deslop — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited deslop (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Run the scanner:
bash "${CLAUDE_PLUGIN_ROOT}/scripts/deslop.sh" ${ARGUMENT:-.}NativeModules usage -- legacy bridge, banned in New ArchitecturerequireNativeComponent -- use codegenNativeComponent insteadUIManager usage -- legacy bridge, bannedAsyncStorage usage -- banned, use MMKV or SecureStoreTouchableOpacity / TouchableHighlight -- banned, use PressablePanResponder -- banned, use Gesture Handler v2 GestureDetectorfetch( outside src/libs/ -- use axios instanceuseEffect with fetch( -- use React Queryhttps://, http://) in source -- use EXPO_PUBLIC_ env vars{expr && <Component>} -- renders 0 or false; use ternary or Boolean()console.log / console.warn anywhere in src/ -- crashes in Reanimated worklets, banned everywhereTODO / FIXME / HACK commentsform.watch( -- use useWatchinterface declaration -- use type insteadImage from react-native -- use expo-imagerouter.push('/ string -- use typed routesstyle={} inline prop -- use className with NativeWindaccessibilityRole on interactive elementseslint-disable comments@ts-ignore / @ts-expect-errorsrc/ (except route files in app/)any type annotationsList critical issues with file:line format. Suggest fix for each. Group by severity.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.