self-extension-workflow — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited self-extension-workflow (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Exact prompt and procedure the agent executes after every mistake. The agent never pushes to `main` directly. Every self-extension is a PR.
Five agent steps plus a search-prerequisite, from mistake to merged rule. The agent never pushes to main. Every rule that lands is CODEOWNERS-approved. This page is the contract.
<!-- target: ~1100 tokens -->
Five conditions. Any one of them starts the workflow.
The agent starts this workflow when any of these is met:
Five steps after the search-prerequisite. Every step is mandatory before the next one.
Mandatory. Duplicates in the error log destroy the signal.
Before creating a new error entry, search the existing error log:
1. Read skills/error-log/SKILL.md.
2. Search for similar errors (same category + similar context).
3. If a similar entry exists:
- Increment its `count` field by 1.
- Update `last_seen` to today.
- Supplement the context if needed.
- Do NOT create a new entry.
4. Only if no similar entry exists, continue with Step 1.The agent answers six questions before writing anything.
1. What exactly did I do? (concrete code/action)
2. What should I have done instead?
3. Why did I do it wrong? (false assumption, missing knowledge, carelessness)
4. Which category applies?
- development: code error, wrong implementation
- git: commit/branch mistake
- deployment: deployment order, configuration
- security: security vulnerability
- performance: N+1, missing indexes, oversized datasets
- domain: wrong understanding of business rules
5. How severe was the error? (critical/high/medium/low)
6. Which target file does the rule belong in?Take the next number after the latest entry.
# Find last entry in error-log.md
grep "id: ERR-" skills/error-log/SKILL.md | tail -1
# Take next number: ERR-2026-004 -> ERR-2026-005Action directive only. The CI verb allow-list rejects anything else.
Use the template at skills/error-log/_entry-template.md. The schema at schemas/error-entry.json is enforced by CI.
[!WARNING] CI GATE · verb allow-list —new_rulemust start with one ofAlways,Never,Before,After,Prefer,Avoid,Use,Do,Ensure. Anything else is rejected.
Bad: "SQL injection is dangerous" Good: "Never concatenate user input directly into SQL queries. Always use prepared statements."
One file per category. Domain rules go to a project file, not a global one.
| Error category | Target file |
|---|---|
development | skills/code-quality/SKILL.md |
git | skills/git-conventions/SKILL.md |
deployment | skills/review-deployment/SKILL.md |
security | skills/code-quality/SKILL.md (Security section) |
performance | skills/code-quality/SKILL.md (Performance section) |
domain | skills/<project>/SKILL.md |
At the end of the matching section. Reference the ERR-ID.
Reference: ERR-YYYY-NNN.Never push to `main` directly. The label triggers the lint-rules workflow.
git checkout -b learn/ERR-YYYY-NNN
git add skills/
git diff --cached # MANDATORY human review step
git commit -m "learn(errors): ERR-YYYY-NNN — <short description>
Co-Authored-By: <your real name> <[email protected]>"
git push -u origin learn/ERR-YYYY-NNN
gh pr create --label needs-rule-review \
--title "learn(errors): ERR-YYYY-NNN" \
--body "Auto-generated rule. Reviewer: confirm rule wording and target file. CI \`lint-rules\` must pass."PR flow — branch, commit, push, PR; lint-rules and auto-approve-rule-pr CI gates run in parallel; CODEOWNERS human gate; squash-merge into main behind branch protection
Branch through CI gates and CODEOWNERS into a squash-merge on `main`.
Why a PR (not a direct commit). Four layers of gating.
| Layer | What it gates | Where |
|---|---|---|
lint-rules | Schema + verb allow-list + forbidden patterns | schemas/error-entry.json |
auto-approve-rule-pr | Diff scope (skills/** — error-log entry plus the target sub-skill) and Co-Authored-By: trailer | .github/workflows/auto-approve-rule-pr.yml |
| Branch protection | CODEOWNERS approval for skills/error-log/ | .github/CODEOWNERS |
| Human review | Final read of rule wording and target file | maintainer |
[!NOTE] CI GATE · four-layer gating — Every rule that goes live has been seen by a human. The validator is best-effort, not airtight — see SECURITY.md Limitations section.
The commit type learn makes self-extension visible in git log --grep="learn(".
When a legitimate rule must mention a forbidden pattern (e.g. preventing `subprocess` misuse).
skills/error-log/exceptions.yml: allow_forbidden_pattern_for:
- ERR-YYYY-NNN # rationale: rule must mention `subprocess` to be specificexceptions.yml changes — the bypass is auditable in git history.When the error log exceeds 50 entries. Manual diff review until eval framework lands.
1. Read all entries in skills/error-log/SKILL.md.
2. Group by root_cause similarity.
3. For groups with the same root cause:
- Keep the most detailed entry.
- Sum up all `count` values.
- Set `last_seen` to the most recent date.
- Delete the duplicates.
4. For entries older than 6 months with severity: low:
- Archive (move to a comment block or separate archive file).
- The rules derived from them remain in the sub-skills.
5. Open a PR: "chore(errors): consolidate error log (N entries merged)".LLM-driven consolidation is non-deterministic. Until the eval framework (Phase 2 roadmap) reports a stable baseline, do consolidation manually with diff review. The threshold of 50 entries is a soft signal, not a forced rebuild.
Self-extension as a normal version-control discipline.
The agent doesn't just fix errors — it learns from them, and every lesson is a Git commit you can review, revert, or share. The PR-flow brings the standard engineering toolkit to rule learning: deterministic validation, branch protection, CODEOWNERS approval, and a public audit trail.
*Your agent's mistakes — versioned. Self-learning skills, every commit. One source, four agent runtimes. That's the loop.*
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.