plan-execute — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited plan-execute (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
When the user runs /plan-execute {plan-file-path}, start the "orchestrated plan execution" workflow:
reviews/ directory, then ask Codex to inspect and fix the issues.Core principle: I do not write or edit code myself. I only do two things: review code and orchestrate Codex. All code changes, including implementation and fixes, are performed by Codex.
/plan-execute plans/my-feature-plan.mdAfter each Codex invocation, extract session_id=xxx from the script output and save it as the session ID for the current task. In later Codex calls for the same task, pass --session <id> to reuse context so Codex remembers prior implementation and fix history instead of rereading the entire codebase every time.
Read the specified plan file and understand:
CLAUDE.mdIf the plan already contains a checklist (- [ ] / - [x]), use those items as execution units. If it does not define clear steps, split the work into reasonable batches, with no more than 5 file changes per batch.
Use the /codex skill and give Codex the following instruction:
Implement the code according to the plan in {plan-file-path}.
Current execution scope: {specific step or batch description}
Requirements:
- Follow the design in the plan exactly. Do not improvise beyond it.
- Obey the Code Quality Hard Limits defined in `CLAUDE.md`.
- Single file <= 800 lines, single function <= 50 lines, nesting <= 3 levels
- Run `pnpm build` after implementation to confirm compilation succeeds
- If the plan includes a checklist, mark completed steps as `[x]`
After implementation, list all changed files and provide a summary of each change.After Codex finishes, I perform a code review. Important: I only read code and write reviews. I never directly modify source files.
Append the review to reviews/{topic}-review.md (shared with plan-review):
---
## Code Review Round {N} — {YYYY-MM-DD}
**Scope**: {code scope covered in this review}
**Build Status**: PASS / FAIL
### Issues
#### Issue 1 ({severity}): {title}
**File**: {file-path:line}
{issue description}
**Fix**: {specific fix recommendation}
...
### Verdict: NEEDS_FIX / APPROVEDIf Verdict: NEEDS_FIX, call /codex and have Codex fix the issues instead of editing them myself:
Read the latest Code Review round in {review-file-path}.
Check each issue one by one. Fix the valid issues, and explain why any disputed item is not actually a problem.
After making fixes, run `pnpm build` to confirm compilation succeeds.
List the issues that were fixed and the corresponding code changes.If Verdict: APPROVED, skip to Step 6.
After Codex applies fixes, I review again, still without editing code directly:
Verdict: APPROVEDAfter each batch is completed, ask Codex to update the checklist in the plan file (- [ ] -> - [x]). If unfinished steps remain, go back to Step 2 for the next batch. Once all work is complete, move to the wrap-up.
Report the following to the user:
| Level | Meaning | Must Fix |
|---|---|---|
| Critical | Causes runtime failures or security vulnerabilities | Yes |
| High | Violates project conventions or has obvious design flaws | Yes |
| Medium | Code quality issue that should be improved | Recommended |
| Low | Style or preference issue | Optional |
| Suggestion | Optimization suggestion | Optional |
Verdict rules:
NEEDS_FIXAPPROVED with optional improvement notesplan-review: reviews/{topic}-review.md{topic} is the plan file name without .md## Round {N} for plan review and ## Code Review Round {N} for code review~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.