contract-check — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited contract-check (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Audits the health of consumer-driven contract tests across all letterbox services. Surfaces staleness, sync gaps, uncommitted pacts, missing tests, documentation drift, and disabled tests.
This is a read-only audit — it does not run tests or modify files. Use /contract-test to execute contract test workflows.
/contract-check # Full audit (all checks)
/contract-check status # Summary dashboard only
/contract-check stale # Consumer output newer than provider copy
/contract-check uncommitted # Pact files not committed in service repos
/contract-check sync-gaps # Trace each intended edge: consumer test → built pact → synced to provider
/contract-check coverage # Provider CI verifies each synced pact? (catches commented-out/disabled consumers)
/contract-check missing # Connectors with no consumer tests
/contract-check docs # Documentation drift in pact-workflow.md
/contract-check disabled # Contract tests excluded from default builds
/contract-check <service> # All checks scoped to one serviceOn first run, ensure the script symlink exists:
ln -sfn "$SKILLS_DIR/contract-check/scripts/contract-check.sh" ./scripts/contract-check
chmod +x ./scripts/contract-checkWhere $SKILLS_DIR resolves to ${CLAUDE_HOME:-$HOME/.claude}/skills.
Check that ./scripts/contract-check exists and is executable. If not, create the symlink as shown in Setup above.
Parse the user's argument:
(none) or full → Run all checks (mechanical + semantic)status → Run all checks but only show the summary tablestale → Run ./scripts/contract-check staleuncommitted → Run ./scripts/contract-check uncommittedsync-gaps → Run ./scripts/contract-check sync-gapscoverage → Run ./scripts/contract-check coverage (CI verifies each synced pact?)missing → Run semantic Missing Consumer Tests check (Step 3)docs → Run semantic Documentation Drift check (Step 4)disabled → Run semantic Disabled Tests check (Step 5). coverage is the mechanicalcompanion: it catches commented-out PACTCONSUMER entries in a provider's CI verify job.
<service> → Run all checks scoped to that servicematrix → Run ./scripts/contract-check matrixBefore running the uncommitted check (or all/full), suggest running make normalize-pacts first. Pact libraries regenerate random UUIDs, dates, and strings on every test run, causing noisy git diffs that aren't real contract changes. The normalizer replaces these with deterministic placeholders.
Note: normalize-pacts.py currently only normalizes values referenced by generators.body metadata. UUIDs in providerStates.params, request.path, request.headers, and response.headers are NOT yet normalized — those may still show as noise in uncommitted diffs. Flag these as noise in the report when the diff is UUID-only.
Run the appropriate script subcommand:
./scripts/contract-check all # or stale, uncommitted, sync-gaps, coverage, matrixParse the script output. Each line starts with a status keyword:
OK — no action neededSTALE — consumer pact is newer than provider copyDIFFERS — same age but content differsMISSING_PROVIDER — provider does not have this pact fileUNCOMMITTED — pact file has uncommitted changesNOT_BUILT — (sync-gaps) consumer test exists but produced no pact in target/ (tests not run)NOT_SYNCED — (sync-gaps) pact is built but not copied into the provider (run sync-pacts.sh)GAP — (coverage) provider CI does not verify all its synced consumer pacts(style=enum with commented-out consumers, or style=none with no verify job)
CLEAN — no issues foundNO_DATA — no consumer pact files foundSUMMARY — counts for the checkFor each consumer service, compare connectors against consumer test files:
<service>/app/connectors/*Connector.scala<service>/src/main/scala/**/connectors/*Connector.scala<service>/test/contract/*Consumer*.scala<service>/src/test/scala/**/contract/*Consumer*.scalaConnector suffix, lowercase. E.g., AccountConnector.scala → account.Output format:
### Missing Consumer Tests
| Service | Connector | Provider | Has Consumer Test |
|---------|-----------|----------|-------------------|
| reconciler | EventConnector | event | NO |
| reconciler | MessageQueueConnector | messagequeue | NO |docs/pact-workflow.md./scripts/contract-check matrix to get actual relationships-l tags.ContractTest or --exclude-tags=ContractTesttest-contract target overrides it (e.g., with set Test/testOptions := Nil)sbt test silently skips contract teststest-contract Makefile target entirelyCombine all findings into a health report:
# Contract Health Report
## Summary
| Check | Status | Details |
|------------------|--------|--------------------------------|
| Staleness | PASS/WARN/FAIL | X stale / Y total |
| Uncommitted | PASS/WARN | X files across Y services |
| Sync coverage | PASS/FAIL | X/Y pairs in sync-pacts.sh |
| Verify coverage | PASS/FAIL | X providers verify all synced pacts |
| Missing tests | PASS/WARN | X connectors without tests |
| Documentation | PASS/FAIL | X items out of date |
| Disabled tests | PASS/INFO | X services exclude by default |
## Staleness
[details from script output]
## Uncommitted Pact Files
[details from script output]
## Sync Coverage Gaps
[details from script output]
## Missing Consumer Tests
[details from LLM analysis]
## Documentation Drift
[details from LLM analysis]
## Disabled Tests
[details from LLM analysis]
## Recommended Actions (priority order)
1. [most impactful fix first]
2. ...Status thresholds:
After presenting the report, ask the user:
Would you like me to create beads for the issues found? I can triage them as P3 tasks with appropriate service labels.
If the user agrees, use /triage to create beads for actionable findings. Group related findings into single beads where appropriate (e.g., "Add digest, patrol, reconciler to sync-pacts.sh" as one bead rather than three).
When invoked with a service name (/contract-check dispatch):
make test-contract in consumer servicesMost providers use test/resources/pacts/. Exceptions:
src/test/resources/pacts/src/test/resources/pacts/Braintree, Stripe, SES, SpamConfiguration, WebConfiguration, ApiConnector (abstract base), ConnectorConfiguration, ConnectorModule
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.