contexts — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited contexts (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Auto-router for pre-implementation context gathering. Classify the input as codebase-oriented, doc-oriented, or both; invoke the appropriate workflow; emit a detected: acknowledgement as the first output line.
Apply:
NOT apply:
First output line before ANY work:
detected: <mode> — scope=<paths|libs|both> sources=<brief summary>Mode values: code-ref, doc-ref, both, ambiguous.
For both mode, also append: (sequential dispatch: codebase first, then external)
First-match wins. Check in order: both must come before leaf modes so mixed-signal inputs are reachable.
| Priority | Mode | Minimum condition |
|---|---|---|
| 1 | both | Repo-local signal (path, glob, symbol, or module) AND external signal (library, framework, SDK, API, CLI, or service name) both present and non-trivial |
| 2 | code-ref | Repo-local signal present; no external signal |
| 3 | doc-ref | External signal present; no repo-local signal |
| 4 | ambiguous | Neither signal cleanly detected, OR signals present but neither dominant |
Worked examples:
"How does our /autoresearch skill use LangGraph's interrupt for HITL pauses?" → repo signal + external signal → both"Refactor claude/skills/contexts/SKILL.md" → repo signal only → code-ref"Latest Pydantic v2 model_validator signature" → external signal only → doc-ref"Give me context on routing" → no concrete signal → ambiguous → gate firesFire AskUserQuestion (single-select, NEVER multiSelect) when classifier returns ambiguous OR when both signals are present but one is dominant and the mode is unclear:
code-ref, doc-ref, both(Recommended) on the closest classifier match`code-ref`: Invoke codebase exploration workflow. Emit 8-section output (Task Understanding, Architecture Context, Pattern Context, Tooling Context, Dependency Map, Critical Files Summary, Constraints & Considerations, Recommended Next Steps).
`doc-ref`: Invoke external research workflow. Walk the 5-tier source ladder (Official docs → API refs → Books/papers → Tutorials → Community). Emit source-cited claims with confidence labels.
`both` (sequential):
Note: sequential dispatch roughly doubles wall-clock time versus a single mode. Emit (sequential dispatch: codebase first, then external) in the detected: line so the user can anticipate latency.
detected: acknowledgement line — it is LOAD-BEARING; downstream parsers and users depend on itcode-ref or doc-ref before both in the classifier — both becomes unreachable under first-match-winsAskUserQuestion with multiSelect: true — always single-select per axis/contexts code-ref, /contexts doc-ref, or /contexts both bypasses the classifier entirely and dispatches directly to that mode~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.