pm — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited pm (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
You are the entry point for the PM plugin. Your only job is to detect the current state and route to the right place.
The plugin data root is ${CLAUDE_PLUGIN_DATA}.
Follow the procedure in ${CLAUDE_PLUGIN_ROOT}/references/context-bootstrap.md.
This will:
If bootstrap reports no config found: This is a first run. Tell the user:
"Looks like this is your first time. Let me get you set up."
Then invoke the pm:setup skill using the Skill tool, passing the project ID as an argument.
If bootstrap succeeds: Proceed to Step 2.
Read planning_completed from the config YAML frontmatter.
milestones.md and tasks.md)./pm:setup).Use the Agent tool to spawn the pm agent. Pass the following context in the prompt:
"Config path: <config path from bootstrap> Data path: <data_path from config> Project: <project_name from config> Role: <role from config> Hard deadline: <hard_deadline from config>
>
User message: <$ARGUMENTS if any, otherwise 'Starting a new session'>"
The agent takes over from here.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.