cds-quick-7c4c34 — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited cds-quick-7c4c34 (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
<objective> Execute small, ad-hoc tasks with GSD guarantees (atomic commits, STATE.md tracking).
Quick mode is the same system with a shorter path:
.planning/quick/ separate from planned phasesDefault: Skips research, discussion, plan-checker, verifier. Use when you know exactly what to do.
`--discuss` flag: Lightweight discussion phase before planning. Surfaces assumptions, clarifies gray areas, captures decisions in CONTEXT.md. Use when the task has ambiguity worth resolving upfront.
`--full` flag: Enables the complete quality pipeline — discussion + research + plan-checking + verification. One flag for everything.
`--validate` flag: Enables plan-checking (max 2 iterations) and post-execution verification only. Use when you want quality guarantees without discussion or research.
`--research` flag: Spawns a focused research agent before planning. Investigates implementation approaches, library options, and pitfalls for the task. Use when you're unsure of the best approach.
Granular flags are composable: --discuss --research --validate gives the same result as --full.
Subcommands:
list — List all quick tasks with statusstatus <slug> — Show status of a specific quick taskresume <slug> — Resume a specific quick task by slug</objective>
<execution_context> @$HOME/.claude/cds-workflow/workflows/quick.md </execution_context>
<context> $ARGUMENTS
Context files are resolved inside the workflow (init quick) and delegated via <files_to_read> blocks. </context>
<process>
Parse $ARGUMENTS for subcommands FIRST:
Slug sanitization (for status and resume): Strip any characters not matching [a-z0-9-]. Reject slugs longer than 60 chars or containing .. or /. If invalid, output "Invalid session slug." and stop.
When SUBCMD=list:
ls -d .planning/quick/*/ 2>/dev/nullFor each directory found:
status from its frontmatter via: node "$HOME/.claude/cds-workflow/bin/gsd-tools.cjs" frontmatter get .planning/quick/{dir}/SUMMARY.md --field status 2>/dev/nullstat -f "%SB" -t "%Y-%m-%d" (macOS) or stat -c "%w" (Linux); fall back to the date prefix in the directory name (format: YYYYMMDD- prefix)complete ✓incompletein-progressabandoned? (>7 days, no summary)SECURITY: Directory names are read from the filesystem. Before displaying any slug, sanitize: strip non-printable characters, ANSI escape sequences, and path separators using: name.replace(/[^\x20-\x7E]/g, '').replace(/[/\\]/g, ''). Never pass raw directory names to shell commands via string interpolation.
Display format:
Quick Tasks
────────────────────────────────────────────────────────────
slug date status
backup-s3-policy 2026-04-10 in-progress
auth-token-refresh-fix 2026-04-09 complete ✓
update-node-deps 2026-04-08 abandoned? (>7 days, no summary)
────────────────────────────────────────────────────────────
3 tasks (1 complete, 2 incomplete/in-progress)If no directories found: print No quick tasks found. and stop.
STOP after displaying the list. Do NOT proceed to further steps.
When SUBCMD=status and SLUG is set (already sanitized):
Find directory matching *-{SLUG} pattern:
dir=$(ls -d .planning/quick/*-{SLUG}/ 2>/dev/null | head -1)If no directory found, print No quick task found with slug: {SLUG} and stop.
Read PLAN.md and SUMMARY.md (if exists) for the given slug. Display:
Quick Task: {slug}
─────────────────────────────────────
Plan file: .planning/quick/{dir}/PLAN.md
Status: {status from SUMMARY.md frontmatter, or "no summary yet"}
Description: {first non-empty line from PLAN.md after frontmatter}
Last action: {last meaningful line of SUMMARY.md, or "none"}
─────────────────────────────────────
Resume with: /cds-quick resume {slug}No agent spawn. STOP after printing.
When SUBCMD=resume and SLUG is set (already sanitized):
*-{SLUG} pattern: dir=$(ls -d .planning/quick/*-{SLUG}/ 2>/dev/null | head -1)No quick task found with slug: {SLUG} and stop. [quick] Resuming: .planning/quick/{dir}/
[quick] Plan: {description from PLAN.md}
[quick] Status: {status from SUMMARY.md, or "in-progress"} node "$HOME/.claude/cds-workflow/bin/gsd-tools.cjs" init quickWhen SUBCMD=run:
Execute the quick workflow from @$HOME/.claude/cds-workflow/workflows/quick.md end-to-end. Preserve all workflow gates (validation, task description, planning, execution, state updates, commits).
</process>
<notes>
.planning/quick/ — separate from phases, not tracked in ROADMAP.mdYYYYMMDD-{slug}/ directory with PLAN.md and eventually SUMMARY.mdlist to audit accumulated tasks; use resume to continue in-progress work</notes>
<security_notes>
</security_notes>
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.