new-work — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited new-work (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Todo notes track work items as markdown files with YAML front matter capturing status, context, and progress.
Use _dev/todos/ if it exists in the repository root; otherwise ask the user where to store todo notes before creating anything. It contains two subdirectories: pending/ (active) and done/ (finished).
YYYY-MM-DD_short-kebab-slug.md, e.g. 2026-02-18_add-oauth-support.md.
YAML front matter plus a markdown body. Only status is required.
---
status: pending # pending | in progress | review | blocked | done
issue: https://github.com/org/repo/issues/123 # optional
pr: https://github.com/org/repo/pull/456 # optional
---
# Title
Overview of what this is about and why it matters.
## Key Files
- `src/relevant-file.ts` — what it does
- `src/other-file.ts:functionName()` — why it matters
## Work Items
- [ ] First thing to do
- [ ] Second thing to do
## Design Decisions
Context, constraints, or choices worth capturing.
## Decision Log
<!--
### YYYY-MM-DD — Short Decision Title
**Decision:** What was decided?
**Rationale:** Why?
-->pending/ if needed, create the date-prefixed file with status: pending, and write enough context to resume later.status; add issue/pr links when they exist; check off Work Items (- [ ] → - [x]); record significant decisions in the Decision Log.status: done and mv the file from pending/ to done/.Treat the todo as a living record for the rest of the session. Update it after any decision, newly discovered problem or requirement, issue raised/resolved, significant implementation work, or commit. When in doubt, update it.
When you form a plan — whether in response to a user request or on your own initiative — write it to the todo document rather than presenting it only in chat. The document is the persistent record; the chat is not.
To resume in a future session, use /working-on <path-to-todo> — same live-document behavior without re-creating the file.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.