craft-garnish — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited craft-garnish (Agent Skill) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Reference for Garnish, Craft CMS's built-in JavaScript UI framework. Covers the class system, UI widgets, drag interactions, form components, accessibility helpers, and integration with Craft's CP.
This skill is scoped to Garnish itself — the JavaScript library at src/web/assets/garnish/. For PHP-side plugin development (elements, controllers, services), see the craftcms skill. For CP template markup that Garnish widgets attach to, see the craftcms skill's cp.md reference.
src/web/assets/garnish/src/ in the Craft CMS repositoryUse WebFetch on Craft's class reference (https://docs.craftcms.com/api/v5/) when looking up PHP-side asset bundle registration.
.on() directly instead of this.addListener() — listeners added via jQuery won't auto-clean on destroy(), causing memory leaks.this.base() when overriding destroy() — parent cleanup (listener removal, event teardown) gets skipped.click instead of activate event on non-<button> elements — activate handles both click and keyboard (Space/Enter), making the UI accessible.UiLayerManager by binding ESC directly — use Garnish.uiLayerManager.registerShortcut(Garnish.ESC_KEY, callback) so escape routes through the layer stack correctly.Garnish.ESC_KEY, Garnish.RETURN_KEY, etc. — constants are self-documenting and consistent.CpAsset dependency chain.destroy() when removing widgets — orphaned listeners accumulate, especially in slideouts and live preview where DOM is repeatedly created/destroyed.import Garnish from 'garnishjs' resolves to window.Garnish via webpack externals; bundling it duplicates 134KB.Garnish.Menu instead of Garnish.CustomSelect — Menu is an alias kept for BC only.Garnish.escManager or Garnish.shortcutManager instead of Garnish.uiLayerManager — the newer manager provides layer-aware keyboard routing that respects the modal/menu stack.Read the relevant reference file(s) for your task. Multiple files often apply together.
Task examples:
class-system.md + ui-widgets.mddrag-system.md + class-system.mdclass-system.md + integration.mdui-widgets.md + integration.mdutilities.md + class-system.mdui-widgets.md (HUD section)ui-widgets.md (Select section)integration.mdintegration.md (Element Index JS Loading)integration.md (Element Index JS Loading — Vite doesn't work for element index classes)utilities.md (ARIA & Focus section)integration.md + class-system.mdintegration.md (Form Widgets section)integration.md (Form Widgets section)| Reference | Scope |
|---|---|
references/class-system.md | Garnish.Base, inheritance (extend/init/base), events (on/off/trigger), listeners (addListener/removeListener), settings, namespacing, enable/disable, destroy lifecycle |
references/ui-widgets.md | Modal, HUD, DisclosureMenu, MenuBtn, SelectMenu, CustomSelect, ContextMenu, Select — constructor args, settings/defaults, methods, events, ARIA behavior |
references/drag-system.md | BaseDrag, Drag, DragSort, DragDrop, DragMove — class hierarchy, settings/defaults, events, helper system, insertion points, scroll handling |
references/utilities.md | Garnish namespace object, key constants, custom jQuery events (activate, textchange, resize), ARIA/focus management, geometry/hit testing, animation, form helpers, detection |
references/integration.md | GarnishAsset PHP bundle, webpack externals, loading sequence, Craft.* class pattern, Twig JS blocks, form widgets (NiceText, CheckboxSelect, MultiFunctionBtn, MixedInput) |
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.