onboard-0bd675 — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited onboard-0bd675 (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Developer onboarding pipeline. Composes /map-codebase, /review-tooling, and /review-agentic-setup with inline agents, then synthesizes everything into .turbo/onboarding.md and .turbo/onboarding.html. Analysis-only.
At the start, use TaskCreate to create a task for each phase:
Use the Agent tool to launch all 6 agents below in a single assistant message so they run concurrently. Each Agent call uses model: "opus" and does not set run_in_background. Each Composed Skills agent invokes its assigned skill via the Skill tool; each Inline Agent follows its exploration brief directly.
Launch one Agent tool call per row. Each agent's prompt instructs it to invoke its assigned skill via the Skill tool.
| Skill | Onboarding role |
|---|---|
/map-codebase | Architecture understanding: structure, tech stack, entry points, patterns, data flow, dependencies, testing |
/review-tooling | Development workflow: linters, formatters, pre-commit hooks, test runners, CI/CD |
/review-agentic-setup | Agentic coding: CLAUDE.md, AGENTS.md, skills, MCP servers, hooks, cross-tool compatibility |
Launch one Agent tool call each with the exploration brief below.
| Agent | Exploration Brief |
|---|---|
| Prerequisites and Setup | Read README.md, CONTRIBUTING.md, and package manager configs (package.json, Gemfile, Cargo.toml, go.mod, pyproject.toml, Package.swift, etc.). Extract: required language runtimes and versions, system dependencies, environment variables, database or service requirements, first-time setup steps (install, build, run, seed), and any bootstrap or setup scripts. |
| Troubleshooting | Search for troubleshooting content in README.md, TROUBLESHOOTING.md, docs/ directory, FAQ files, and GitHub Discussions/Wiki if accessible. Extract common errors, known quirks, platform-specific gotchas, and debugging tips. If no troubleshooting docs exist, report that. |
| Next Steps | Run gh issue list --state open --json number,title,url,reactionGroups,comments,labels --limit 50. Identify: (1) issues labeled good-first-issue or good first issue, (2) top 5 issues by engagement score (sum of reactions weighted 2x for thumbs-up, plus comment count). If gh is not available or not in a GitHub repo, skip and note that. |
Each agent writes its findings as structured markdown.
After all agents complete:
.turbo/threat-model.md exists; if so, read it for the Security Considerations section./review-tooling findings become "Development Workflow" (what tools are used and how to run them). /review-agentic-setup findings become "AI-Assisted Development" (what's set up and how to use it). Focus on what exists, not what's missing. Strip severity labels, findings numbering, and gap framing from review skill outputs. Present detected tools and configurations as project conventions the new developer should know..turbo/onboarding.md using the report template. Output the welcome summary as text before writing the file.# Onboarding Guide
**Date:** <date>
**Project:** <project name>
## Welcome
<3-5 sentences: what this project is, who it's for, fastest path to a first contribution>
## Prerequisites and Setup
<from Prerequisites and Setup agent: language runtimes, dependencies, first-time setup steps, build/run commands>
## Architecture Overview
<from /map-codebase: condensed executive summary and key structural insights — not the full report, which lives at .turbo/codebase-map.md>
## Development Workflow
<from /review-tooling: reframed as "how to develop" — what linters/formatters to run, how to test, pre-commit hooks, CI/CD pipeline>
## AI-Assisted Development
<from /review-agentic-setup: reframed as "how to use AI coding tools" — what CLAUDE.md/AGENTS.md cover, installed skills, MCP servers, cross-tool compatibility>
## Security Considerations
<from .turbo/threat-model.md if present: key trust boundaries, security-sensitive areas, and what to be careful with — or omit this section if no threat model exists>
## Troubleshooting
<from Troubleshooting agent: common errors, known quirks, debugging tips, or "no troubleshooting docs found">
## Next Steps
<from Next Steps agent: good-first-issue issues, top-engaged issues, or "no GitHub issues found">Convert the markdown report into a styled, interactive HTML page.
/frontend-design skill to load design principles..turbo/onboarding.md for the full report content..turbo/onboarding.html (single file, no external dependencies beyond Google Fonts) that presents the onboarding guide with:@media print/map-codebase skill produces its own full report at .turbo/codebase-map.md. The onboarding guide includes a condensed summary and links to the full report.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.