agent-guidance-factory — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited agent-guidance-factory (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Create source-controlled instructions that coding agents actually load and can follow. These files guide behavior; they do not replace linters, hooks, tests, permissions, or other enforcement.
Read references/agent-guidance-files.md before creating, migrating, or materially changing AGENTS.md, CLAUDE.md, .claude/rules/, or .cursor/rules/.
AGENTS.md for shared repository guidance. Use CLAUDE.md only for Claude Code-specific behavior, and Cursor rules when structured metadata, glob attachment, or Team/User/Project rule behavior is required.
subtrees with different commands or constraints, and override files only when the target agent documents that override behavior.
docs, config, existing guidance files, PR templates, and recent commit messages. Verify commands from source files rather than inventing them.
that matter in most relevant sessions: layout, exact commands, coding conventions, test expectations, security/configuration boundaries, review expectations, and completion proof.
agent action, boundary, command, style rule, test rule, or contribution workflow. Move long procedures, architecture notes, release runbooks, and rare variants into linked docs or skills.
ask unless source evidence makes one rule clearly stale.
proof that is cheap and safe for the current host.
pipeline in references/agent-guidance-files.md before editing.
clear different character set.
paths, credentials, live tokens, or unverified service details.
review gates when a rule must be enforced.
stable project convention that a new contributor would need.
change.
Use only sections supported by evidence from the repository:
State the guidance files changed, why that scope was chosen, which source facts were verified, which checks ran, whether any agent visibility was verified, and what remains intentionally out of scope.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.