upkeep-audit — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited upkeep-audit (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Run the full Upkeep audit pipeline (discovery → parallel reviewers → synthesis → HTML report) against a local repository. Output-only: the target repo is never modified.
~/.cache/upkeep:git clone --depth 1 https://github.com/wei18/upkeep ~/.cache/upkeepgit -C ~/.cache/upkeep pull --ff-only (if the pull fails — diverged or dirty checkout — delete ~/.cache/upkeep and re-clone; it is disposable)(cd ~/.cache/upkeep && npm ci) after a fresh clone or whenever the pull changed package-lock.json (when unsure, run it — it is idempotent).claude -p subprocesses — run it in the background and report progress): ~/.cache/upkeep/scripts/local-audit.sh <target-path> [--model M] [--rubric-lang L] [--max-turns N] [--out FILE]Pass flags only when the user asked for them, with one exception: the report defaults to ./upkeep-report.html in the current working directory, so if the working directory is inside the target repo, pass --out pointing outside it (e.g. ~/upkeep-report.html) — the audit must never write into the target repo. Other defaults match the CI inputs (claude-opus-4-8, rubric en, 30 turns); --rubric-lang accepts en or zh-TW.
upkeep-report.html by default, or the --out path). If any reviewers failed, name them.claude CLI installed and logged in (Claude Pro/Max subscription).~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.