chezmoi — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited chezmoi (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
chezmoi diff or chezmoi cat <file> before any applying.~) - Your actual dotfiles (destination state)~/.local/share/chezmoi/) - Chezmoi's managed files (source state)Chezmoi encodes file attributes in filenames:
dot_bashrc → ~/.bashrcprivate_dot_netrc → ~/.netrc (restricted permissions)executable_dot_local/bin/script → ~/.local/bin/script (executable)~/.local/share/chezmoi/
├── .chezmoiroot # Root directory specifier
└── home/ # $HOME directory
├── .chezmoidata/ # Custom template data
├── .chezmoiexternals/ # External resource config
├── .chezmoiscripts/ # Script directory
├── .chezmoitemplates/ # Reusable partial templates
├── .chezmoi.toml.tmpl # Config template (prompts during init)
├── .chezmoiremove.tmpl # Patterns of files to remove on apply
├── .chezmoiignore # Ignore patterns
└── .chezmoiversion # Minimum version specifier
.chezmoi* files and directories control chezmoi behavior.dot_, private_, .tmpl, etc)..chezmoiscripts/ run during apply. Format: run_[once_|onchange_][before_|after_]<order>-<name>.<ext>[.tmpl]chezmoi, variables, and functions.chezmoiexternals/ which is fetched from URLs, archives, and git repositories~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.