cursorrules-cfd896 — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited cursorrules-cfd896 (Rules) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Six tools. One install.
A single installable toolkit that brings six WhenLabs developer tools into your Claude Code workflow. After install, the tools are exposed over a single MCP server and Claude calls them automatically when relevant.
<p align="center"> <img src="demos/hero.gif" alt="when doctor — six tools, one unified health report" width="820" /> </p>
npx @whenlabs/when installOne-time setup. The installer:
whenlabs) in your Claude Code configurationvelocity-mcp registration (velocity is now bundled)| Tool | Purpose |
|---|---|
| aware | Auto-detect stack and generate AI context files (CLAUDE.md, .cursorrules, …) |
| berth | Detect port conflicts before starting dev servers |
| envalid | Validate .env files against a schema |
| stale | Detect documentation drift between docs and code |
| vow | Scan dependency licenses and validate against policy |
| velocity | Time coding tasks and learn from historical data |
Eight endpoints across the six tools:
| Endpoint | What it does |
|---|---|
aware_sync | Detect stack and regenerate AI context files |
berth_check | Scan project for port conflicts |
envalid_validate | Validate .env files against schema |
stale_scan | Detect documentation drift |
vow_scan | Scan licenses and validate against policy |
velocity_start_task | Start timing a coding task |
velocity_end_task | End timing and record results |
whenlabs_summary | Unified rollup across all five scanners in one call |
All eight are served by the single whenlabs MCP server (stdio, Node 20+). Fix/init/auxiliary commands remain available via each tool's CLI (npx @whenlabs/<tool> --help).
when init # Onboard a project — detect stack, bootstrap configs, run all checks
when doctor # Run all six tools and show a unified health report
when install # Register MCP server in Claude Code
when uninstall # Remove MCP serverFor per-tool operations, use the tool directly:
npx @whenlabs/stale scan
npx @whenlabs/envalid validate
npx @whenlabs/berth check
npx @whenlabs/aware sync
npx @whenlabs/vow scanIf you're not using the install command, add this to your Claude Code MCP config:
{
"mcpServers": {
"whenlabs": {
"command": "npx",
"args": ["@whenlabs/when", "when-mcp"]
}
}
}MIT — see LICENSE
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.