ln-647-configuration-boundary-auditor — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited ln-647-configuration-boundary-auditor (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Paths: File paths (references/,../ln-*) are relative to this skill directory.
Type: L3 Worker
Specialized worker auditing whether configuration access has a clear architectural boundary.
ADD_SETTINGS_BOUNDARY, STOP_SCATTERED_ENV_READS, or TYPE_CONFIG_CONTRACTOut of Scope:
.env inventory, .env.example completeness, committed env files, or secrets hygieneMANDATORY READ: Load references/audit_worker_core_contract.md. Tool policy: follow host AGENTS.md MCP preferences; load references/mcp_tool_preferences.md and references/mcp_integration_patterns.md only when host policy is absent or MCP behavior is unclear.
Receives contextStore with tech stack, codebase root, output_dir, domain_mode, scan_path.
Use hex-graph first when symbol or reference analysis materially improves config-boundary findings. Use hex-line first for local code/config reads when available. If MCP is unavailable, unsupported, or not indexed, continue with built-in Read/Grep/Glob/Bash and state the fallback in the report.
Detection policy: use two-layer detection (candidate scan, then context verification); load references/two_layer_detection.md only when the verification method is ambiguous.
1) Parse context -- determine scan_root from domain-aware scope or codebase root 2) Detect config access (Layer 1)
3) Verify architecture context (Layer 2)
4) Collect findings with severity, location, action, effort, and recommendation 5) Calculate score using references/audit_scoring.md 6) Write report to {output_dir}/ln-647--{identifier}.md 7) Return summary per references/audit_summary_contract.md
What: Raw environment/config reads appear across multiple architectural layers
Detection:
process.envos.getenv, os.environos.GetenvSeverity: HIGH when domain/business logic reads env directly, MEDIUM in services, LOW in adapters
Action: STOP_SCATTERED_ENV_READS
What: Configuration is passed as raw dictionaries, strings, or primitives without a typed settings contract
Detection:
dict, Record<string, string>, Map<String,String>, or untyped config objects in service constructorsSeverity: MEDIUM by default, HIGH when security or persistence behavior depends on untyped config
Action: TYPE_CONFIG_CONTRACT
What: Lower layers decide deployment/runtime configuration instead of receiving explicit settings from the composition boundary
Detection:
Severity: HIGH for domain/persistence ownership leakage, MEDIUM for service-layer leakage
Action: ADD_SETTINGS_BOUNDARY
MANDATORY READ: Load references/audit_scoring.md.
MANDATORY READ: Load references/audit_output_schema.md. MANDATORY READ: Load references/templates/audit_worker_report_template.md.
Write JSON summary per references/audit_summary_contract.md. In managed mode the caller passes both runId and summaryArtifactPath; in standalone mode the worker generates its own run-scoped artifact path per shared contract.
Write report to {output_dir}/ln-647--{identifier}.md with category: "Configuration Boundary" and checks: scattered_env_reads, typed_settings_boundary, config_ownership_leakage.
When summaryArtifactPath is absent, write the standalone runtime summary under .hex-skills/runtime-artifacts/runs/{run_id}/evaluation-worker/{worker}--{identifier}.json and optionally echo the same summary in structured output.
Apply the already-loaded references/audit_worker_core_contract.md.
.env hygiene, committed secrets, startup validation, package health, or lifecycle readiness.ADD_SETTINGS_BOUNDARY, STOP_SCATTERED_ENV_READS, or TYPE_CONFIG_CONTRACT.Apply the already-loaded references/audit_worker_core_contract.md.
references/audit_scoring.md{output_dir}/ln-647--{identifier}.md (atomic single Write call)Version: 1.0.0 Last Updated: 2026-03-15
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.