skill-composer — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited skill-composer (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Orchestrate complex workflows by chaining multiple skills into validated execution DAGs. This skill discovers applicable skills, resolves dependencies, validates compatibility, presents execution plans, and manages skill-to-skill context passing. Use when a task requires 2+ skills chained together, parallel skill execution, or conditional branching between skills. Invoke the single skill directly when it can handle the request alone, or for simple sequential invocation that needs no dependency management.
Core principle: Minimize composition overhead. Prefer simple 2-3 skill chains. Add only skills directly needed or "nice to have" additions without explicit user request.
| Signal | Load These Files | Why |
|---|---|---|
| checking skill chain compatibility and input/output type matching | compatibility-matrix.md | Loads detailed guidance from compatibility-matrix.md. |
| choosing sequential vs parallel composition; chain length limits | composition-patterns.md | Loads detailed guidance from composition-patterns.md. |
| composition walkthroughs: feature+tests, debug+docs, parallel quality checks, research-driven builds | examples.md | Loads detailed guidance from examples.md. |
| selecting a proven composition pattern; troubleshooting compositions | skill-patterns.md | Loads detailed guidance from skill-patterns.md. |
Goal: Analyze the task and find applicable skills.
Step 1: Analyze the user's request
Identify:
Step 2: Discover available skills
Before building any DAG, scan skills/*/SKILL.md for available skills:
python3 ${CLAUDE_SKILL_DIR}/scripts/discover_skills.py ./skillsReview the discovered skills. Categorize by type (workflow, testing, quality, documentation, code-analysis, debugging) with dependency metadata.
Step 3: Select skills (Apply minimum-skills principle)
Choose only skills directly needed for the stated goals. This prevents over-composition and unnecessary failure points:
Cross-reference selections against references/compatibility-matrix.md to confirm chaining is valid before proceeding.
Gate: Task goals identified. Available skills indexed. Selected skills directly address stated goals with no extras. Proceed only when gate passes.
Goal: Build a validated execution DAG.
Step 1: Build the DAG
Construct the execution DAG as a JSON structure with nodes (skills) and edges (dependencies) based on the task analysis:
python3 ${CLAUDE_SKILL_DIR}/scripts/build_dag.py skill-index.json task-description.jsonStep 2: Validate the DAG (MANDATORY before execution)
ALWAYS validate the execution graph is acyclic before moving to execution. Validation checks:
references/compatibility-matrix.md)If validation fails, fix the issue and re-validate. Common fixes:
Step 3: Present the execution plan (Dry run is MANDATORY)
ALWAYS show the execution plan and get user confirmation before running skills. This prevents wasting time on composition errors:
=== Execution Plan ===
Phase 1 (Sequential):
-> skill-name
Purpose: [what it does in this context]
Output: [what it produces]
Phase 2 (Parallel):
-> skill-a
Purpose: [what it does]
Input: [from Phase 1]
-> skill-b
Purpose: [what it does]
Input: [from Phase 1]
Phase 3 (Sequential):
-> skill-c
Purpose: [what it does]
Input: [from Phase 2]
Skills: N | Phases: N | Parallel phases: N
Proceed? [Y/n]Gate: DAG is acyclic. All skills exist. Input/output types are compatible. Topological ordering is valid. User has seen the plan. Proceed only when gate passes.
Goal: Run skills in topological order, passing context between them.
Step 1: Execute each phase
For sequential phases:
For parallel phases:
Step 2: Pass context between skills
ALWAYS verify output/input compatibility between chained skills before passing context:
references/compatibility-matrix.md)Step 3: Report progress
After each phase completes, report:
Show command output rather than describing it. Be concise but informative.
Step 4: Handle failures during execution
ALWAYS catch skill failures and determine if remaining chain can continue. If a skill fails mid-chain:
Skill failed: [skill-name]
Phase: N
Error: [error message]
Downstream impact: [list blocked skills]
Continuing branches: [list unaffected skills]
Recovery options:
1. Fix error and retry
2. Skip skill and continue (if non-critical)
3. Abort entire workflowGate: All phases executed. All skill outputs captured. Context passed successfully between all transitions. Proceed only when gate passes.
Goal: Collect results and clean up.
Step 1: Generate results summary
=== Composition Results ===
Execution Summary:
Total phases: N
Skills executed: N
Duration: X minutes
Phase Results:
Phase 1: [skill-name] - [status]
Output: [summary]
Phase 2: [skill-a] - [status]
[skill-b] - [status]
Output: [summary]
Phase 3: [skill-c] - [status]
Output: [summary]
Final Output:
[Key deliverables with file paths]Step 2: Clean up temporary files
Remove temporary files at task completion. Keep only files explicitly needed for final output:
/tmp/skill-index.json/tmp/execution-dag.jsonGate: Results reported. Temporary files cleaned up. Composition complete.
Cause: Skills reference each other cyclically in the DAG Solution:
Cause: Output type from one skill does not match expected input of the next Solution:
references/compatibility-matrix.md for valid chainsCause: A skill in the chain encountered an error Solution:
Cause: Referenced skill does not exist or name is misspelled Solution:
${CLAUDE_SKILL_DIR}/references/composition-patterns.md: Proven multi-skill composition patterns with duration estimates${CLAUDE_SKILL_DIR}/references/compatibility-matrix.md: Skill input/output compatibility and valid chains${CLAUDE_SKILL_DIR}/references/skill-patterns.md: Common skill patterns with sequential/parallel decision trees~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.