session-dream — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited session-dream (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A manual trigger for the memory distillation that Claude Code's autoDream service does automatically in the background. Where autoDream fires after 5+ sessions and 24+ hours, this skill fires on demand — letting you capture a session's insights before they're lost in compaction.
From services/autoDream/consolidationPrompt.ts, the autoDream process has 4 phases:
This skill follows the same 4-phase structure but applies it to the current conversation rather than historical transcripts.
Check what memory already exists:
MEMORY.md if it exists (or note that it doesn't)Review the current conversation and identify:
High-value (always distill):
Medium-value (distill if not easily discoverable):
Low-value / skip:
For each high-value item:
Topic file format:
---
name: [descriptive topic name]
description: [one line — what query would cause this file to be loaded?]
type: feedback | project | user | reference
---
[For feedback/project type, lead with the rule or fact]
**Why:** [the reason this matters — context that makes the rule sensible]
**How to apply:** [when/where this kicks in]Key types:
feedback: User preferences, corrections, confirmed approaches — things that shape HOW to workproject: Facts about the current project — decisions, constraints, current stateuser: Information about the user's background, expertise, goalsreference: Pointers to external resources, tools, docsConvert relative dates to absolute dates: "yesterday" → "2026-04-15", "last week" → "2026-04-07".
Update MEMORY.md:
- [Title](filename.md) — one-line hookAt the end, tell the user:
Good memory entry for a feedback type:
**Rule:** For this project, prefer explicit error types over generic Error objects.
**Why:** The error handling middleware needs to distinguish between validation errors (400) and server errors (500) — string matching on error messages is fragile.
**How to apply:** When writing any error-throwing code in the API layer, create or use a typed error class (ValidationError, AuthError, etc.).Good memory entry for a project type:
The payments module uses Stripe's older API (v2019-10-17) pinned in config — do not upgrade without coordinating with the billing team.
**Why:** An upgrade in 2025-Q3 broke webhook signature validation and caused missed payment events. The pin is intentional.
**How to apply:** When touching payments code, verify any Stripe API usage against the v2019-10-17 docs, not the latest.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.