cook — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited cook (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
End-to-end implementation with automatic workflow detection.
Principles: YAGNI, KISS, DRY | Token efficiency | Concise reports
/cook <natural language task OR plan path>IMPORTANT: If no flag is provided, the skill will use the interactive mode by default for the workflow.
Optional flags to select the workflow mode:
--interactive: Full workflow with user input (default)--fast: Skip research, scout→plan→code--parallel: Multi-agent execution--no-test: Skip testing step--auto: Auto-approve low-risk steps; high-risk changes stop for human approval before finalize/commit/shipComposable flags (combine with any mode):
--tdd: Tests-first per phase — write tests for current behavior beforerefactoring, then verify they still pass after the implementation step
Example:
/cook "Add user authentication to the app" --fast
/cook path/to/plan.md --auto
/cook "Refactor auth middleware" --tdd<HARD-GATE> Do NOT write implementation code until a plan exists and has been reviewed. This applies regardless of task simplicity. "Simple" tasks are where unexamined assumptions waste the most time. Exception: --fast mode skips research but still requires a plan step. User override: If user explicitly says "just code it" or "skip planning", respect their instruction. </HARD-GATE>
<HARD-GATE-SCOUT-FIRST> Before planning OR asking clarifying questions, scan the codebase. Mandatory scout outputs:
./docs/ and any in-flight plans in ./plans/ covering this areaState a 3-6 bullet codebase-context summary to the user before asking questions. Skip ONLY when input is a plan.md/phase-*.md path (the plan already encodes scout output). </HARD-GATE-SCOUT-FIRST>
<HARD-GATE-EXACT-REQUIREMENTS> Before producing a plan, you MUST be able to answer ALL of these in one concrete sentence each (use AskUserQuestion to pin them down — do NOT proceed on vague intent):
Ground every AskUserQuestion option in scout findings (e.g., "Add to src/api/users.ts (matches existing pattern) or new src/api/profile.ts?"). Skip ONLY when input is a plan.md/phase-*.md path. </HARD-GATE-EXACT-REQUIREMENTS>
<HARD-GATE-NO-SIDE-EFFECTS> Implementation is NOT done until verified to be side-effect-free. Code-review and test gates MUST prove:
User override: If user invoked --no-test, item 2 is downgraded to a warning. Surface the unverified-tests risk in the finalize AskUserQuestion so the user accepts the trade-off rather than having it silently chosen. Items 1, 3, 4, 5 remain enforceable via the mandatory code-reviewer subagent.
If review/testing reveals a side effect, regression, or broken workflow, STOP. Use AskUserQuestion to present:
Let the user decide. Do not silently patch around regressions. </HARD-GATE-NO-SIDE-EFFECTS>
| Thought | Reality |
|---|---|
| "This is too simple to plan" | Simple tasks have hidden complexity. Plan takes 30 seconds. |
| "I already know how to do this" | Knowing ≠ planning. Write it down. |
| "Let me just start coding" | Undisciplined action wastes tokens. Plan first. |
| "The user wants speed" | Fastest path = plan → implement → done. Not: implement → debug → rewrite. |
| "I'll plan as I go" | That's not planning, that's hoping. |
| "Just this once" | Every skip is "just this once." No exceptions. |
| Input Pattern | Detected Mode | Behavior |
|---|---|---|
Path to plan.md or phase-*.md | code | Execute existing plan |
| Contains "fast", "quick" | fast | Skip research, scout→plan→code |
| Contains "trust me", "auto" | auto | Auto-approve low-risk artifact-validated steps; stop on high-risk |
| Lists 3+ features OR "parallel" | parallel | Multi-agent execution |
| Contains "no test", "skip test" | no-test | Skip testing step |
| Default | interactive | Full workflow with user input |
See references/intent-detection.md for detection logic.
flowchart TD
A[Intent Detection] --> B{Has plan path?}
B -->|Yes| F[Load Plan]
B -->|No| C{Mode?}
C -->|fast| D[Scout → Plan → Code]
C -->|interactive/auto| SC[Scout Codebase MANDATORY]
SC --> SR[Summarize Findings to User]
SR --> RQ{Exact requirements captured?<br/>output, acceptance, scope, constraints, touchpoints}
RQ -->|No| SR
RQ -->|Yes| E[Research → Review → Plan]
E --> F
D --> F
F --> G[Review Gate]
G -->|approved| H[Implement]
G -->|rejected| E
H --> H1{Simplify signal?}
H1 -->|Yes| H2[Conditional Simplify]
H1 -->|No| I[Review Gate]
H2 --> I
I -->|approved| J{--no-test?}
J -->|No| K[Test]
J -->|Yes| L[Finalize]
K --> L
L --> M[Report + Journal]This diagram is the authoritative workflow. Prose sections below provide detail for each node. If prose conflicts with this flow, follow the diagram.
[Intent Detection] → [Research?] → [Review] → [Plan] → [Review] → [Implement] → [Conditional Simplify?] → [Review] → [Test?] → [Review] → [Finalize]Default (non-auto): Stops at [Review] gates for human approval before each major step. Auto mode (`--auto`): Skips human review gates only for low-risk work. High-risk changes stop for human approval before finalize/commit/ship. Claude Tasks: Utilize TaskCreate, TaskUpdate, TaskGet, TaskList during implementation step. Fallback: These are CLI-only tools — unavailable in VSCode extension. If they error, use TodoWrite for progress tracking instead.
| Mode | Research | Testing | Review Gates | Phase Progression |
|---|---|---|---|---|
| interactive | ✓ | ✓ | User approval at each step | One at a time |
| auto | ✓ | ✓ | Auto only if artifacts pass and high-risk stop is false | All low-risk phases continuously |
| fast | ✗ | ✓ | User approval at each step | One at a time |
| parallel | Optional | ✓ | User approval at each step | Parallel groups |
| no-test | ✓ | ✗ | User approval at each step | One at a time |
| code | ✗ | ✓ | User approval at each step | Per plan |
✓ Step [N]: [Brief status] - [Key metrics]Human review required at these checkpoints (skipped with --auto):
Always enforced (all modes):
code-reviewer subagent with explicit checks:(a) every acceptance criterion met, (b) no regression to business logic in touchpoints/blast-radius, (c) no breaking changes to public contracts (signatures, schemas, APIs, env vars) unless called out, (d) follows existing patterns from scout, (e) no new lint/type/build errors anywhere. Pass scout summary + acceptance criteria as context. If reviewer flags side effects → trigger HARD-GATE-NO-SIDE-EFFECTS (AskUserQuestion with 2-4 options). Then: User approval OR artifact-gated auto approval. Score is advisory; it never approves by itself.
phase-XX-*.md (not only current phase), update plan.md status/progress, hydrate Claude Tasks, generate progress reportdocs-manager subagent → update ./docs if changes warrantTaskUpdate → mark all Claude Tasks complete after sync-back verification (skip if Task tools unavailable)git-manager subagent/journal to write a concise technical journal entry upon completion| Phase | Subagent | Requirement |
|---|---|---|
| Research | researcher | Optional in fast/code |
| Scout | scout | Optional in code |
| Plan | planner | Optional in code |
| UI Work | ui-ux-designer | If frontend work |
| Testing | tester, debugger | MUST spawn |
| Review | code-reviewer | MUST spawn |
| Finalize | /project-management skill + docs-manager, git-manager subagents | MUST invoke all |
CRITICAL ENFORCEMENT:
Task(subagent_type="[type]", prompt="[task]", description="[brief]")references/intent-detection.md - Detection rules and routing logicreferences/workflow-steps.md - Detailed step definitions for all modesreferences/review-cycle.md - Interactive and auto review processesreferences/subagent-patterns.md - Subagent invocation patterns../_shared/references/workflow-artifacts.md - Review artifact schema and validator contractTypically follows: /plan (execute a plan), /brainstorm (implement agreed solution) Typically precedes: /code-review (review after implementation), /test (validate changes) Related: /fix (alternative for bug fixes), /plan (create plan before cooking)
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.