create-engine-installer — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited create-engine-installer (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
When building or reviewing an install generator, follow these steps in order. DO NOT ship a generator without completing steps 3 and 4.
config/initializers/, migrations at db/migrate/, route mount in config/routes.rb).Key implementation rules:
All generator actions must be safe to run multiple times. Guard every file creation and injection at the point of use:
def create_initializer
return if File.exist?(File.join(destination_root, 'config/initializers/my_engine.rb'))
create_file 'config/initializers/my_engine.rb', <<~RUBY
MyEngine.configure do |config|
config.user_class = "User"
end
RUBY
end
def mount_route
# inject_into_file with force: false skips insertion if sentinel already present
inject_into_file 'config/routes.rb',
"\n mount MyEngine::Engine, at: '/admin'\n",
after: "Rails.application.routes.draw do",
force: false
endMinimal rerun spec:
it 'does not duplicate the route mount on rerun' do
2.times { run_generator }
expect(File.read(file('config/routes.rb')).scan('mount MyEngine::Engine').size).to eq(1)
endFor larger installers, extract extended guard patterns and spec templates into a dedicated companion file alongside the generator (e.g. lib/generators/my_engine/install/install_generator_patterns.rb) to keep the generator lean and this skill focused on workflow. Reference that file explicitly in your generator's comments so future maintainers know where to find the shared patterns.
| Skill | When to chain |
|---|---|
| create-engine | When designing the engine structure that installers will configure |
| document-engine | When documenting install steps or upgrade instructions |
| test-engine | When adding generator specs or dummy-app install coverage |
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.