capability-discovery-97f149 — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited capability-discovery-97f149 (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Discovers available capabilities in the user's environment for dynamic workflow adaptation.
DISCOVER BEFORE ASSUMING. Never hardcode tool availability. Always scan the environment first.
Assuming a tool exists leads to runtime failures. Assuming it doesn't leads to missing capabilities.
Steps 1-5 are independent — execute ALL simultaneously with parallel tool calls.
Use Glob to find agent files, then Grep to extract descriptions:
Glob: ".claude/agents/*.md" — project agentsGlob: "plugins/*/agents/*.md" — plugin agentsParse: source, name (filename without .md), description (from frontmatter).
Glob: ".claude/skills/*/SKILL.md" — project skillsGlob: "plugins/*/skills/*/SKILL.md" — plugin skillsParse: source, name (parent directory), description (from frontmatter).
Glob: ".claude/commands/*.md" — project commandsGlob: "plugins/*/commands/*.md" — plugin commandsParse: source, name (filename without .md), description (from frontmatter).
CLAUDE_MD=""
[ -f ".claude/CLAUDE.md" ] && CLAUDE_MD=".claude/CLAUDE.md"
[ -z "$CLAUDE_MD" ] && [ -f "CLAUDE.md" ] && CLAUDE_MD="CLAUDE.md"
[ -n "$CLAUDE_MD" ] && grep -E "(npm|pnpm|yarn|bun|ruff|pytest|go |cargo |make )" "$CLAUDE_MD" 2>/dev/null[ -f "package.json" ] && echo "node"
[ -f "tsconfig.json" ] && echo "typescript"
[ -f "pyproject.toml" ] && echo "python"
[ -f "Gemfile" ] && echo "ruby"
[ -f "go.mod" ] && echo "go"
[ -f "Cargo.toml" ] && echo "rust"
[ -f "Makefile" ] && echo "makefile"If no tech stack files found and no quality commands in CLAUDE.md, report:
ls verify.sh scripts/verify* playwright.config.* cypress.config.* 2>/dev/nullPre-check: Read lsp.enabled from settings (default true). If false, skip this step and report all LSP features as "Disabled" in the output table.
Probe for available LSP code intelligence features. Find a representative source file in the project (use the first file matching the detected tech stack — e.g., .ts, .py, .go, .rs, .rb), then test each LSP operation against it.
LSP feature probes (run each, catch failures individually):
| Operation | Test | Capability |
|---|---|---|
documentSymbol | List symbols in the file | Symbol navigation |
hover | Hover on first symbol (line 1, char 1) | Type info / docs |
goToDefinition | Definition lookup on an import or reference | Definition tracing |
findReferences | Find references to a symbol | Impact analysis |
goToImplementation | Find implementations | Interface resolution |
Diagnostics inference: LSP diagnostics are not a discrete operation to probe — they are reported by the language server when it processes a file. If documentSymbol succeeds, the LSP server is active and diagnostics are available. Record diagnostics as "Available" when documentSymbol succeeds, "Unavailable" otherwise.
Process:
Glob: "**/*.ts" or "**/*.py" or "**/*.go" or "**/*.rs" or "**/*.rb" (match detected tech stack)lsp.timeout from settings (default 5000ms). If an operation doesn't respond within this timeout, mark it as unavailable.Graceful degradation: If no source files exist (markdown-only project) or no LSP server is configured, report "No LSP server available — using CLI-only analysis" and skip. This is not an error.
### Agents Available
| Agent | Source | Description |
|-------|--------|-------------|
### Skills Available
| Skill | Source | Description |
|-------|--------|-------------|
### Quality Commands
| Command | Purpose | Source |
|---------|---------|--------|
### Tech Stack
- {language} ({indicator file})
### Verification Capabilities
| Capability | Command | Source |
|-----------|---------|--------|
### LSP Capabilities
| Feature | Status | Use Case |
|---------|--------|----------|
| documentSymbol | {Available/Unavailable} | Symbol navigation in files |
| hover | {Available/Unavailable} | Type info and documentation during CODE phase |
| goToDefinition | {Available/Unavailable} | Trace code paths during EXPLORE phase |
| findReferences | {Available/Unavailable} | Impact analysis during EXPLORE, caller verification during REVIEW |
| goToImplementation | {Available/Unavailable} | Interface resolution |
| diagnostics | {Available/Unavailable} | Quality signal during VERIFY phase (errors→P1, warnings→P2) || Missing | Fallback |
|---|---|
| No agents | Use built-in review checklist |
| No CLAUDE.md commands | Detect from tech stack |
| No tech stack | Ask user for commands |
| No LSP server | CLI-only analysis (grep/glob for references, CLI tools for diagnostics) |
This skill runs in a forked context. The calling command must store the output for use in later phases — do not re-invoke within the same command execution.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.