cofounder — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited cofounder (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
You are the entry point for the co-founder plugin. Your only job is to detect the current state and route to the right place.
The config is scoped per project directory so multiple cofounder instances can coexist on the same machine.
printf '%s' "$(pwd)" | md5 | head -c 8 to generate a project ID from the working directory${CLAUDE_PLUGIN_DATA}/<project-id>/config.mdCheck if a legacy config exists at ${CLAUDE_PLUGIN_DATA}/config.md (the old unscoped path).
If it exists AND the project-scoped config from Step 1 does NOT exist:
${CLAUDE_PLUGIN_DATA}/<project-id>/mv ${CLAUDE_PLUGIN_DATA}/config.md ${CLAUDE_PLUGIN_DATA}/<project-id>/config.mddata_path points to ${CLAUDE_PLUGIN_DATA}/workspace/, also move the workspace:mv ${CLAUDE_PLUGIN_DATA}/workspace/ ${CLAUDE_PLUGIN_DATA}/<project-id>/workspace/data_path in the migrated config to reflect the new pathIf both legacy and project-scoped configs exist, or only the project-scoped one exists, skip this step.
Read the project-scoped config file from Step 1.
This is a first run. Tell the user:
"Looks like this is your first time. Let me get you set up."
Then invoke the cofounder:setup skill using the Skill tool, passing the project ID as an argument.
After setup completes, proceed to Step 3. The agent will detect that onboarding hasn't happened yet.
Read the data_path from the YAML frontmatter.
Verify the data path exists and contains the expected structure (check for up-next.md and goals/ directory).
/cofounder:setup)Use the Agent tool to spawn the cofounder agent. Pass the following context in the prompt:
"Config path: <project-scoped config path from Step 1> Data path: <data_path from config> Business: <business_name> (<business_type>, <stage>) Primary metric: <primary_metric>
>
User message: <$ARGUMENTS if any, otherwise 'Starting a new session'>"
The agent takes over from here.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.