agent-rules — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited agent-rules (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Generate and maintain AGENTS.md files following the agents.md convention. AGENTS.md is FOR AGENTS, not humans.
| Script | Purpose |
|---|---|
scripts/generate-agents.sh PATH | Generate AGENTS.md files |
scripts/validate-structure.sh PATH | Validate structure compliance |
scripts/check-freshness.sh PATH | Check if files are outdated |
scripts/verify-content.sh PATH | Verify documented files/commands match codebase |
scripts/verify-commands.sh PATH | Verify documented commands execute |
scripts/score-agents.sh PATH | Grade AGENTS.md quality, worst-first |
scripts/detect-project.sh PATH | Detect language, version, build tools |
scripts/detect-scopes.sh PATH | Identify directories needing scoped files |
scripts/extract-commands.sh PATH | Extract commands from build configs |
scripts/extract-ci-rules.sh PATH | Extract CI quality gates and version matrix |
scripts/extract-architecture-rules.sh PATH | Extract module boundaries |
scripts/extract-adrs.sh PATH | Extract architectural decision records |
scripts/extract-github-rulesets.sh PATH | Extract GitHub rulesets and merge rules |
See references/scripts-guide.md for full options.
detect-project.sh + detect-scopes.sh to identify stacks and subsystemsextract-commands.sh, extract-ci-rules.sh, etc. to gather factsgenerate-agents.sh with --style=thin (default) or --verboseverify-content.sh + verify-commands.sh -- MANDATORY before doneUse --update to preserve human-curated content outside <!-- GENERATED --> markers.
ai-tool-compatibility.md)| File | Contents |
|---|---|
verification-guide.md | Verification steps, design principles, anti-bloat |
scripts-guide.md | Script options, validation checklist |
quality-rubric.md | Quality grading rubric |
ai-tool-compatibility.md | 16-agent compatibility matrix |
output-structure.md | Root/scoped sections |
git-hooks-setup.md | Hook framework detection and setup |
examples/ | Complete examples |
ai-contribution-guidelines.md | "3 Cs" framework for AI contributions |
directory-coverage.md | Scoped-file coverage rationale |
Root: assets/root-thin.md (default) or root-verbose.md. Scoped: assets/scoped/, one per stack (Go/PHP/Python/TYPO3/Symfony/Oro/CLI/TS/skill-repo).
Go, PHP (Composer/Laravel/Symfony/TYPO3/Oro), TypeScript (React/Next/Vue/Node), Python (pip/poetry/ruff/mypy), Skill repos, Hybrid (auto-scoping).
agent-harness-skill — agent-readiness harness (CI enforcement).skill-repo-skill — skill-repo structure (plugin.json, licensing, releases).~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.