step-through — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited step-through (Agent Skill) and scored it 92/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 2 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 2 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Take a long enumerated response and walk through it interactively, one item at a time, with a decision per item — and learn the user's per-severity habits over sessions.
_On startup, use the Read tool to load ~/.claude/skills/step-through/preferences.md. If missing, treat as first-run (see First-time detection below)._
Defaults when no preferences exist:
concise — one paragraph plus 1–2 references on dive deeperyes — print the outline before startingyes — append decisions to sessions/<date>.mdmost-recent — most recent enumerated assistant messagedestructive-only — confirm before file deletes / branch ops / pushes / external posts; everything else proceedsyes — when a session is stopped mid-way, save resume state so the next invocation can pick up where it left off_Do NOT pre-load anything on startup. The skill works against the current conversation's recent assistant messages. Run Bash/Read only when the user picks "dive deeper" or "take action" on a specific item — at that point, fetch only what's needed for that item._
Check $ARGUMENTS:
~/.claude/skills/step-through/preferences.md AND feedback-journal.md AND sessions/, confirm, stop/step-through — Walk through a long enumerated response item-by-item
Usage:
/step-through Walk through the most recent enumerated response
/step-through --filter blockers Only walk through items in that section/severity
/step-through --start 3 Resume from item N
/step-through --from "<hint>" Pick a different message by short description
/step-through resume Continue the most recent stopped walkthrough
/step-through feedback Rate the last walkthrough (improves future defaults)
/step-through config Set preferences
/step-through reset Clear preferences + feedback journal + sessions
/step-through help This help
Per-item options:
Dive deeper Pull code / docs / context to better understand
Take action Edit, run, research, or fix right now
Note & defer Capture decision (e.g. "address with AIS-XXXX"), move on
Skip Drop without action
Stop End the walkthrough, summarise
Examples:
/step-through After a long PR review
/step-through --filter blockers Only critical items
/step-through --start 7 Resume mid-list
Current preferences:
(loaded from ~/.claude/skills/step-through/preferences.md)Use AskUserQuestion to collect 5 preferences in one batch:
concise (one paragraph + 1–2 refs) vs thorough (open files, web, full context)yes, always show outline vs skip, jump to item 1yes, write to sessions/<date>.md vs no, summary in chat onlyauto: most-recent enumerated message vs always ask which messagedestructive only (file deletes, pushes, external posts) vs every action (confirm any edit/command)Save to ~/.claude/skills/step-through/preferences.md in this format:
# /step-through preferences
Updated: YYYY-MM-DD
## Defaults
- default-depth: concise
- show-outline: yes
- persist-session-log: yes
- auto-pick-source: most-recent
- action-confirmation: destructive-only
- resume-on-stop: yes
## Profile (optional — edit freely)
- preferred severity to start with: blockers
- usual filter: none
- typical action style: minimal-edit, prefer linking a Linear ticket over inline fix
## Learned
- (populated by feedback over time — e.g. "follow-up severity → defer by default")After save, print a one-line summary: Saved. /step-through will use these defaults from now on.
Delete:
~/.claude/skills/step-through/preferences.md~/.claude/skills/step-through/feedback-journal.md~/.claude/skills/step-through/sessions/ (entire directory if exists)~/.claude/skills/step-through/resume-state.md (if exists)Confirm: All cleared. Starting fresh next time.
If no preferences file exists, show a warm one-liner (do not block):
First time using/step-through? I'll walk you through the most recent long response one item at a time. After your first walkthrough, run/step-through feedbackso I can learn your defaults. Or run/step-through configfirst to tune behaviour.
Then proceed with defaults.
Before anything else:
preferences.md — carry Defaults, Profile, and Learned forward into the session.feedback-journal.md if it exists — scan for any "Signal" lines that match the current source (e.g. severity terminology, source style). These quietly bias the per-item pre-selection in step 4b.--filter, --start, or --from are present in $ARGUMENTS, parse them now.If any file fails to read, continue silently with defaults — never block on missing learning state.
Default behaviour: the most recent assistant message in this conversation that contains an enumerated list. Look for any of:
1., 2., …) at line start### N. Something or 🔴 Blockers / 🟠 Major / 🟡 Follow-upIf --from "<hint>" is set, scan back for an assistant message whose contents loosely match the hint (substring or theme) and use that.
If preference auto-pick-source is always-ask, list up to 3 candidate messages with one-line summaries and ask which one to use.
If nothing enumerable is found in recent context: stop and tell the user — I can't see a long enumerated response in this conversation. Paste it, or tell me which message to use. Do not fabricate items.
Extract a structured list. For each item capture:
index — 1-based position in the listseverity — if the source uses sections like Blockers / Major / Follow-up / Nice-to-have, capture the section as severity. Otherwise leave blank.title — short label (first line / heading)body — the full text of the item (verbatim, do not paraphrase)references — any path/to/file.ts:LN citations, URLs, or doc links found in the bodyIf --filter <severity> is passed (e.g. blockers, major, follow-up), keep only matching items. Match case-insensitively against the section the item came from.
If --start <n> is passed, drop items with index < n.
Print a single compact outline so the user knows the scope:
14 items found in the last response. Walking through:
1. [BLOCKER] Client Sentry init missing environment + release
2. [BLOCKER] global-error.tsx was deleted
3. [BLOCKER] Triple Sentry ingestion via structuredLog
…Titles only — never reproduce the full bodies here. Then say one line: Starting with item 1. and move on (no permission prompt — the user invoked the skill).
For each item in order:
#### 4a. Present the item
Print the item exactly as it appeared in the source response — verbatim body, references included. Add one header line:
Item N of M — [SEVERITY] — TitleDo not rewrite, summarise, or "improve" the item text on first presentation. The user already chose to walk through this content as-is.
#### 4b. Ask what to do — single AskUserQuestion
Use AskUserQuestion with these 5 fixed options (in this order):
Header: Item N of M.
Pre-selection logic (apply in priority order, top wins):
Learned has a per-severity rule matching this item's severity, pre-select that.#### 4c. Execute the choice
Read for paths, Bash(git *) for blame/log if relevant, WebFetch for URLs in the item, Grep/Glob for symbol lookups.default-depth preference (concise vs thorough).Edit/Write for code, Bash for commands, WebSearch/WebFetch for verification.action-confirmation: every, confirm in chat before any edit/command. If destructive-only, confirm only before file deletes, branch operations, pushes, or external posts. Auto mode does not bypass destructive-only confirmation.Note? — capture the user's reply (or accept empty) and move on.resume-on-stop: yes, write resume state (see step 6) before summarising.#### 4d. Track the decision
Maintain an in-memory record per item:
{ index, severity, title, decision: "deeper|action|defer|skip", note?: string, action_summary?: string }If persist-session-log: yes, also append to ~/.claude/skills/step-through/sessions/YYYY-MM-DD-HHMM.md after each decision (incremental write, not at the end). Header line on first write should include the source — message hash, date, and total item count.
When the loop ends (all items processed, or user picked Stop), print one compact block:
Walkthrough complete — N items.
Action taken: [list of indices + 1-line action summaries]
Deferred: [indices + notes]
Skipped: [indices]
Not reached: [indices, if Stop was used]Then ask one follow-up question via AskUserQuestion:
Do not auto-create tickets/PRs without explicit confirmation.
If the user picked Stop and resume-on-stop: yes, write ~/.claude/skills/step-through/resume-state.md with: source identifier, processed indices, remaining indices, decisions so far. Tell the user: Run /step-through resume to continue from item N.
If the loop completed normally, delete any stale resume-state.md.
End with one short line:
When you're done, run /step-through feedback — even one rating helps me sharpen per-severity defaults for next time.Do not ask interactively here. Feedback is opt-in via the dedicated subcommand.
When invoked as /step-through feedback:
sessions/YYYY-MM-DD-HHMM.md). If none, say No recent walkthrough found. and stop.AskUserQuestion (4 questions, one batch):yes, smooth / too slow / too fast / wrong defaultsdefer by default / skip by default / dive deeper first / variesdive deeper first / take action immediately / defer with ticket / varies~/.claude/skills/step-through/feedback-journal.md:## {session slug} — {date}
- Pace: {smooth|too-slow|too-fast|wrong-defaults}
- Wrong calls: {indices + user text}
- Follow-up default: {answer}
- Blocker default: {answer}
- Signal: {one-line generalization, e.g. "user defers all follow-ups, dives deeper on blockers"}## Learned in preferences.md as a rule like follow-up severity → defer by default. Mention once: Noticed you consistently defer follow-up items. Saved as standing default. These rules feed step 4b's pre-selection.## Demoted: {rule} — too unstable). Never leave stale rules.disable-model-invocation: true makes the skill user-triggered, but file deletes, branch ops, pushes, and external posts always require an explicit yes — auto mode does not bypass that.preferences.md or feedback-journal.md can't be read, continue with built-in defaults — never block on missing learning state.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.