onescience-coder — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited onescience-coder (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
如果用户只是要求“只告诉我技能路线”“先不要写代码”“先做规划”“先看怎么走”,或当前请求尚未授权实现代码,本 skill 不应继续做 DataPipe、模型或配置方案设计。
此时应返回上游路由语义:
onescience-workflowonescience-roleonescience-coder 只能作为未来执行入口,不是当前下一跳不要在这种情况下读取 datapipe / model / contract 卡片,也不要输出实现策略、文件落点或测试计划。
paper_repro_handoff=true、task_method=paper2code 或 domain_task_family=paper-reproduction,只把 task_description_content 或 task_description_path 指向的 coder_task_description.md 作为论文复现编码任务输入;不要再读取 reproduction_spec.md 来补齐任务细节。若 coder_task_description.md 明显缺少实现必需信息,应报告任务描述不完整并要求上游重新生成,而不是自行综合两份文档。coder_reference_mode=assets_only,不要读取 ./references/workflow.md,直接按交接摘要和 coder_task_description.md 读取 ./assets/ 下的模型卡、数据卡和组件契约。assets_only 约束,再读 ./references/workflow.md,理解 OneScience 的整体实现路径。{onescience_path} 变量指代,后续使用卡片时,若需要该路径则相应替换./references/first_round_guide.md./references/second_round_guide.md./assets/models/model_index.md./assets/datapipes/datapipe_index.md./assets/contracts/component_index.mdtool_family=single-cell、AnnData、Scanpy 或 scvi-tools 时,按需使用 ./assets/bio_single_cell_tools/ 下的脚本资产;这些是实现层资产,不从 onescience-role/bio_domain/.../scripts 读取新入口./assets/bio_workflow_templates/./assets/bio_model_templates/ 下的 handoff 模板./assets/bio_molecular_templates/ 与 ./assets/bio_molecular_tools/./assets/bio_population_templates/ 与 ./assets/bio_population_tools/./assets/bio_cell_imaging_templates/ 与 ./assets/bio_cell_imaging_tools/./assets/bio_table_templates/ 与 ./assets/bio_table_qc_tools/./assets/bio_protocol_templates/./assets/bio_knowledge_templates/ 与 ./assets/bio_report_templates/./assets/bio_lab_quality_tools/*_parameter_policy.md,再使用:./assets/contracts/mace_parameter_schema.json 或 ./assets/contracts/uma_parameter_schema.json./assets/contracts/mace_config_builder.py 或 ./assets/contracts/uma_hydra_override_builder.py./assets/contracts/material_config_validator.pyrequired_chain=[onescience-coder, onescience-runtime] 或 final_execution_skill=onescience-runtime,则当前任务在代码完成后仍未结束;必须继续把任务交接给 onescience-runtimechain_continuation_required=true,不要把“代码已完成”误判为“整条任务链已完成”onescience-runtime 的 diagnose 阶段;需要运行或日志证据时由 runtime 统一提交、同步和分类代码生成后的 review 是静态需求一致性审查,不是运行校验、测试执行、日志排查或 debug。
若上游交接包含 coder_static_review_required=true,静态 review 是代码生成完成前的硬性门槛;不能只说“建议 review”,也不能省略 review 结果直接结束。
执行方式:
onescience-runtime。静态需求一致性 review 结果 小节,列出已核对项、已修正偏差和仍需确认项;缺少该小节时,不算完成代码生成。至少给出:
如果进入编码阶段,再补充:
如果上游已要求续传到 onescience-runtime,还必须补充:
next_action=onescience-runtimechain_continuation_required=trueruntime_handoff:至少包含本地脚本路径或入口文件、期望 execution_mode、access_mode、可选 execution_channelsubmission_authorized=true 与 authorization_scopeonescience-coder -> onescience-runtime 时,把代码完成误判为任务完成runtime 时省略 next_action、chain_continuation_required 或 runtime_handoffcase 目录时,才把生成文件固定写入 case~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.