repo-scaffold — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited repo-scaffold (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use this skill to create the repo foundation that lets product, architecture, implementation, verification, and operations stay connected. It is broader than agentsmd-scaffold; it may include AGENTS.md, but also specs, tests, CI, config, release, and runbook structure.
Before adding files, inspect the repo for existing equivalents:
rg --files -g 'AGENTS.md' -g 'CONTRIBUTING.md' -g 'README*' -g 'pyproject.toml' -g 'package.json' -g 'go.mod' -g 'Cargo.toml' -g '.github/workflows/*' -g 'docs/**' -g 'specs/**' -g 'tests/**'Reuse existing conventions. Do not create parallel docs/, spec/, planning/, or test/ trees when the repo already has a standard location.
Add only the layers needed for the repo:
| Layer | Typical Files |
|---|---|
| Product and specs | specs/PRODUCT.md, specs/TECH.md, docs/adr/ |
| Agent context | AGENTS.md, scoped AGENTS.md, local skill notes |
| Source layout | language-specific src/, pkg/, cmd/, app/, lib/ |
| Tests | tests/, fixtures, golden snapshots, e2e harness |
| CI | .github/workflows/ci.yml, lint/typecheck/test jobs |
| Config | .env.example, config schema, secret inventory |
| Release | CHANGELOG.md, release checklist, versioning notes |
| Operations | docs/runbooks/, SLO and incident templates |
For planning:
existing_foundation:
missing_layers:
proposed_tree:
files_to_create_or_update:
verification_commands:For implementation, finish by running the repo's validation command and, when available, the scaffold-specific lint or generated-file check.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.