mapping-webapp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited mapping-webapp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Generate _FEATURES.md files documenting what a web app does — screens, flows, states, behavioral invariants. Companion to mapping-codebases which documents code structure.
v0.3.0: Code-first architecture. The code IS the ground truth; screenshots are supplementary verification.
_MAP.md files exist)api-credentials skill or ANTHROPIC_API_KEY env var)--code-only)# Code-only analysis (no browser needed):
python /mnt/skills/user/mapping-webapp/scripts/featuremap.py \
--app-url https://example.com --codebase /path/to/repo --code-only
# Full pipeline (code analysis + selective visual verification):
python /mnt/skills/user/mapping-webapp/scripts/featuremap.py \
--app-url https://example.com --codebase /path/to/repo
# Incremental update:
python /mnt/skills/user/mapping-webapp/scripts/featuremap.py \
--app-url https://example.com --codebase . --incremental| Flag | Default | Description |
|---|---|---|
--app-url | required | Base URL of the web app |
--codebase | required | Path to repo root (must have _MAP.md files) |
--output | <codebase>/_FEATURES.md | Output path |
--max-pages | 100 | Cap on pages to discover |
--code-only | false | Skip all vision — code analysis only |
--verify-only | false | Only run vision on already-analyzed pages |
--batch-size | auto | Pages per batch (auto-detected from environment) |
--incremental | false | Only re-process changed pages |
--viewport | 1280x720 | Screenshot viewport (WxH) |
--routes | none | Comma-separated routes or path to routes file |
--screenshots-dir | <codebase>/screenshots | Where to store PNGs |
--model | claude-sonnet-4-6 | Claude model for analysis/vision |
--dry-run / -n | false | Discover only, print sitemap |
Discovers pages from code structure, not browser crawling:
_MAP.md for page references--routes for manual seedingNo browser required for discovery.
Reads source code for each discovered page and uses Claude API (text, not vision) to generate behavioral descriptions:
_MAP.md excerpts for code contextCode-derived descriptions are usable standalone. Vision is enrichment, not requirement.
Selective visual verification for pages where it adds value:
Skipped entirely with --code-only. Run only this phase with --verify-only.
Compiles all descriptions into _FEATURES.md:
The skill auto-detects the runtime environment and adjusts batch size:
| Environment | Batch Size | Notes |
|---|---|---|
| Claude.ai container | 4 pages | Short bash timeouts |
| Claude Code on Web | 12 pages | Longer execution windows |
| Local CLI | Unbatched | Full control |
Override with --batch-size N.
Progress is checkpointed after each batch via _FEATURES_MANIFEST.json, so work survives if a conversation ends mid-pipeline.
Each run stores page hashes and descriptions in _FEATURES_MANIFEST.json. With --incremental:
Pages requiring authentication are detected during verification (redirect detection + text heuristics) and marked GATED. The skill generates step-by-step manual capture instructions in GATED_PAGES.md.
# _FEATURES.md — App Name
Generated: 2026-03-22T12:00:00+0000
App URL: https://example.com
## Feature Inventory
### Status Summary
- **Documented:** 45 pages
- Code-analyzed: 40
- Visually verified: 5
- **Gated (auth required):** 2 pages
### Page Title (`/route`)
> *Derived from source code analysis*
**What the user sees:** Prose description from code analysis.
**Interactions:**
- Button "X" → does Y
**Invariants:**
- Rule 1
**Code:** `src/page.html` :1
---_FEATURES.md is the behavioral source of truth. Combined with _MAP.md (structural):
mapping-codebases → _MAP.md (structural)mapping-webapp → _FEATURES.md (behavioral)--routes flag~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.