c4-code — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited c4-code (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
resources/implementation-playbook.md.functionName(param1: Type, param2: Type): ReturnTypeClassNameOptional Mermaid diagrams for complex code structures. Choose the diagram type based on the programming paradigm. Code diagrams show the internal structure of a single component.
Use classDiagram for OOP code with classes, interfaces, and inheritance:
---
title: Code Diagram for [Component Name]
---
classDiagram
namespace ComponentName {
class Class1 {
+attribute1 Type
+method1() ReturnType
}
class Class2 {
-privateAttr Type
+publicMethod() void
}
class Interface1 {
<<interface>>
+requiredMethod() ReturnType
}
}
Class1 ..|> Interface1 : implements
Class1 --> Class2 : uses
### Functional/Procedural Code (Modules, Functions)
For functional or procedural code, you have two options:
**Option A: Module Structure Diagram** - Use `classDiagram` to show modules and their exported functions:
title: Module Structure for [Component Name]
classDiagram namespace DataProcessing { class validators { <<module>> +validateInput(data) Result~Data, Error~ +validateSchema(schema, data) bool +sanitize(input) string } class transformers { <<module>> +parseJSON(raw) Record +normalize(data) NormalizedData +aggregate(items) Summary } class io { <<module>> +readFile(path) string +writeFile(path, content) void } }
transformers --> validators : uses transformers --> io : reads from
**Option B: Data Flow Diagram** - Use `flowchart` to show function pipelines and data transformations:
title: Data Pipeline for [Component Name]
flowchart LR subgraph Input A[readFile] end subgraph Transform B[parseJSON] C[validateInput] D[normalize] E[aggregate] end subgraph Output F[writeFile] end
A -->|raw string| B B -->|parsed data| C C -->|valid data| D D -->|normalized| E E -->|summary| F
**Option C: Function Dependency Graph** - Use `flowchart` to show which functions call which:
title: Function Dependencies for [Component Name]
flowchart TB subgraph Public API processData[processData] exportReport[exportReport] end subgraph Internal Functions validate[validate] transform[transform] format[format] cache[memoize] end subgraph Pure Utilities compose[compose] pipe[pipe] curry[curry] end
processData --> validate processData --> transform processData --> cache transform --> compose transform --> pipe exportReport --> format exportReport --> processData
### Choosing the Right Diagram
| Code Style | Primary Diagram | When to Use |
| -------------------------------- | -------------------------------- | ------------------------------------------------------- |
| OOP (classes, interfaces) | `classDiagram` | Show inheritance, composition, interface implementation |
| FP (pure functions, pipelines) | `flowchart` | Show data transformations and function composition |
| FP (modules with exports) | `classDiagram` with `<<module>>` | Show module structure and dependencies |
| Procedural (structs + functions) | `classDiagram` | Show data structures and associated functions |
| Mixed | Combination | Use multiple diagrams if needed |
**Note**: According to the [C4 model](https://c4model.com/diagrams), code diagrams are typically only created when needed for complex components. Most teams find system context and container diagrams sufficient. Choose the diagram type that best communicates the code structure regardless of paradigm.
## Notes
[Any additional context or important information]
When analyzing code, provide:
## Limitations
- Use this skill only when the task clearly matches the scope described above.
- Do not treat the output as a substitute for environment-specific validation, testing, or expert review.
- Stop and ask for clarification if required inputs, permissions, safety boundaries, or success criteria are missing.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.