local-copilot — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited local-copilot (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use this skill when adding, debugging or extending the ableton-mind local LLM feature.
src/llm/config.ts, src/llm/tools.ts, src/llm/agent.ts, src/llm/server.ts and src/cli/chat.ts.tests/llm-local-copilot.test.ts and the latest relevant QA report._workspace/tdmcp-compatible-features.md for deferred tdmcp-inspired items.ask, model/backend, safety tier, docs, or QA.safe). Use explicit --write for simple mutations and --creative for recipes/browser load.tdmcp.src/llm/tools.ts over new schema-conversion dependencies.ToolDefinition handlers, not duplicate Ableton business logic.docs/pt/.Run focused checks first:
npm run typecheck
npx vitest run tests/llm-local-copilot.test.tsFor broader changes, add:
npm run lint
npm run test
npm run buildLive/Ollama validation is optional unless the task changes runtime connectivity. If skipped, report it explicitly.
ableton-mind ask --read-only "What is in this set?" with Ollama reachable and bridge connected.ableton-mind chat --no-ollama --no-open opens the local UI even when Live is closed; live tool calls return a bridge-offline error.safe; --write switches to standard; --creative exposes recipes/browser load.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.