release-registry — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited release-registry (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use this skill for package and registry release preparation.
server.json, registry publishing automation, and full release verification land in later Epic 6 stories.coffee-roaster-mcpio.github.syamaner/coffee-roaster-mcpRoastPilotserver.json exists and matches the package version when the registry metadata story lands.Until Epic 6 lands, use this skill to review readiness only:
coffee-roaster-mcpio.github.syamaner/coffee-roaster-mcpdisabled so package install smoke does not require audio or model downloadserver.json remains part of the release planWhen published package verification becomes available, the minimum smoke target remains:
coffee-roaster-mcp --help
coffee-roaster-mcp --version
python -c "import os, tempfile; from coffee_roaster_mcp.config import load_config; tmp = tempfile.TemporaryDirectory(); os.chdir(tmp.name); c = load_config(environ={}); print(c.roaster.driver, c.first_crack.mode, c.first_crack.precision); tmp.cleanup()"Expected bootstrap output:
mock disabled int8server.json, PyPI verification, and mcp-publisher stories are complete.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.