hub-maintenance-workflow — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited hub-maintenance-workflow (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use this owner for Harness Hub repository work.
docs/personal-workflow-distribution.md, docs/source-projects.md, docs/skill-routing.md, capabilities/index.json, relevant skills, and tests.scripts/validate-skills.ps1 -SkipExternal, and bun run validate when TypeScript, tests, capabilities, or CLI behavior changed.effective-interact for material handoff reports.Use repo-local source records and deterministic project files instead of delegating to removed library skills:
docs/personal-workflow-distribution.md for the personal distribution rules, TODOs, and acceptance criteria.docs/source-projects.md for upstream URLs, versions, license notes, import decisions, and reference-only candidates.docs/harness-vocabulary.md for local concept boundaries when maintaining Harness Hub-owned skills, reports, or validation language.docs/workflow-source-dossier.md for lifecycle-stage comparisons across Matt Pocock skills, Superpowers, ECC, OpenSpec, Effective Interact, Vercel, retired Ralph source notes, and local docs.docs/skill-routing.md for overlap and trigger decisions.capabilities/index.json for the installable component surface.harness-hub CLI dry-runs for target-repo analyze/install/status/update/remove behavior.skill-creator for standard skill authoring and routing-evaluation details when local skills are created or changed.doc-coauthoring for durable proposals or decision records when the maintenance change needs a reviewed document.For any parallel source review, hook proposal, or lifecycle smoke split, follow workflow-router/references/orchestration-policy.md: subagents must have independent scopes, hooks stay advisory by default, and lock-backed lifecycle checks remain deterministic.
Do not rewrite imported skill bodies for local style. Do not wholesale replace local skills or the local workflow overlay with upstream text. Do not bypass lock-backed install, update, status, or remove behavior.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.