complete-new-work — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited complete-new-work (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
End-to-end Gyst delivery workflow for the workspace repo. Requires the gyst MCP server with a valid GYST_API_TOKEN.
workspacePath if auto-detection fails).GYST_WORKSPACE in ~/.cursor/mcp.json.projectId.status !== "Completed".ticketNumber ascending.| Key | Status | Title |
|-----|--------|-------|
| GYST-5 | Idea | ... |Include project name(s) and ticketKeyPrefix context.
Do not implement, commit, or push until the user confirms.
Ask the user to choose:
If the list is empty, report that and stop.
Process confirmed tickets one at a time.
ticketStatuses.In Progress (must be valid for the project).`add_ticket_ai_dev_comment` with Completed and Testing sections.
Do not set status to Completed yet if a commit is still required.
Only when the user confirmed work in Phase 2:
GYST-4: Expand MCP tooling.) so dev-link sync works.main.CompletedticketId| Step | Tool |
|---|---|
| Projects for this repo | get_projects_for_current_repo |
| Open tickets | list_tickets + filter status !== "Completed" |
| Read ticket | get_ticket_by_key |
| Start / close | update_ticket_status |
| Progress notes | add_ticket_ai_dev_comment |
| Link commits | sync_ticket_dev_links |
Server: `gyst` in Cursor MCP config. Generate token at Gyst → Settings → Cursor MCP.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.