Source Command Track MentionsCAUTION
The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.
Overview
The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.
d90170da4369OBSERVED · 2026-10-07Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: "source-command-track-mentions" description: "Search for new online mentions of the Claude Code Ultimate Guide or Florian Bruniaux's public project portfolio and update the relevant tracker" --- # source-command-track-mentions Use this skill when the user asks to run the migrated source command `track-mentions`. ## Command Template # Track Mentions Workflow Find new online mentions of either the Claude Code Ultimate Guide or the wider public project portfolio. The guide catalog lives in `docs/media-mentions/mentions.yaml`. The cross-project catalog lives in `~/Sites/perso/florian-portfolio/src/data/mentions.json`. ## Usage ``` /track-mentions # Search + report new mentions, confirm before adding /track-mentions --dry-run # Search + report only, no YAML changes /track-mentions --scheduled # Unattended report-only run, equivalent to --dry-run /track-mentions --add-all # Add all confirmed results after explicit approval in this session /track-mentions --all-projects # Search the active GitHub portfolio and update the portfolio catalog /track-mentions --commit # Commit only the validated tracker files after an approved update ``` `--scheduled` always wins over write flags. A scheduled run must not edit files, create a commit, push, open a pull request, or publish a tracker update. ## Step 1: Load existing tracker For the default guide mode, read `docs/media-mentions/mentions.yaml` to get: - Current `meta.total_mentions` count - All existing `url` fields → build a deduplication set - `docs/media-mentions/review-queue.yaml` → keep inaccessible candidates pending and rejected URLs excluded For `--all-projects`: 1. Read the public `FlorianBruniaux` GitHub profile and list active repositories owned by that account. 2. Exclude forks, landing-only repositories, support repositories such as `homebrew-tap`, and RTK. 3. Read `~/Sites/perso/florian-portfolio/src/data/mentions.json` to get tracked projects, source URLs, and existing multi-project assignments. 4. Treat one canonical URL as one source even when it names several projects. ## Step 2: Run Perplexity deep research Use `mcp__perplexity__perplexity_research` with `reasoning_effort: "high"`. Append the normalized URLs from the confirmed catalog and review queue as `<KNOWN_URLS>`. Search broadly on every run instead of assuming that a weekly time window captures pages indexed late. ``` Find all articles, blog posts, newsletters, Reddit threads, Twitter/X posts, LinkedIn posts, YouTube videos, podcasts, GitHub issues/repos, and directories that mention "Claude Code Ultimate Guide" by Florian Bruniaux (GitHub: FlorianBruniaux/claude-code-ultimate-guide, website: cc.bruniaux.com). Search broadly for third-party content only - exclude the GitHub repo itself and cc.bruniaux.com own pages. Return exactly three groups: - `new_confirmed`: evidence is accessible and contains an explicit project identifier - `already_tracked`: canonical URL matches `<KNOWN_URLS>` - `rejected_or_unverified`: title collision, inaccessible evidence, owned property, or uncertain attribution For each result provide: canonical URL, publication date if available, author/platform name, language, project identifier found, evidence location, one sentence on how the source references the guide, classification, confidence, and metadata problems. Also search explicitly for: - "cc.bruniaux.com" cited as a resource on third-party sites - "claude-code-ultimate-guide florian bruniaux" in blog posts and tutorials - "FlorianBruniaux" in dev tutorials referencing the guide - The guide mentioned in non-English content (French, Spanish, German, Korean, Portuguese, etc.) Known canonical URLs for deduplication: <KNOWN_URLS> ``` **If Perplexity returns no results** (model refuses citing knowledge cutoff), fall back to WebSearch with these parallel queries: ``` "Claude Code Ultimate Guide" -site:github.com -site:cc.bruniaux.com site:reddit.com "cc.bruniaux.com" OR "Claude Code Ultimate Guide" site:dev.to OR site:hashnode.com OR site:medium.com "Claude Code Ultimate Guide" "florian" OR "bruniaux" "Claude Code Ultimate Guide" twitter OR x.com ``` Then use `WebFetch` on each candidate URL to verify the guide is explicitly mentioned by name or URL. Treat a result as confirmed only when the page itself, its public metadata, or an indexed snippet contains at least one project identifier: the guide name, the canonical repository slug, or `cc.bruniaux.com`. A matching generic title such as "ultimate Claude Code guide" is not enough. Classify every confirmed result before reporting it: - `editorial`: article, newsletter, podcast, or video with independent commentary - `social`: third-party LinkedIn, X, Instagram, or Facebook post - `forum`: Reddit, Hacker News, forum, or community discussion - `translation`: translated or adapted repository that credits the original - `mirror`: copied or republished guide content - `adoption`: a third-party repository visibly embeds, configures, or uses the project - `registry`: a package or protocol registry entry proving distribution coverage - `automated_directory`: generated index, catalog, MCP directory, or repository documentation service Do not count the project's own pages, the author's own social posts, GitHub topic pages generated from the repository's own metadata, or referral query parameters as earned third-party mentions. Keep automated directories separate from organic mentions. Flag incorrect install commands, package names, star counts, line counts, authorship, or capabilities instead of silently copying them. ## Step 3: Deduplicate For each result from Perplexity: 1. Normalize the URL (strip trailing slash, lowercase domain) 2. Check against existing URLs in the YAML 3. Check against pending and rejected URLs in `review-queue.yaml` 4. Resolve obvious redirects and compare the canonical destination 5. Skip if already tracked 6. Keep inaccessible candidates pending; never promote them from a repeated snipp
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (2)
whitepapers/recap-cards/en/_extensions
whitepapers/recap-cards/fr/_extensions
Gates applied: no_behavioural_pass.
d90170da4369full audit observations/trust-audit/skill/florianbruniaux__source-command-track-mentions.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | d90170da4369 | CAUTION | B | 89 | first audit |
Questions
What does the Source Command Track Mentions skill do?
The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.
Is Source Command Track Mentions safe to install?
With care. The audit graded it B (89/100) and found 2 things worth knowing before you trust this skill, listed below with the exact line each was found on.
What can Source Command Track Mentions access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Source Command Track Mentions work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (d90170da4369), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.