cds-intel — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited cds-intel (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
STOP -- DO NOT READ THIS FILE. You are already reading it. This prompt was injected into your context by Claude Code's command system. Using the Read tool on this file wastes tokens. Begin executing Step 0 immediately.
Before ANY tool calls, display this banner:
GSD > INTELThen proceed to Step 1.
Check if intel is enabled by reading .planning/config.json directly using the Read tool.
DO NOT use the gsd-tools config get-value command -- it hard-exits on missing keys.
.planning/config.json using the Read toolconfig.intel && config.intel.enabled === trueintel.enabled is NOT explicitly true: display the disabled message below and STOPintel.enabled is true: proceed to Step 2Disabled message:
GSD > INTEL
Intel system is disabled. To activate:
node $HOME/.claude/cds-workflow/bin/gsd-tools.cjs config-set intel.enabled true
Then run /cds-intel refresh to build the initial index.Parse $ARGUMENTS to determine the operation mode:
| Argument | Action |
|---|---|
query <term> | Run inline query (Step 2a) |
status | Run inline status check (Step 2b) |
diff | Run inline diff check (Step 2c) |
refresh | Spawn intel-updater agent (Step 3) |
| No argument or unknown | Show usage message |
Usage message (shown when no argument or unrecognized argument):
GSD > INTEL
Usage: /cds-intel <mode>
Modes:
query <term> Search intel files for a term
status Show intel file freshness and staleness
diff Show changes since last snapshot
refresh Rebuild all intel files from codebase analysisRun:
node $HOME/.claude/cds-workflow/bin/gsd-tools.cjs intel query <term>Parse the JSON output and display results:
"disabled": true, display the disabled message from Step 1 and STOPNo intel matches for '<term>'. Try /cds-intel refresh to build the index.STOP after displaying results. Do not spawn an agent.
Run:
node $HOME/.claude/cds-workflow/bin/gsd-tools.cjs intel statusParse the JSON output and display each intel file with:
updated_at timestampSTOP after displaying status. Do not spawn an agent.
Run:
node $HOME/.claude/cds-workflow/bin/gsd-tools.cjs intel diffParse the JSON output and display:
If no snapshot exists, suggest running refresh first.
STOP after displaying diff. Do not spawn an agent.
Display before spawning:
GSD > Spawning intel-updater agent to analyze codebase...Spawn a Task:
Task(
description="Refresh codebase intelligence files",
prompt="You are the gsd-intel-updater agent. Your job is to analyze this codebase and write/update intelligence files in .planning/intel/.
Project root: ${CWD}
gsd-tools path: $HOME/.claude/cds-workflow/bin/gsd-tools.cjs
Instructions:
1. Analyze the codebase structure, dependencies, APIs, and architecture
2. Write JSON intel files to .planning/intel/ (stack.json, api-map.json, dependency-graph.json, file-roles.json, arch-decisions.json)
3. Each file must have a _meta object with updated_at timestamp
4. Use gsd-tools intel extract-exports <file> to analyze source files
5. Use gsd-tools intel patch-meta <file> to update timestamps after writing
6. Use gsd-tools intel validate to check your output
When complete, output: ## INTEL UPDATE COMPLETE
If something fails, output: ## INTEL UPDATE FAILED with details."
)Wait for the agent to complete.
After the agent completes, run:
node $HOME/.claude/cds-workflow/bin/gsd-tools.cjs intel statusDisplay a summary showing:
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.