cm-start-1ccac4 — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited cm-start-1ccac4 (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
/cm-start [your objective]Role: Workflow Orchestrator — You assess complexity, select the right workflow depth, and drive execution from objective to production code.
When this workflow is called, the AI Assistant should execute the following action sequence in the spirit of the CodyMaster Kit:
Per _shared/helpers.md#Load-Working-Memory — use Smart Spine order:
.cm/context-bus.json → any active pipeline? any prior skill output to reuse?learnings-index.md (~100 tok) + skeleton-index.md (~500 tok)cm_query — only load what matches current objectiveCONTINUITY.md → set Active Goal to the new objectivecm continuity budget → confirm no category is over soft limit⚡ Total context load: ~700 tokens. Full load used to be ~3,200. Only escalate to L2 (full files) if L0 index explicitly flags a match.
0.5. Skill Coverage Check (Adaptive Discovery):
cm-skill-index Layer 1 triggerscm-skill-mastery Part C:npx skills find "{keyword}" → review → ask user → install if approved
.cm-skills-log.json0.6. Stack & Tier Detection (Phase 2):
cm stack detect --write → writes .cm/project-skills.md (frameworks + suggested skills)cm tier classify --write → writes .cm/project-tier.md (LITE/STANDARD/PROFESSIONAL/ENTERPRISE)0.7. Code Intelligence Setup (cm-codeintell):
bash scripts/index-codebase.sh → .cm/skeleton.md.cm/skeleton.md (~5K tokens) → instant codebase understanding.cm/architecture.mmdcodegraph status → index if neededCONTINUITY.md/cm-start command.cm-planning).Per _shared/helpers.md#Project-Level-Detection
L0 (Micro): Code + Test only
cm-tdd directly → cm-quality-gateL1 (Small): Planning lite → Code → Deploy
cm-planning (lightweight implementation plan)cm-tdd + cm-execution → cm-quality-gateL2 (Medium): Full analysis flow
openspec/changes/[initiative-name]/ folder and artifacts manually)cm-brainstorm-idea if problem is ambiguouscm-planning (full implementation plan with OpenSpec tasks.md)cm-tasks.json from tasks.md → launch RARV autonomous executioncm-quality-gate → cm-safe-deployL3 (Large): Full + PRD + Architecture + Sprint
openspec/changes/[initiative-name]/ folder and artifacts manually)cm-brainstorm-idea (mandatory)cm-planning with FR/NFR requirement tracingopenspec/changes/[objective]/tasks.md sync with cm-tasks.jsoncm-execution (Mode E: TRIZ-Parallel for speed)cm-quality-gate → cm-safe-deployopenspec/changes/[objective]/tasks.md (for standardized spec tracking)cm-tasks.json (for autonomous agent execution)/cm-dashboard for visual tracking/cm-status for quick terminal summaryPer _shared/helpers.md#Update-Continuity
cm continuity bus → verify context bus reflects completed stepcm continuity index (auto-runs on addLearning, manual refresh here)Note for AI: If this is a brand new project, suggest runningcm-project-bootstrapfirst. If the working environment has a risk of accidentally switching accounts/projects, remind aboutcm-identity-guard(Per_shared/helpers.md#Identity-Check).
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.