utility-pm-skill-auditor — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited utility-pm-skill-auditor (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
<!-- PM-Skills | https://github.com/product-on-purpose/pm-skills | Apache 2.0 -->
Cross-client dispatch wrapper for the pm-skill-auditor sub-agent. Detects runtime; dispatches to the native sub-agent on Claude Code; reads agents/pm-skill-auditor.md and executes inline on non-Claude clients.
utility-pm-critic insteadutility-pm-changelog-curator (ships in Phase 4)utility-pm-release-conductor (ships in Phase 5)pm-frontmatter-doctor (v2.17+)Runtime detection step. Determine which AI client is invoking this skill.
Invoke @agent-pm-skills:pm-skill-auditor on the repo. Pass any scope arguments from $ARGUMENTS (e.g., --scope changed, --since-tag v2.15.0, --severity-floor P1). Return the sub-agent's audit report to the user.
Codex CLI, Cursor, Windsurf, Copilot, Gemini CLI, or any other client without native pm-skills plugin sub-agent support:
agents/pm-skill-auditor.mdbash scripts/pre-tag-validate.sh as canonical entry point)docs/internal/release-plans/v2.16.0/spec_pm-skill-auditor.md#cross-cutting-check-catalog$ARGUMENTSSee Sub-Agent Compatibility Matrix for the canonical cross-client status. Summary for this skill as of v2.16.0: PRODUCTION on Claude Code + Codex CLI (Codex CLI successfully invoked the validator suite via Bash + produced a layered audit report with re-derived aggregate counters); EXPERIMENTAL on Cursor / Windsurf / Copilot CLI / Gemini CLI.
The "read canonical agent definition and execute inline" pattern depends on the AI client being able to:
Most AI clients support all three. If any are unreliable on a specific client, that client falls back to manual validator invocation + manual cross-cutting checks.
agents/pm-skill-auditor.mddocs/internal/release-plans/v2.16.0/spec_pm-skill-auditor.mddocs/reference/runtime-components.mddocs/internal/release-plans/v2.16.0/spec_pm-skill-auditor.md#cross-cutting-check-catalogscripts/pre-tag-validate.{sh,ps1}references/TEMPLATE.mdreferences/EXAMPLE.md~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.