claude-md-updater — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited claude-md-updater (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Analyze the current conversation to identify information worth persisting in CLAUDE.md for future sessions, then propose the edits for approval before writing anything.
Show the exact patch first, then a short summary grouped by category:
## Proposed CLAUDE.md updates
--- a/CLAUDE.md +++ b/CLAUDE.md @@ section being changed @@ existing context line +new durable lesson, infra fact, or workflow
Summary of the diff above:
- Hard-won lessons: [one line, if any]
- Infrastructure updates: [one line, if any]
- New workflows: [one line, if any]
Apply this diff? Nothing is written until you approve.CLAUDE.md is team-shared (checked into git) and advisory: it loads into every session, so it is for durable, infrequently-changing facts, not a running log. Per the project-memory skill, keep these out of CLAUDE.md:
Route those to auto memory (~/.claude/projects/<project>/memory/, which Claude maintains on its own) or to a gitignored CLAUDE.local.md for personal notes. Putting them in CLAUDE.md bloats shared context and loads stale per-session facts into future sessions.
CLAUDE.local.md, never the committed CLAUDE.md.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.