tarnished — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited tarnished (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
The unified entry point for all Rune workflows. Understands natural language, routes to the correct skill, checks prerequisites, and chains multi-step workflows.
References:
Read $ARGUMENTS. Three paths:
Path A — Empty input (no arguments):
→ Enter interactive mode
→ Scan current project state (plans/, tmp/, git status)
→ AskUserQuestion: "What would you have the Tarnished do?"
Options based on current state:
- If uncommitted changes exist: "Review my changes" (→ appraise)
- If plans/ has recent plans: "Implement latest plan" (→ strive)
- If TOME exists: "Fix review findings" (→ mend)
- If docs/brainstorms/ has recent brainstorms: "Continue brainstorming" (→ brainstorm)
- Always: "Brainstorm an idea" (→ brainstorm)
- Always: "Plan a new feature" (→ devise)Path B — Fast-path keyword (first word matches a known skill):
→ Extract first word from $ARGUMENTS
→ Match against fast-path keyword table (see intent-patterns.md)
→ If match: route immediately to target skill with remaining args
→ Example: "plan add auth" → Skill("rune:devise", args: "add auth")Fast-path keywords: plan, work, review, brainstorm, explore, devise, strive, appraise, audit, arc, forge, mend, inspect, goldmask, elicit, rest, variant-hunt, supply-chain-audit, post-findings, ship, fix, debug, cancel, file-todos, resolve-comments, resolve-comment, resolve-todos, skill-testing, status, team-delegate, self-audit.
Note:verifyandarc-quickare no longer fast-path keywords — both were absorbed in v3.0.0-alpha.6 into flags on/rune:inspect(--verify-tome) and/rune:arc(--quick-mode) respectively. Natural-language phrasing for these is still picked up via the catalog in skill-catalog.md.
Path C — Natural language (no keyword match):
→ Read references/intent-patterns.md for classification rules
→ Classify intent into: direct | chain | contextual | exploratory | meta
→ Route based on classification (see Phase 2)#### Direct Intent (single skill)
The input clearly maps to one Rune skill. Route immediately.
Invoke via: Skill("{skill-name}", args: "{extracted args}")#### Chain Intent (multi-step)
Connectors detected: "then", "and", "after that", "rồi", "sau đó", "xong thì".
1. Read references/workflow-chains.md
2. Match to a defined chain pattern
3. Present the chain to user:
The Tarnished charts the path:
Step 1: {description} → /rune:{skill1}
Step 2: {description} → /rune:{skill2}
4. AskUserQuestion:
- "Proceed with full chain"
- "Just step 1"
- "Modify the plan"
5. Execute step by step with confirmation between steps#### Contextual Intent (needs prerequisite check)
Input implies a skill but doesn't specify required input (e.g., "implement it" without a plan path).
1. Read references/skill-catalog.md for prerequisite map
2. Scan for required artifacts:
- Plans: Glob("plans/*.md") → sort by date → latest
- TOMEs: Glob("tmp/reviews/*/TOME.md") or Glob("tmp/audit/*/TOME.md")
- Git changes: Bash("git diff --stat HEAD")
3. If prerequisite found → route with artifact path
4. If prerequisite missing → guide user:
"No plan found. Would you like to create one first?"
→ AskUserQuestion with options#### Exploratory Intent (discussion/research first)
User wants to think before acting.
1. If idea exploration / brainstorm intent → Skill("rune:brainstorm", args: "{topic}")
2. If structured reasoning needed → Skill("rune:elicit", args: "{topic}")
3. If research needed → gather context inline (Read, Grep, Glob)
4. After exploration, suggest next step:
"Ready to create a plan?"
→ AskUserQuestion#### Meta Intent (about Rune)
User asks about capabilities or status.
"help" / "what can you do":
→ Display capability summary from skill-catalog.md
→ Highlight most common commands
"status" / "what's next":
→ Scan artifacts:
- plans/ for recent plans
- tmp/reviews/ for recent TOMEs
- tmp/work/ for recent work sessions
- git status for uncommitted changes
→ Suggest logical next stepFor single-step routing:
Invoke: Skill("{target-skill}", args: "{passthrough args}")For chain execution:
1. Invoke step 1: Skill("{skill1}", args: "{args1}")
2. After completion, check next step prerequisites
3. AskUserQuestion: "Step 1 complete. Proceed to step 2?"
4. If yes → Invoke step 2: Skill("{skill2}", args: "{args2}")
5. Repeat until chain completeUse Rune's Elden Ring-inspired tone, brief and purposeful:
The Tarnished heeds your call.
→ Routing to /rune:devise — planning "add user authentication"...The Tarnished charts the path:
Step 1: Review → /rune:appraise
Step 2: Mend → /rune:mend {TOME from step 1}
Shall we proceed?The Tarnished surveys the Lands Between...
📋 1 plan found: plans/2026-02-25-feat-auth-plan.md
📝 No active reviews
🔀 12 files changed (uncommitted)
What would you have me do?When the user asks questions about Rune (how it works, what to do, best practices), load rune-knowledge.md and provide educational guidance.
/rune:tarnished help
/rune:tarnished what can you do?
/rune:tarnished rune là gì?→ Read references/rune-knowledge.md → Present a concise overview tailored to the user's apparent experience level → Suggest the most relevant next action based on current project state
/rune:tarnished what should I do next?
/rune:tarnished tôi nên làm gì tiếp?→ Scan project state (plans/, tmp/, git status, git log) → Read references/rune-knowledge.md "Decision Tree" section → Recommend the logical next step with explanation
/rune:tarnished how do I review code?
/rune:tarnished explain the arc pipeline
/rune:tarnished khi nào nên dùng audit vs review?→ Read references/rune-knowledge.md for relevant section → Read references/skill-catalog.md for details → Explain with context from the user's actual codebase
/rune:tarnished add agent
/rune:tarnished custom reviewer
/rune:tarnished which agents
/rune:tarnished force agent
/rune:tarnished always use agent→ For "add agent" / "custom reviewer" / "custom ash": Guide user to add a custom Ash via the orchestration layer (.claude/agents/<name>.md) — the legacy ashes.custom[] registry was removed in v3.0.0-alpha.4. See plugins/rune/skills/roundtable-circle/references/custom-ashes.md for the wiring pattern. Then suggest: "Create the agent at .claude/agents/my-reviewer.md" Or route to: plugins/rune/skills/roundtable-circle/references/custom-ashes.md (custom-ash wiring reference)
→ For "which agents" / "agent list" / "list agents": Route to: Skill("rune:ash-guide")
→ For "force agent" / "always use agent" / "always run agent": In v3.x, custom Ashes are wired in the orchestration layer rather than configured. Route to: plugins/rune/skills/roundtable-circle/references/custom-ashes.md for the cli: field contract and trigger.always semantics. Guide the user to create the agent at .claude/agents/<name>.md and update the relevant skill's summon list. The legacy ashes.custom[] YAML block was removed in v3.0.0-alpha.4 alongside the talisman.yml config layer.
/rune:tarnished the review found too many issues
/rune:tarnished arc failed at mend phase
/rune:tarnished how to resume?→ Read references/rune-knowledge.md "Common Pitfalls" section → Provide specific, actionable guidance
Use AskUserQuestion with the top 2-3 interpretations.
Explain the dependency and suggest the correct chain.
tmp/.rune-*.json state files.Warn if a workflow is active and suggest waiting or cancelling.
--quick, --deep, --approve pass throughto the target skill unchanged. Example: /rune:tarnished plan --quick add auth → Skill("rune:devise", args: "--quick add auth")
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.