infra-kit.workflow — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited infra-kit.workflow (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use this skill to run a repeatable workflow from an incoming ticket (Jira/GitHub/Slack/Email) to:
This framework focuses on infra delivery artifacts that are easy to review and operate.
For the end-to-end mapping across skills, see docs/infras-kit/flow.md.
docs/infras-kit/work-items/<id>-<slug>/.implementation-notes.md.bash infras-kit-plugin/skills/infra-kit.workflow/scripts/new-work-item.sh "<short title>" \
--id "<TICKET-ID>" \
--link "<ticket url>"ticket.md, then generate plan.md and tasks.md.infra-kit.domain.iac for Terraform/Terragrunt changesinfra-kit.domain.helm for chart workinfra-kit.domain.k8s-doctor for runtime debugginginfra-kit.domain.github for repo and CI/CD changesinfra-kit.workflow.verify to record verification evidence and “definition of done”infra-kit.workflow.review to prepare PRs and handle review feedbackinfra-kit.workflow.audit to review before merge/releaseNote: skill names were renamed. Use infra-kit.workflow.* for workflow skills and infra-kit.domain.* for domain skills.
This workflow is intentionally iterative. If you discover new unknowns mid-way, add them as [NEEDS CLARIFICATION: ...], loop back, and update the upstream artifact instead of guessing.
[NEEDS CLARIFICATION: ...][NEEDS CLARIFICATION] remain, ask targeted questions and stop[NEEDS CLARIFICATION] remain, ask targeted questions and stop[NEEDS CLARIFICATION] remain, ask targeted questions and stop[infra-kit.domain.iac], [infra-kit.domain.helm])[P]At the end of each phase, always do these two things in chat:
If the user explicitly wants an exploratory spike, allow proceeding with labeled assumptions:
[ASSUMPTION: ...] and keep them in the doc so they can be revisited.plan.md.[ASSUMPTION: ...].docs/infras-kit/work-items/<id>-<slug>/ticket.mddocs/infras-kit/work-items/<id>-<slug>/spec.mddocs/infras-kit/work-items/<id>-<slug>/plan.mddocs/infras-kit/work-items/<id>-<slug>/tasks.mddocs/infras-kit/work-items/<id>-<slug>/implementation-notes.mddocs/infras-kit/work-items/<id>-<slug>/confluence.md~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.