project-learnings-6c910c — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited project-learnings-6c910c (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Capture project-specific patterns and anti-patterns into the project's CLAUDE.md. This creates a self-improving feedback loop where discoveries from debugging, development, and review make future Claude sessions smarter.
CRITICAL: Only project-specific knowledge qualifies. Generic programming advice does not belong in CLAUDE.md.
Determine if the finding qualifies as project-specific. The finding must pass at least ONE of these criteria:
| Criteria | Example That Qualifies | Example That Doesn't |
|---|---|---|
| Would a developer unfamiliar with this project likely hit this issue? | "The processOrder() function expects amounts in cents, not dollars" | "Always validate function inputs" |
| Is this pattern specific to this codebase's architecture, APIs, or conventions? | "The UserProfile type has an optional metadata field that is always present at runtime" | "Use TypeScript strict mode" |
| Is it something Claude's training data wouldn't cover? | "Never call db.query() without the timeout option — the default is infinite" | "Use async/await instead of callbacks" |
If NO to all criteria → STOP. Do not add generic programming knowledge to CLAUDE.md. Return to the calling skill and report that no project-specific learning was found.
If YES to any → proceed to Step 2.
.claude/ directory## Known Gotchas or ## Project-Specific Patterns)Write a concise, actionable instruction following these rules:
Format:
Templates:
For bug patterns:
- **[Area/Component]**: [What to do/avoid] — [why, with specific details]For API gotchas:
- `functionName()` in `path/to/file`: [What's surprising about it] — [consequence if ignored]For architectural constraints:
- [Constraint description] — [why it exists and what breaks if violated]Examples of well-formatted learnings:
processOrder() — it expects cents, not dollarsdb.query() in src/database.ts: Always pass the timeout option — the default is infinite and has caused production hangs (30 second timeout recommended)internal/ directories in src/api/ — the build system treats these as separate compilation units and circular dependencies will silently break HMRPresent the proposed addition via AskUserQuestion:
Show:
Options:
If the user confirmed (or provided edited text):
If the user chose "Skip":
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.