session-start — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited session-start (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Get your bearings before doing any work. Every session starts here.
Core principle: Understand the current state before taking action.
Announce at start: "I'm using session-start to get oriented before beginning work."
Execute these steps in order at the start of every session:
Verify required tools and environment variables are available.
# Check GitHub CLI authentication
gh auth status
# Check git is available
git --version
# Verify GITHUB_PROJECT is set
echo $GITHUB_PROJECTIf any check fails: Report to user before proceeding.
Skill: environment-bootstrap
Check for available development services (docker-compose).
# Detect compose services
if [ -f "docker-compose.yml" ] || [ -f ".devcontainer/docker-compose.yml" ]; then
docker-compose config --services
docker-compose ps
fiKey questions:
If services are available but not running:
# Start all services
docker-compose up -d
# Or start specific service
docker-compose up -d postgresSkill: local-service-testing
Understand the current state of the repository.
# Current branch
git branch --show-current
# Working directory status
git status
# Recent commits
git log --oneline -5
# Any stashed changes?
git stash listKey questions:
Check the current state of work via the GitHub Project Board (the source of truth).
CRITICAL: Use `github-api-cache` to minimize API calls.
# === CACHE INITIALIZATION (3 API calls total) ===
# This replaces 20+ individual API calls
echo "Initializing GitHub API cache..."
# CALL 1: Cache all project fields
export GH_CACHE_FIELDS=$(gh project field-list "$GITHUB_PROJECT_NUM" --owner "$GH_PROJECT_OWNER" --format json)
# CALL 2: Cache all project items
export GH_CACHE_ITEMS=$(gh project item-list "$GITHUB_PROJECT_NUM" --owner "$GH_PROJECT_OWNER" --format json)
# CALL 3: Get project ID
export GH_PROJECT_ID=$(gh project list --owner "$GH_PROJECT_OWNER" --format json --limit 100 | \
jq -r ".projects[] | select(.number == $GITHUB_PROJECT_NUM) | .id")
# Extract field IDs from cache (NO API CALLS)
export GH_STATUS_FIELD_ID=$(echo "$GH_CACHE_FIELDS" | jq -r '.fields[] | select(.name == "Status") | .id')
export GH_STATUS_IN_PROGRESS_ID=$(echo "$GH_CACHE_FIELDS" | jq -r '.fields[] | select(.name == "Status") | .options[] | select(.name == "In Progress") | .id')
export GH_STATUS_DONE_ID=$(echo "$GH_CACHE_FIELDS" | jq -r '.fields[] | select(.name == "Status") | .options[] | select(.name == "Done") | .id')
echo "Cached $(echo "$GH_CACHE_ITEMS" | jq '.items | length') project items"Query from cache (NO API CALLS):
# Get all project items with their status (from cache)
echo "$GH_CACHE_ITEMS" | jq '.items[] | {number: .content.number, title: .content.title, status: .status.name}'
# Get Ready issues (from cache)
echo "$GH_CACHE_ITEMS" | jq -r '.items[] | select(.status.name == "Ready") | .content.number'
# Get In Progress issues (from cache)
echo "$GH_CACHE_ITEMS" | jq -r '.items[] | select(.status.name == "In Progress") | .content.number'
# Get Blocked issues (from cache)
echo "$GH_CACHE_ITEMS" | jq -r '.items[] | select(.status.name == "Blocked") | .content.number'Key questions:
Skill: github-api-cache
MANDATORY: Verify project board state matches actual work state.
Uses cached data from Step 3 - NO additional API calls for project queries.
# Check for sync issues between project board and reality
# ALL project queries use GH_CACHE_ITEMS (cached in Step 3)
echo "## Project Board Sync Check"
echo ""
# 1. Issues marked "In Progress" should have active branches (0 API calls)
echo "### Checking: In Progress issues have branches"
for issue in $(echo "$GH_CACHE_ITEMS" | jq -r '.items[] | select(.status.name == "In Progress") | .content.number'); do
branch=$(git branch -r 2>/dev/null | grep -E "feature/$issue-" | head -1)
if [ -z "$branch" ]; then
echo "⚠️ Issue #$issue is 'In Progress' but has no branch"
fi
done
# 2. Active branches should have issues marked "In Progress" (0 API calls)
echo ""
echo "### Checking: Active branches have In Progress issues"
for branch in $(git branch -r 2>/dev/null | grep -E 'origin/feature/[0-9]+' | sed 's/.*feature\///' | cut -d- -f1 | sort -u); do
status=$(echo "$GH_CACHE_ITEMS" | jq -r ".items[] | select(.content.number == $branch) | .status.name")
if [ "$status" != "In Progress" ] && [ "$status" != "In Review" ]; then
echo "⚠️ Branch for #$branch exists but project Status='$status' (expected: In Progress or In Review)"
fi
done
# 3. Open PRs should have issues marked "In Review" (1 API call for PR list - REST API)
echo ""
echo "### Checking: Open PRs have In Review issues"
for pr in $(gh pr list --json number,body --jq '.[] | select(.body | contains("Closes #")) | .body' 2>/dev/null | grep -oE 'Closes #[0-9]+' | grep -oE '[0-9]+'); do
# Use cached items, not API call
status=$(echo "$GH_CACHE_ITEMS" | jq -r ".items[] | select(.content.number == $pr) | .status.name")
if [ "$status" != "In Review" ]; then
echo "⚠️ Issue #$pr has open PR but project Status='$status' (expected: In Review)"
fi
done
echo ""
echo "Sync check complete."If sync issues found:
Skill: project-board-enforcement
CRITICAL: Check if autonomous orchestration was running and needs to resume.
# Check MCP Memory for active orchestration marker
ACTIVE_ORCH=$(mcp__memory__open_nodes({"names": ["ActiveOrchestration"]}))If ActiveOrchestration entity exists:
## ⚠️ ACTIVE ORCHESTRATION DETECTED
**Status:** [from entity]
**Scope:** [from entity]
**Tracking Issue:** #[from entity]
**Last Loop:** [from entity]
**Repository:** [from entity]
### Action Required
Context was compacted mid-orchestration. Resuming now.
1. Verify tracking issue still exists
2. Resume orchestration via `autonomous-orchestration` skill
3. Continue from current phase (BOOTSTRAP or MAIN_LOOP)Resume orchestration immediately - do not wait for user input. The original request for autonomous operation is still the active consent.
If no ActiveOrchestration entity: Continue to Step 4.
Search for relevant context from previous sessions.
Episodic Memory:
Knowledge Graph (mcp__memory):
Skill: memory-integration
Determine if there's work in progress to resume.
Indicators of active work:
If active work detected:
issue-driven-development processIf starting fresh or environment needs setup:
# Run init script if it exists
if [ -f scripts/init.sh ]; then
./scripts/init.sh
fi
# Or common alternatives
pnpm install --frozen-lockfile # Node projects
pip install # Python projectsVerify basic functionality works before starting new work.
Skill: environment-bootstrap
Summarize current state to user:
## Session State
**Repository:** [owner/repo]
**Branch:** [current branch]
**Working Directory:** [clean/dirty]
**Active Work:**
- Issue: #[number] - [title]
- Status: [project status]
- Progress: [what's been done]
**Environment:**
- [tool versions]
- [any issues detected]
**Development Services:**
- postgres: [running/stopped] @ localhost:5432
- redis: [running/stopped] @ localhost:6379
- [other services from docker-compose]
**Ready to:** [resume work on X / start new issue / await instructions]Start Session
│
▼
┌─────────────────┐
│ Environment OK? │──No──► Report issues, await fix
└────────┬────────┘
│ Yes
▼
┌─────────────────┐
│ On main branch? │──Yes──► Ready for new work
└────────┬────────┘
│ No
▼
┌─────────────────┐
│ Uncommitted │──Yes──► Resume in-progress work
│ changes exist? │
└────────┬────────┘
│ No
▼
┌─────────────────┐
│ Issue marked │──Yes──► Resume in-progress work
│ In Progress? │
└────────┬────────┘
│ No
▼
Ready for new workIf resuming work from a previous session:
issue-driven-development stepsThen continue from the appropriate step in issue-driven-development.
If no work in progress:
issue-driven-development from Step 1| Issue | Resolution |
|---|---|
| GITHUB_PROJECT not set | Ask user for project URL |
| Not authenticated to gh | Run gh auth login |
| Dirty working directory on main | Stash or discard before proceeding |
| Issue "In Progress" but branch deleted | Reset issue status, start fresh |
Before proceeding to work:
Skills: github-api-cache, project-board-enforcement
After session-start completes, proceed to either:
issue-driven-developmentissue-driven-development from Step 1Always operate under autonomous-operation mode.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.