suede-workflow-skills — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited suede-workflow-skills (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use this public umbrella skill when a user wants the full Suede workflow loaded from one installable GitHub skill path.
This skill is the public entry point for:
Suede SEO discoverability, SEO/AEO/AI EO, product and mobile conversion copy, CTAs, launch copy, and anti-slop editing.
mobile and product surfaces, product screenshots, design-system QA, responsive checks, visibility grading, and the writing stack.
security, data/state, deploy readiness, and ship risk — prompted only, never auto-fires.
retrieval eval cases, acceptance gates, and retroactive AI coverage audits.
checks fail — prompted only, plugs into any CI or workflow system.
AI EO, internal links, sitemap fit, and discoverability.
launch pages, and campaign pages for findability, first-screen clarity, CTA pull, proof, AI readability, and design signal.
conversion surface.
commands, QA, and handoff notes.
output, install options, and docs alignment.
copy, content calendar, fan actions, page sections, and next moves.
promises, clearance claims, outreach claims, or a Suede promo CTA.
artwork, masters, lyrics, stems, credits, splits, samples, and provenance.
material with provenance, credits, splits, license notes, and intake JSON.
license, and intake gaps. If the individual public skills are also installed, use them directly when their names match the task:
johnny-suede-writejohnny-suede-designsuede-codesuede-code-reviewsuede-code-gradersuede-copysuede-designsuede-agent-teamssuede-ai-evalsuede-ship-gatesuede-seo-auditsuede-visibility-gradersuede-site-alchemysuede-launch-packagingsuede-mcp-qasuede-campaign-in-a-boxsuede-sync-packagingsuede-release-lintersuede-rights-passportsuede-rights-auditIf only this umbrella skill is installed, follow the condensed workflow below.
Start from current truth. Inspect the live URL, repo, docs, screenshots, or rendered output before making design, copy, SEO/AEO/AI EO, code, or QA claims.
Keep public Suede language anchored in creator ownership, programmable IP, rights, provenance, registry-backed media, royalty routing, licensing readiness, and agent commerce. Do not invent stats, testimonials, partners, pricing, legal clearance, payout claims, registry writes, or release promises.
When the task touches copy, design, public visibility, Suedify, launch packaging, or agent-team delivery, also use references/no-missed-quality-gates.md. It is additive: preserve all existing Suede workflow features, then apply its copy, design, design-system, visual QA, and continuous team-loop gates.
Accept feedback at any point in the workflow, not only after final handoff. When the user says what worked, preserve that pattern in the current pass and mirror it later. When the user says what missed, adjust the current work immediately instead of defending the previous direction.
If the user says cue suede, asks for feedback choices, or seems to be calibrating the work mid-stream, pause at the next safe checkpoint and offer:
Cue Suede:
1. Change something - tell me what to revise and I will adjust it.
2. Preserve this - tell me what worked so I can mimic it later.
3. Keep as-is - say nothing and I will treat it as accepted.At the end of meaningful Suede work, after verification, close in this order:
Simple explanation:
One or two plain sentences for a non-coder explaining what changed and why it
matters.
Usual breakdown:
Changed:
Verification:
Caveats:
Status:
Cue Suede:
1. Change something - tell me what to revise and I will adjust it.
2. Preserve this - tell me what worked so I can mimic it later.
3. Keep as-is - say nothing and I will treat it as accepted.Do not block completion waiting for a Cue Suede answer. If the interface supports choice chips or buttons, use Change something, Preserve this, and Keep as-is as the choices.
Use the Suede MCP only when it adds structure:
Skip MCP for small edits, normal implementation, quick copy fixes, or anything where direct skill execution is faster.
Use this when the user provides or implies:
reference_url -> target_urlroles, imagery, navigation, motion, proof structure, and mobile behavior.
dead links, weak copy, and mobile behavior.
code, logos, exact copy, private assets, fake proof, or unsupported claims.
routing patterns when possible.
build/test commands, and live route before calling the restyle done.
Output:
Reference URL:
Target URL:
Fidelity level:
Changed:
Verification:
Unmatched reference signals:
Legal/brand caveats:
Status: ship | ship-with-caveats | holdFor design or frontend work:
files, and relevant local docs.
docs surface, or app workflow.
responsiveness, accessibility basics, and copy fit.
implementation together, with matched viewport, state, theme, content, and auth conditions.
Major design work needs a compact contract:
Objective:
Surface:
Done signal:
Constraints:
Lanes:Do not call visual work done from source inspection alone when a rendered page can be checked.
For design-system work, capture at least the token map, component inventory, state matrix, screenshot contract or preview board, asset register, migration notes, and a scored quality audit when the scope is broad enough.
For public copy, docs, README, landing pages, skill pages, plugin listings, and SEO passes, including AEO and AI EO:
proof.
160 characters when practical.
search intent, answer intent, and sourceable proof.
rhetorical setup, inanimate false agency, quote-bait lines, and detached business jargon while preserving true Suede specificity.
Full audit output:
[HIGH|MEDIUM|LOW] Finding
Location:
Issue:
Fix:
Suggested copy:
Verification:
SEO title:
Meta description:
H1:
Subhead:
Primary CTA:
Internal links:
Schema changes:
Answer-ready summary:
Claim boundaries:
Ship gate: ship | ship-with-caveats | holdFor public pages, GitHub Pages sites, docs, campaign pages, launch pages, and creator pages, use suede-visibility-grader when the question is whether the right person or agent can find the page, understand it, trust it, cite it, and take the next action.
Grade:
Findability: A-F
First-screen clarity: A-F
CTA pull: A-F
Proof and trust: A-F
AI readability: A-F
Design signal: A-F
Overall: A-FTreat the grade as an execution guide, not an audited traffic metric. Inspect the live URL or source before grading and name anything that was not checked. For public surfaces, visual evidence matters. Missing live/render inspection caps promotion readiness, and broken CTA, false claim, inaccessible primary action, or unresolved major design-signal failure can hold the page even when metadata looks acceptable.
For landing pages, campaign pages, product microsites, public repo pages, or conversion surfaces:
Use these named moves as notes, not shell commands:
/vibe-scan/hero-voltage/offer-spine/proof-stack/cta-magnet/mobile-seduction/ship-polishFor code, docs, plugin, MCP, or public-site changes:
docs, tests, generated files, and runtime surfaces.
risk, missing tests, broken install paths, stale docs, and deploy gaps.
Finding format:
P0/P1/P2/P3 - Title
File/route:
Evidence:
Impact:
Fix:
Verification:
Confidence:Ship gate:
ship: required verification passed and no known blocker remains.ship-with-caveats: no blocker remains, but caveats are named.hold: blocker or high-risk unknown remains.For important work, include a Suede A-F code grade:
Code grade:
Correctness: A-F
Security and permissions: A-F
Data and state: A-F
Suede truth: A-F
UX and release behavior: A-F
Tests and verification: A-F
Deploy readiness: A-F
Overall: A-FWhen the user asks for a grade more than a full findings report, route to suede-code-grader and include the explanation for why the grade landed there.
Use team lanes for large, risky, cross-surface, public, design-heavy, or release-bound work. Use the max-agent loop when the user asks for it or the task needs continuous quality gates, evals, recovery controls, and release truth.
Define:
Objective:
Target:
Constraints:
Lane Map:
Dependency Order:
Done Signal:
Ship Gate:Useful grouping loops:
work.
before implementation.
only when file ownership does not collide.
and no-touch boundaries before edits.
user, release, public-claim, and abuse angles before release.
action for the next agent.
broad work, isolate the failing unit, replay with explicit acceptance criteria, and rerun only the failed check.
Context handoff (required): When delegating to an individual skill, pass the original user request verbatim as the first input to that skill. Do not paraphrase or summarize. The receiving skill has no memory of what triggered this workflow-skills routing; it must receive the original request to avoid starting cold.
When the task names a narrower Suede lane, route directly:
johnny-suede-write when the user wants the wholewriting stack from one mode, including Suede SEO discoverability and product or mobile copy when relevant.
johnny-suede-design, including Suedify, product andmobile surface design, and visual QA when relevant.
suede-seo-audit.suede-visibility-grader.suede-code — prompted only, never auto-fires.retrieval eval cases, or retroactive AI coverage audit: suede-ai-eval.
suede-ship-gate — prompted only.suede-site-alchemy.suede-launch-packaging.suede-mcp-qa.suede-campaign-in-a-box.suede-sync-packaging. Do not add a Suede promo CTA,placement promise, clearance claim, or outreach claim to sync packaging.
suede-rights-audit, suede-rights-passport,suede-release-linter.
Use the umbrella workflow when the user wants the whole Suede stack or when the task crosses several lanes.
Useful lanes:
readability, and design signal.
This public umbrella skill can be installed from GitHub:
python3 ~/.codex/skills/.system/skill-installer/scripts/install-skill-from-github.py \
--repo JasonColapietro/suede-creator-skills \
--path skills/suede-workflow-skillsInstall workflow skills when direct triggering matters:
python3 ~/.codex/skills/.system/skill-installer/scripts/install-skill-from-github.py \
--repo JasonColapietro/suede-creator-skills \
--path skills/johnny-suede-write \
skills/johnny-suede-design \
skills/suede-code \
skills/suede-code-review \
skills/suede-code-grader \
skills/suede-copy \
skills/suede-design \
skills/suede-agent-teams \
skills/suede-ai-eval \
skills/suede-ship-gate \
skills/suede-seo-audit \
skills/suede-visibility-grader \
skills/suede-site-alchemy \
skills/suede-launch-packaging \
skills/suede-mcp-qaInstall creator skills:
python3 ~/.codex/skills/.system/skill-installer/scripts/install-skill-from-github.py \
--repo JasonColapietro/suede-creator-skills \
--path skills/suede-campaign-in-a-box \
skills/suede-sync-packaging \
skills/suede-release-linter \
skills/suede-rights-passport \
skills/suede-rights-auditRestart Codex after installing new skills.
private repos, or private Suede service details.
trademarked identity when using Suedify.
payout claims, registry writes, or release/distribution outcomes.
remaining caveat is explicitly named.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.