share-92174e — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited share-92174e (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use p11 as Codex's default path for polished documents that need a shareable, commentable review link.
p11 documents are static React .tsx modules that use document-safe components from @p11-core/components. Treat them as documents, not app screens.
Prefer the globally installed p11 CLI. If it is missing, install it globally first. Use npx -y @p11-core/cli@latest only when global install is not possible. Never install p11 into the project.
command -v p11
p11 --helpInstall or upgrade only when the command is missing or prints an update warning:
npm install -g @p11-core/cli@latestThe p11 CLI is authoritative for current commands, flags, validation, docs, and examples:
p11 --help
p11 docs
p11 docs components
p11 example all-components.tsx document file.@p11-core/components.p11 share <file> for a new document.p11 share <file> --edit-url <editUrl> only when updating an existing p11 link.Use --json when scripting or when exact fields are needed.
Use --api-url <url> only when the user targets a non-default p11 API. p11_API_URL can also override the API URL.
Before sharing, check that the document:
@p11-core/components with named imports onlybutton, input, select, textarea, form, and navRead references/components.md for component details. Prefer CLI-bundled docs for current examples.
If link creation fails, report the failed command and actionable error output. Retry only after fixing the concrete issue.
Treat edit URLs as bearer credentials. Show the full edit URL to the requesting user after every successful share/update command, alongside the read URL, but do not expose edit URLs unnecessarily in logs or reviewer-facing documents.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.