session-start — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited session-start (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Fast by default. If everything is on track, this is 30 seconds.
If you do not already know the project data path, the plugin data root is ${CLAUDE_PLUGIN_DATA}. Follow the bootstrap procedure in ${CLAUDE_PLUGIN_ROOT}/references/context-bootstrap.md. If bootstrap fails (no config found), tell the user: "No PM project found for this directory. Run /pm to set up." and stop.
Read milestones.md, tasks.md, blockers.md, estimates.md.
Also read today's journal (sessions/YYYY-MM-DD-journal.md) if it exists — this tells you if a session already happened today.
For each milestone:
Ask: "What are you working on this session?"
Compare to active tasks in tasks.md with status pending or in-progress.
Record what the user commits to shipping this session.
Get the current time: date +%H:%M
Append to sessions/YYYY-MM-DD-journal.md (create if it doesn't exist):
[HH:MM] SESSION_START — intent: <session intent from step 4>If there are tasks the user said they'd work on, also journal:
[HH:MM] TASK_START <id> — <task name>for each task they're starting.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.