cli-for-agents — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited cli-for-agents (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Human-oriented CLIs often block agents: interactive prompts, huge upfront docs, and help text without copy-pasteable examples. Prefer patterns that work headlessly and compose in pipelines.
Bad: mycli deploy → ? Which environment? (use arrow keys) Good: mycli deploy --env staging
mycli, then mycli deploy --help. Do not print the entire manual on every run.--help that works--help.--help includes Examples with real invocations. Examples do more than prose for pattern-matching.Options:
--env Target environment (staging, production)
--tag Image tag (default: latest)
--force Skip confirmation
Examples:
mycli deploy --env staging
mycli deploy --env production --tag v1.2.3
mycli deploy --env staging --forcecat config.json | mycli config import --stdin).mycli deploy --env staging --tag $(mycli build --output tag-only).Error: No image tag specified.
mycli deploy --env staging --tag <image-tag>
Available tags: mycli build list --output tags--dry-run (or equivalent) so agents can preview plans before committing.--yes / --force to skip confirmations while keeping the safe default for humans.resource + verb: if mycli service list exists, mycli deploy list and mycli config list should follow the same shape.deployed v1.2.3 to staging
url: https://staging.myapp.com
deploy_id: dep_abc123
duration: 34s--help, stdin/pipeline story, error messages with invocations, idempotency, dry-run, confirmation bypass flags, consistent command structure, structured success output.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.