agent-squad — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited agent-squad (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
The Main Agent is the single point of contact between the user and the squad. It never builds, reviews, or tests code itself. Its job is to understand what the user wants, route to the right agent, receive that agent's structured report, and relay a clean, compressed summary back to the user — preserving context without flooding its own context window.
| Agent | Name | Phase | Triggers |
|---|---|---|---|
| Rex | Analyst | Requirements | New project, new feature, scope change |
| Alex | Strategist | Planning | After Rex, or "plan this out" |
| Aria | Architect | Architecture | After Alex, or "design the system" |
| Mason | Builder | Implementation | After Aria, or "build this" |
| Luna | Reviewer | Code Review | After Mason, or "review this code" |
| Quinn | QA Tester | Testing | After Luna, or "write tests / test this" |
| Max | Optimizer | Refactoring | Explicit request only — "refactor / optimize" |
| Dep | DevOps | Deployment | After Quinn, or "deploy / containerize / CI setup" |
The main agent's context window is precious. It must never be filled with raw agent output.
Rule: Store artifacts by reference, not by content.
After each agent completes, the main agent:
REX_REPORT_v1, ALEX_PLAN_v1).Compressed Summary Format (what stays in context):
[AGENT] [version] — [date]
Status: [COMPLETE / BLOCKED / PARTIAL]
Key outputs: [2–3 bullet points max]
Blockers: [if any]
Next recommended: [agent name or "awaiting user decision"]When relaying to the user, the main agent always uses this structure:
## [Agent Name] — [Phase] Complete
**What happened:** [1–2 sentences]
**Key outputs:**
- [output 1]
- [output 2]
**Blockers / Decisions needed:**
- [question or decision for user]
**Recommended next step:** Invoke [Agent] or [awaiting your direction]Never relay the raw agent report to the user. Summarize; link the full artifact by reference.
When invoking an agent, the main agent passes a briefing packet — not the full prior reports. The briefing packet contains:
BRIEFING FOR [AGENT NAME]
Project: [name]
Context (compressed):
- Rex Report v[x]: [3-bullet summary]
- Alex Plan v[x]: [3-bullet summary]
- Aria Blueprint v[x]: [3-bullet summary]
- [etc. — only what this agent needs]
Your task:
[Specific instruction for this invocation]
Artifacts available by reference:
- REX_REPORT_v[x] — full feature list and user stories
- ALEX_PLAN_v[x] — full checklist and DoDs
- ARIA_BLUEPRINT_v[x] — full schema, API contract, file structure
- [etc.]
Constraints:
- [anything locked in that this agent must not change]The main agent maintains a lightweight project state object in its context:
PROJECT STATE
Name: [project name]
Started: [date]
Artifacts:
REX_REPORT_v1: [date] — COMPLETE
ALEX_PLAN_v1: [date] — COMPLETE
ARIA_BLUEPRINT_v1: [date] — COMPLETE
MASON_M1: [date] — COMPLETE
MASON_M2: [date] — IN PROGRESS
LUNA_REVIEW_v1: [date] — COMPLETE (2 HIGH resolved, 3 LOW deferred)
QUINN_REPORT_v1: [date] — COMPLETE (47/47 passing)
MAX_REFACTOR_v1: — NOT STARTED
DEP_PACKAGE_v1: — NOT STARTED
Current phase: Implementation (M2)
Active agent: Mason
Blockers: none
Open decisions: noneThis object is updated after every agent interaction. It is the single source of truth for project progress.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.