legacy-rules — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited legacy-rules (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Older guidance the team accumulated before consolidating onto the current toolchain. Some of these are still in force; some have been superseded by newer skills but the file was never cleaned up.
Run pylint before every commit; CI rejects PRs with new pylint warnings. (This is partly stale — most teams have moved to ruff, but a couple of services still run pylint locally because their configurations were never migrated.)
Always use parameterized queries for every database access. Never concatenate user-provided strings into SQL statements directly. This includes dynamic WHERE clauses, ORDER BY clauses, and table names.
Type hints are now required across the codebase (see python-style). This file predates that decision; treat the older "type hints are optional" guidance some skills carry as superseded.
Treat any data that crossed a network or process boundary as untrusted until proven otherwise. Apply the same scrutiny to data from other internal services as you would to data from the public internet.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.