detail there and replacing the root entry with a short pointer (e.g., "Latest status in [Project Name]/MEMORY.md").MEMORY.md exists yet, flag it as a candidate for create-project.Group findings by check. Use this format:
**Workspace Audit Report — [date] — [scope: root / project name]**
## A. Wrong-location entries
[N]. **[Entry summary]**
- Currently in: `[file]`
- Should be in: `[file]`
- Proposed wording: [exact text]
- Why: [one sentence]
## B. Archive candidates
[same format]
## C. Size ceiling status
| File | Lines | Target | Status |
|---|---|---|---|
| CLAUDE.md | [X] | 200–250 (max 300) | ✓ / ⚠ over target / ❌ over max |
| MEMORY.md | [X] | max 150 | ✓ / ❌ over max |
| ARCHIVE.md | [X] | n/a | n/a |
## D. Entry format violations
[same format]
## E. Cascade opportunities
[same format]If a check returns no findings, say so under that section header. Don't omit the section.
If there are no findings overall, report "Clean workspace. Nothing to move." Don't manufacture work.
After the user approves (all, some, or none of the findings), write the approved changes. For each change, confirm what was written and where:
Important: Never write changes without approval. Always present findings first and wait.
create-project separately.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.