agent-copy — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited agent-copy (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
This skill creates or refreshes a repo-root AGENTS.md file by copying the user's canonical global agent instructions, then appending a repo-specific guide for the current project.
Architecture:
canonical global instructions -> repo-local AGENTS.md -> repo-specific tailUse one agent-copy skill for this workflow. Do not create separate runtime-specific variants such as agent-copy-codex, agent-copy-claude, or agent-copy-cursor; change the source path instead.
Default source:
$HOME/.codex/AGENTS.mdDefault target:
./AGENTS.mdCodex is the default because this repo demonstrates a Codex-first setup. If the user's canonical instructions live somewhere else, use that source path instead. Examples include a Claude project instruction file, an OpenCode context file, or another agent-compatible global instruction file.
Only AGENTS.md files should be created, copied, or updated unless the user explicitly asks for another instruction file.
The repo-root ./AGENTS.md file must:
## Repo-Specific Guide.TBD - ask the user before implementing this area.Do not paraphrase, summarize, or partially copy the canonical source file.
Check for the default source:
test -f "$HOME/.codex/AGENTS.md" && echo "$HOME/.codex/AGENTS.md"If the file does not exist and the user wants Codex as the canonical source, tell the user to install the repo's root AGENTS.md template into their Codex root first:
mkdir -p "$HOME/.codex"
cp AGENTS.md "$HOME/.codex/AGENTS.md"If the user is not using Codex, ask for the exact path to their equivalent canonical instruction file before copying anything.
Run before editing:
pwd
git status --short --branch
git branch --show-current
git remote -v
find . -maxdepth 2 -type f \( -name 'package.json' -o -name 'pnpm-lock.yaml' -o -name 'package-lock.json' -o -name 'yarn.lock' -o -name 'pyproject.toml' -o -name 'requirements.txt' -o -name 'go.mod' -o -name 'Cargo.toml' -o -name '.env.example' -o -name 'README.md' -o -name 'DESIGN.md' \) -print
find . -maxdepth 3 \( -name AGENTS.md -o -name CLAUDE.md \) -printScan and read existing repo docs/manifests before writing repo-specific details.
If ./AGENTS.md already exists:
If existing repo instructions conflict with the selected canonical source, keep the canonical source rules unless the user explicitly says the repo is an exception.
Append this section after the global preamble. Populate known fields from the user's project description, README.md, DESIGN.md, package manifests, lockfiles, env examples, app directory structure, existing scripts, and tests.
Never invent production credentials, live deployment state, database schema, auth policy, or external integrations.
## Repo-Specific Guide
### Project Overview
### Product Goal
### Audience / Users
### Key Directories / Docs / Scripts
### Stack / Architecture
### Local Dev Commands
### Build / Test / Verification
### Branch / Git Workflow
### Boundaries / Do Not Touch
### Implementation NotesAfter writing:
SOURCE_AGENTS="${SOURCE_AGENTS:-$HOME/.codex/AGENTS.md}"
head -n "$(wc -l < "$SOURCE_AGENTS")" ./AGENTS.md | cmp "$SOURCE_AGENTS" -
rg -n "Repo-Specific Guide|Project Overview|Product Goal|Stack / Architecture|Build / Test / Verification|Boundaries / Do Not Touch|Implementation Notes" ./AGENTS.md
git status --short --branchIf a non-default source was used, set SOURCE_AGENTS to that path before verification.
Report whether the global preamble verification passed.
Final response should include:
Commit only when the user explicitly asked for commit/push or the current task includes publishing.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.