preflight-checks — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited preflight-checks (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Reference document for the pre-flight policy. The executable bash lives in plugins/flow/commands/start.md (Phase 0) — that is the single source of truth that runs at workflow start. This skill describes what each check enforces and why, so the policy can be reviewed, audited, and extended without untangling shell logic.
NO LLM CALLS IN PRE-FLIGHT. Every check is a bash command with a pass/fail exit code. If pre-flight fails, the workflow stops before spending any tokens on planning.
Pre-flight is the cheapest possible filter. It runs before EXPLORE, before any agent dispatch, and before any token-spending reasoning. The goal is to fail fast on conditions that would invalidate everything downstream — saving both wall-clock time and LLM cost.
If pre-flight is honest about what it can and cannot prove, downstream phases can trust their preconditions and stop re-checking them.
| # | Check | Failure mode it prevents |
|---|---|---|
| 1 | Clean git state (no uncommitted changes) | Starting a feature branch on top of unrelated dirty state, then accidentally including those changes in the PR. |
| 2 | Not on detached HEAD | Creating commits that have no branch reference and silently disappear when the workflow checks out something else. |
| 3 | gh CLI authenticated | Spending tokens on planning, then failing at the first gh issue view call because auth was never established. |
| 4 | Issue exists and is OPEN | Working an issue that was already closed, deleted, or mistyped — produces a PR with nothing to close. |
| 5 | Remote origin reachable | Reaching the push step after hours of work and discovering the network is down or the remote is misconfigured. |
| 6 | Already on a feature branch for this issue (warning only) | Accidentally re-starting an issue that is already in progress on the current branch — recoverable, so warning not error. |
Checks 1–5 are errors: any one fails, the workflow halts. Check 6 is a warning: noted in output, workflow proceeds.
The runnable implementation is the bash block in plugins/flow/commands/start.md under "Phase 0: PRE-FLIGHT". $ARGUMENTS is substituted with the issue number from command arguments. That is the copy that actually runs.
This skill intentionally does not duplicate the bash. Two copies of the same checks drift silently — when a check is added to one and not the other, the gap is invisible until pre-flight either misses a real failure or fires on a condition that was already removed. Keeping the policy here and the implementation in the command means there is one place to read the shell, and one place to read the rationale.
When adding a new check, the policy contract is:
gh and git that pre-flight already performs.If a proposed check cannot meet all four, it does not belong in pre-flight. Push it to a later phase or to a domain skill.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.