task-profile — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited task-profile (Agent Skill) and scored it 92/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 2 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 2 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Platforms: Claude Code / Cowork and Codex.scripts/inventory.pydetects the host (via theplatformstampinstall.shwrites, orAI_FIRST_PLATFORM) and routes: Claude Code (~/.claude/projects) + Cowork transcripts, or Codex rollouts (~/.codex/sessions), building the same session condensate + token aggregates either way. Antigravity is unsupported: its IDE store is AEAD-encrypted at rest and its CLI store has no parseable turn content, so the skill prints a clear "not available" message and exits.
End-to-end skill: session inventory → LLM clustering → parallel Haiku analysis → aggregation → branded explorer HTML + shareable CSV + atomic skill proposals.
When the user asks to understand their own Claude usage patterns: what tasks they repeat, how much friction those tasks generate where tokens go which principles they already follow vs. where they slip, and which new skills would compound across many tasks.
~/.claude/projects/*/\*.jsonl~/Library/Application Support/Claude/local-agent-mode-sessions/*/*/local_*/audit.jsonlsession-search skill is already installed at ~/.claude/skills/session-search/ (optional but recommended; this skill does its own inventory pass).Run from any working directory, outputs land under ./out/ in that directory.
~/.claude/skills/task-profile/scripts/inventory.py --out out/inventory.jsonFlags: --since YYYY-MM-DD, --until YYYY-MM-DD, --all (default window: last 6 months).
Writes per-session rows with: summary, token totals (per model, from message.usage), automation flag + reason, and a structured condensate (intent turns + correction turns + tool-flail episodes + outcome turns). Automated sessions (paperclip, scheduled-task, sdk-cli, ditto-routine) are flagged and excluded from downstream analysis but kept for transparency.
You (the main agent) read the non-automation rows and group them into ~40–80 clusters by judgment, no scripted heuristics past cwd. Write out/clusters.json. Merge sessions with the same cwd, similar Cowork titles, or clearly similar topics. Show the cluster list to the user before the Haiku fan-out so they can adjust.
Run out/build_payloads.py (generated per-run, sample below) to produce one payload per cluster. Sampling: ≤ 10 sessions → all included; > 10 → include 10 biased to outliers (3 longest by turns, 3 most corrections, oldest, newest, even-spaced fill).
Dispatch one Agent(subagent_type="general-purpose", model="haiku", run_in_background=true) per cluster in parallel. Each subagent reads:
~/.claude/skills/task-profile/references/task-style.md~/.claude/skills/task-profile/references/success-rubric.md~/.claude/skills/task-profile/references/friction-signals.mdout/payloads/<cluster_id>.jsonAnd emits strict JSON to out/analyses/<cluster_id>.json with a 1–3 task list per cluster.
You (the main agent) read out/analyses/*.json, decide cross-cluster merges, and write out/canonical-merges.json with entries of the form:
{"canonical": "<sentence>", "category": "<cat>", "source_tasks": [{"cluster": "...", "match": "<substring>"}]}Then run:
~/.claude/skills/task-profile/scripts/write_profile.pyThe script normalises success/category enums, applies redaction one more time, sums tokens per task from the inventory (no estimation, real message.usage values), and writes:
out/profile.csv, shareable, one row per canonical task, with tokens_by_model as a compact string.out/profile.json, richer, includes per-task friction points and session list (for the explorer).Do not skip this phase. The explorer is half-empty without it. build_explorer.py will refuse to run unless both out/coaching-panel.json and out/skill-proposals.json exist; override with --allow-empty is only for debugging.
#### E.1, Coaching panel
Read out/profile.json and ~/.claude/skills/task-profile/references/ai-first-principles.md. Pick 3–5 principles where the user has a clear, evidenced gap. For each, cite ≥ 1 good-example session path and ≥ 1 friction-example session path. Write out/coaching-panel.json.
Schema:
{
"cards": [
{
"principle": "<short name of the habit>",
"pattern": "<one-line description of the observed pattern>",
"good_example": {"description": "<what worked here>", "session_path": "<path>"},
"friction_example": {"description": "<what slipped>", "session_path": "<path>"},
"suggested_adjustment": "<concrete habit to try next time>"
}
]
}#### E.2, Skill proposals
Step 1, MANDATORY: enumerate what's already installed. Before you write a single proposal, list every skill the user already has access to:
# User-level skills
ls ~/.claude/skills/ 2>/dev/null
# Project-level skills (if present)
ls .claude/skills/ 2>/dev/null
# Plugin-namespaced skills (read SKILL.md frontmatter to capture `description`)
for f in ~/.claude/plugins/cache/*/*/skills/*/SKILL.md ~/.claude/plugins/*/skills/*/SKILL.md; do
[ -f "$f" ] && echo "=== $f ===" && head -5 "$f"
done 2>/dev/nullAlso scan the transcripts: any mcp__... tool call, any /<namespace>:<name> slash command the user has typed, and anything the coaching-panel.json cites as "you do this well already", all of those are skills already in play. Collect the full list into a working set before proposing anything.
Step 2, de-duplicate against reality. For every task cluster you might propose a skill for, ask:
description covers this territory? If yes, DO NOT propose a parallel skill. Either skip the proposal or reframe it as "enhance <existing-skill> with X", scoped narrowly to the gap.<existing-skill>", not a new skill.A proposal that duplicates an installed skill is a worse recommendation than no proposal at all. Five sharp proposals are better than five padded ones, and two sharp proposals beat five mediocre ones. Do not pad the list to reach 5.
Step 3, propose. Up to 5 atomic skills, each impacting ≥ 2 top tasks (breadth) and following the task-centric shape: prescriptive mandatory_steps, bundled sources-of-truth (guidelines, prior-art scripts, templates), fixed output_shape, invocation-as-slash-command. Avoid abstract workflow shapers ("opener-template", "staged-drafts", "checkpoint"), these sit outside a task and so don't get invoked in context.
For each proposal emit to out/skill-proposals.json:
name, slug for the skilltrigger_description, SKILL.md frontmatter descriptionmodelled_after, the existing installed skill it takes inspiration from, one line (REQUIRED, non-empty, references a real skill from Step 1)overlaps_considered, list of installed skills that cover adjacent territory + one-line why this proposal is still distinct (REQUIRED; empty list is only valid if the domain is genuinely uncovered)mandatory_steps, ordered list the skill runs every time (MANDATORY reads of guidelines/prior-art/references)output_shape, fixed filename convention + required sectionstasks_impacted, ≥ 2 entries with task_id + why_relevantexpected_savings, small/medium/large + whyinvocation_hint, /skill-creator <name>Add a top-level _installed_skills_checked array to skill-proposals.json listing every skill enumerated in Step 1, so the user can verify the pre-check actually ran.
Do not skip. build_explorer.py refuses to run without out/persona.json.
~/.claude/skills/task-profile/scripts/persona_features.pyProduces out/persona-features.json with the numbers only.
~/.claude/skills/task-profile/references/personas.md (the 20-persona catalogue + fallback Explorer).out/persona-features.json, out/profile.json, out/coaching-panel.json, out/skill-proposals.json.modifier: null when none fits cleanly.out/persona.json:{
"id": "<persona-slug>",
"name": "<The Xxxx>",
"tagline": "<catalogue tagline>",
"modifier": "<slug or null>",
"confidence_note": "<why this persona beats the others, one sentence>",
"blurb": "<your rewritten 40–60-word blurb>",
"highlight_stat": {"label": "<short>", "value": <number>},
"top3_task_names": ["<short>", "<short>", "<short>"],
"features_used": { ... relevant numbers cited in the blurb ... }
}~/.claude/skills/task-profile/scripts/build_explorer.pyFixed light theme baked into the generator: off-white background, aquamarine accents, subtle dot-grid atmosphere, Geist sans-serif via Google Fonts, glassmorphism adapted for light. Single-file, no network at runtime (fonts via CDN). Data embedded as a JSON blob. Uses progressive disclosure, categories open to reveal tasks; tasks open to reveal friction and tokens; coaching and proposals open to reveal detail. Includes:
Open with open out/explorer.html.
Before considering the run done, scan out/profile.csv and the explorer for the top-100 highest-entropy tokens (any random-looking string of mixed case + digits ≥ 16 chars). These are the most likely way a secret slipped past automated redaction. Ask the user to confirm the scan is clean.
| File | Audience | Shape |
|---|---|---|
out/inventory.json | Internal | Full per-session rows with condensates |
out/clusters.json | Internal | [{cluster_id, label, session_paths}] |
out/payloads/*.json | Haiku subagents | Sampled condensates per cluster |
out/analyses/*.json | Internal | Haiku output, 1–3 tasks per cluster |
out/canonical-merges.json | Internal | Main-agent cross-cluster merge decisions |
out/profile.csv | Shareable with company | One row per canonical task |
out/profile.json | Feeds the explorer | Rich task rows + session detail |
out/coaching-panel.json | Feeds the explorer | Personal AI-first coaching cards |
out/skill-proposals.json | Feeds the explorer + user action | Up to 5 cross-cutting skill proposals |
out/explorer.html | Personal | Single-file UI with progressive disclosure |
references/task-style.md, CSV-style task sentence rules, good/bad examplesreferences/success-rubric.md, 4-level success taxonomy with signalsreferences/friction-signals.md, correction phrases + behavioural markersreferences/automation-filters.md, rules for flagging non-interactive sessionsreferences/redaction-rules.md, regex + heuristic rules for stripping secretsreferences/ai-first-principles.md, bootcamp + prompting principles used for coaching~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.