utility-pm-workflow-builder — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited utility-pm-workflow-builder (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
<!-- PM-Skills | https://github.com/product-on-purpose/pm-skills | Apache 2.0 -->
This skill creates new multi-skill workflows for the pm-skills library. It produces a Workflow Implementation Packet - a draft _workflows/<name>.md file, a draft commands/workflow-<name>.md command, and the cross-cutting update checklist - in a staging area for review before promotion to canonical locations. The builder authors; it never executes a chain and it never promotes its own output.
quarterly business reviews")
("chain competitive-analysis, experiment-results, pivot-decision")
/chain run (orchestrator Mode B) proved reusable and its completionoutput suggested promoting the chain to a durable workflow; hand this skill the exact chain expression from that suggestion
/chaincommand or utility-pm-workflow-orchestrator directly
utility-pm-skill-builder,utility-pm-skill-validate, or utility-pm-skill-iterate
_workflows/<name>.mddirectly; the overlap analysis below will point you there when coverage is high
Accept the idea in any of three entry forms, all converging on the same downstream flow:
process, who runs it, and the artifact trail it should leave.
measure-experiment-results -> discover-stakeholder-summary), usually pasted from the orchestrator's completion suggestion, plus the context the run used.
If the idea is vague, ask ONE clarifying question (the recurring trigger and the final artifact), then proceed. Do not interrogate.
Scan the _workflows/ directory at run time for the current inventory (list every *.md except README.md). Never rely on a remembered count or a hardcoded list. Compare the idea against ALL existing workflows:
Kill gate (>70% coverage overlap): recommend, in order, (a) customizing the existing workflow, (b) adding a step to it, or (c) just using /chain for the occasional run. Do not proceed.
Why Gate (any meaningful overlap): ask for 2-3 specific scenarios where the existing workflows fail to produce what is needed. Do not pass the gate without that evidence or an explicit user override (record the override in the packet's Decision section).
Select and order the steps with the user. Apply the chain-expression contract's validation rules at authoring time (skills/utility-pm-workflow-orchestrator/references/PARSE-CONTRACT.md, Mode B Chain Expression Contract):
skills/<name>/SKILL.mdby EXACT name. Never approximate or auto-correct; on a miss, refuse the step and OFFER the closest real names (an offer, never a substitution).
explanation: Tier-3 maintenance skills (utility-pm-skill-*, utility-pm-release-conductor, utility-pm-changelog-curator, utility-update-pm-skills, foundation-prioritized-action-plan), dispatch skills that fan out to sub-agents (utility-pm-critic, utility-pm-workflow-orchestrator, and peers), and existing workflows (a workflow never nests a workflow). Self-reference is impossible by construction: this builder is itself Tier-3.
step's output, and what it must produce for the next. This authored handoff guidance is exactly what distinguishes a durable workflow from an ad-hoc chain; a packet without real handoffs is not ready.
Write the complete Workflow Implementation Packet to _staging/workflows/<name>/ (gitignored; the same review model as the skill builder). Never write to canonical locations.
_staging/workflows/<name>/
├── workflow.md <- draft _workflows/<name>.md
├── command.md <- draft commands/workflow-<name>.md
└── PACKET.md <- decision, overlap analysis, checklist, promotion stepsUse references/TEMPLATE.md as the packet format. The workflow draft must carry the full section inventory the current _workflows/*.md files share (see the TEMPLATE's embedded skeleton); the command draft mirrors the existing commands/workflow-*.md shape, including one literal skills/<name>/SKILL.md path per step and the $ARGUMENTS footer. Derive a linear mermaid context-flow diagram from the final sequence (step names as nodes, execution order as edges).
Present the packet and stop. The builder itself never promotes. On approval, the user (or a follow-up session) moves the drafts to their canonical paths and works the packet's Cross-Cutting Checklist, which names every count and documentation surface that adding a workflow trips, including the validator-blind .github/workflows/release.yml release-note template. The builder never edits those cross-cutting files itself.
The packet follows references/TEMPLATE.md:
_workflows/<name>.md contentcommands/workflow-<name>.md contentSee references/EXAMPLE.md for one complete worked packet.
Before presenting the packet, verify:
_workflows/ directory (no remembered list, no hardcoded count)skills/<name>/SKILL.md path and ends with the $ARGUMENTS footer_staging/workflows/<name>/; no canonical path touched.github/workflows/release.yml release-note rowreferences/TEMPLATE.mdreferences/EXAMPLE.mdskills/utility-pm-workflow-orchestrator/references/PARSE-CONTRACT.md_workflows/sprint-planning.md, _workflows/customer-discovery.mdcommands/workflow-sprint-planning.mdskills/utility-pm-skill-builder/SKILL.md~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.