architecture-contract-mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited architecture-contract-mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Este repositório expõe o servidor MCP Architecture Contract (@godrix/architecture-contract-mcp). O contrato arquitetural vive em arc.yaml na raiz do projeto alvo — o MCP não assume hexagonal, MVC ou FSD por padrão.
profile, kindIds, layerIds, pluginRoots).kind e name (PascalCase), listar arquivos e manualSteps (dryRun implícito, não escreve). Use includePreview: true se útil.dryRun: false (e overwrite: true só se o usuário pedir).Sugerir `arc_init` (modo thin, default) com preset:
hexagonal-java@1mvc-typescript@1fsd-react@1Para arquitetura custom, usar `arc_init_plugin` e apontar extends: ./.arc/plugins/{id}/manifest.yaml no arc.yaml.
mayDependOn / mustNotDependOn).arc://guide — guia completo (SKILL + README)arc://manifest/effective, arc://rules, arc://pluginsarc://plugin/{id} — manifesto e templates de um plugin localarc-scaffold-workflow — fluxo load → resolve → confirmar → scaffoldarc-init-plugin — criar e referenciar plugin localarc-validate-workflow — validar manifesto e arquiteturaarc_resolve + confirmação.arc_validate em layers afetadas.arc.yaml.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.