automatic-code-review — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited automatic-code-review (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Hook-driven skill that performs semantic code review after Claude finishes modifying files.
Write, Edit, or MultiEdit operation to /tmp/event-log-{SESSION_ID}.jsonlautomatic-code-reviewer agentrulesFile and reviews only the changed filesSettings in .claude/settings.json:
{
"automaticCodeReview": {
"enabled": true,
"fileExtensions": ["ts", "tsx"],
"rulesFile": ".claude/automatic-code-review/rules.md"
}
}Set "enabled": false to disable for a project.
../../agents/automatic-code-reviewer.md — Review agent (model: haiku, tools: Read, Grep, Glob) — lives at plugin root agents/../../hooks/hooks.json — Hook manifest (PostToolUse + Stop) — merged into plugin root hooks/../../scripts/automatic-code-review-plugin.sh — Shell script for logging and review triggering — lives at plugin root scripts/default-rules.md — Default semantic review rules (stays with skill)~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.