mirror of
https://github.com/alirezarezvani/claude-skills.git
synced 2026-09-07 08:26:02 +00:00
6 commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
08740d4ec2
|
fix(stream): post-merge required changes for PRs #895/#926/#942/#943/#944/#965 + counter true-up + #964 guard + #954 doc drift
Applies every pre-merge required change from audit/pr-stream-2026-08/ that could not land on contributor forks, plus the stream's cross-cutting fixes: - stock-analysis (#944): description trimmed 1463 -> 1001 chars; Anti-Patterns + Cross-References sections added; security-auditor false positive at holdco-assetmgr.md:58 suppressed inline (auditor:ignore-line) -> strict PASS - deepread (#965): renamed research/dsh-deepread -> research/deepread; H1 and name updated; research-summarizer cross-ref path-qualified; 12 cited sources added across both references; plugin.json + marketplace entry; routed in the research orchestrator (SKILL.md registry + SIGNALS + classifier.py in lockstep, verified: 'deeply read this pdf' -> deepread, 3 signals) - business-name-fit (#926): 'Use whenever' -> 'Use when' (validator trigger regex); +2 cited sources (USPTO TMEP §1209, Usunier & Shaner 2002) -> 5 - embedded-iot-mentor (#942): references/hardware-selection.md (7 sources, datasheet-anchored) + worked mini-example; validator length gate now passes - swedish-mentor (#943): references/swedish-resources.md (6 sources, stable official URLs only); session recipes, milestones, learner situations, worked example; mandated opener softened to guidance; plugin.json + marketplace entry; validator length gate now passes - Related Projects (#895): LinkedIn Skills row trued up (10 -> 11 skills, hardcoded star count dropped) - check_plugin_json.py: marketplace description <= 1024 guard added to --all (the #964 regression guard; commercial-skills sits at 1021/1024) - #954 doc drift: quality_gates_for_skills.md, cs-skill-author.md, security-guidance SKILL.md now point attribution at authoring-notes.json - Counter true-up after the 6-skill merge batch: 370 skills / 672 tools / 809 refs / 92 plugins across README.md badge+table, CLAUDE.md, marketplace metadata (derive_counters.py --check passes) All gates green locally: frontmatter 0 errors, model freshness 0 findings, dual-publish 0 drifted, paths 0, smoke 0 failed, plugin-json 0 FAIL. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017Bzm6Pafyxja6g4jUDPcei |
||
|
|
7405298b4b
|
fix: resolve the actionable reported issues (#954, #949, #933, #931, #969, #968, #924, #885)
- #954: strip non-spec source/attribution keys from all 39 plugin.json manifests so Claude Code's validator accepts them; metadata preserved in new .claude-plugin/authoring-notes.json sidecars; check_plugin_json.py now hard-fails manifests carrying those keys and sanity-checks the sidecar; CLAUDE.md ClawHub schema section updated to the new rule. - #949: move the c-level-agents plugin out of c-level-advisor/ to a top-level directory so the two marketplace sources no longer overlap; updated marketplace.json source, homepage, descriptions, all cross-references, docs, harness manifest, mirror-tree symlinks/indexes, and rebased the moved files' relative links; domain counters trued up (18 -> 19 domains). - #933: replace dead links to the gitignored maintainer-local megaprompts/ tree with annotated plain-text references (44 files: SKILL.md, READMEs, agents, commands). - #931: DynamoDB on-demand pricing updated to post-Nov-2024 rates ($0.625/M writes, $0.125/M strongly consistent reads). - #969: skill_security_auditor.py and the three dossier scripts reconfigure stdout/stderr to UTF-8 (errors=replace) so legacy Windows codepages no longer crash at print time; PYTHONUTF8=1 documented. - #968: Windows Notes section in INSTALLATION.md + README pointer for the core.symlinks mirror-tree checkout caveat. - #924/#885 residuals: hook commands quote "${CLAUDE_PLUGIN_ROOT}" paths in all plugin hooks.json/settings.json (space-safe roots); removed the stale pre-rename status/review mirror symlinks and index entries left over from the memory-status/memory-review rename. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qgc6RYXWJPr5oW9DHU7zR4 |
||
|
|
b19c40cf95
|
feat(engineering): add book-to-skill — compile documents into knowledge-base skills
Derived from virgiliojr94/book-to-skill (MIT). Compiles a book, docs folder, or
spec collection (PDF, EPUB, DOCX, HTML, Markdown, RST, AsciiDoc, RTF, MOBI/AZW)
into an agent skill: a resident master SKILL.md (core frameworks + chapter index
+ topic index, capped at 4k tokens) plus on-demand chapter files, a glossary, a
patterns file, and a decision cheatsheet.
The extraction library (scripts/book_to_skill/, 12 modules incl. 7 per-format
parsers) is vendored close to verbatim and keeps upstream's format chains,
chapter detection across Latin/Roman/Chinese/Thai/Korean heading styles,
invisible-Unicode (Trojan Source) sanitization, and the DOCX entity guard.
12 numbered deviations recorded in the plugin README (authoritative list):
- No implicit installs: --install-missing defaults to `report`, printing the pip
command and using the stdlib fallback, where upstream prompts on a TTY and
installs into the caller's environment.
- Rights gate: emitting a shareable package refuses without --rights from
public-domain|open-license|internal-docs|author-permission. `fair-use` is
deliberately excluded — a defence, not a licence.
- Validator merged and extended: upstream's two validators become one four-family
gate, adding budget (token caps) and index (dead chapter links, unindexed
chapters, dangling topic refs) — the failure that silently breaks navigation
while the skill still looks complete.
- Folded YAML scalars now parse, so a wrapped description no longer under-reports
its length past the 1024-char cap.
- token_budget_estimator replaces discovery_tax: tiktoken path dropped for one
deterministic estimator, post-flight budget audit added, plus an explicit
worth-converting verdict that says "just read it" below ~3x the compiled size.
- Two PRIV-ESC criticals fixed: upstream install hints contained a literal
`sudo apt install`; they now name the package manager without escalating.
Repo-native addition with no upstream counterpart — Step 11 / /cs:book-to-plugin:
upstream stops at a bare ~/.claude/skills folder this library cannot route to.
skill_plugin_emitter.py wraps a compiled skill as a full plugin package (manifest
+ cs-<slug> agent + /cs:<slug> command + README) and prints the marketplace entry
without editing marketplace.json. Its --force path is guarded against symlinks,
paths outside the destination root, and non-package directories.
Ships 4 stdlib-only tools (all --help/--sample/--output json), 5 references citing
7-8 sources each, 3 asset templates, cs-book-to-skill agent, 2 commands.
Cross-linked into write-a-skill ("author first, compile second").
Regenerated the engineering harness manifest: picked up book-to-skill plus three
skills that had drifted out (minimalist, skillopt-sleep, strict-api), 81 -> 85.
Counters: skills 362 -> 363, tools 644 -> 662, refs 741 -> 746, agents 102 -> 103,
commands 116 -> 118, plugins 88 -> 89 (derive_counters.py --check passes).
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017zu9Gmm9S78c2t3kDLnpPX
|
||
|
|
0f88555485
|
chore(versioning,docs): normalize stale versions to 2.9.0 + refresh counts
Version normalization (scope: only plugins/skills older than 2.7.0): - Bumped 52 plugin.json + 21 SKILL.md `version` fields from pre-2.7.0 values (1.0.0 / 2.0.x / 2.2.x / 2.3.x / 2.4.x / 2.5.x) to 2.9.0. Left 2.7.0+ packages untouched. Tool mirrors (.codex/.gemini/.vibe/ .hermes) excluded. All manifests still pass check_plugin_json --all. Doc count refresh (recomputed raw figures: 338 skills, 16 domains, 62 plugins, 533 Python tools, 676 references): - marketplace.json: both descriptions + metadata.version -> 2.9.0. - Root README: headline, badges (Skills 338, Agents 51+, Commands 87+), intro counts, convert section (338 skills / 9 tools), and the full domain table rebuilt to 16 domains summing to 338 (adds research-ops, business-operations, commercial, compliance-os; corrects product 17, marketing 46, c-level 66, ra-qm 18, finance 4, engineering 51/78). - Fixed stale per-skill README `Version:` lines left inconsistent by the bump (andreessen, c-level-agents, product-team, senior-qa). - Fixed stale domain README footers (product-team 17/17, c-level 66/66, project-management 9/9). - CLAUDE.md scope line, structure tree, highlight, and footer synced to the raw figures. https://claude.ai/code/session_01PUNmQVE4WYvcrzpq2anC3D |
||
|
|
d3c822a517
|
fix(v2.6.1): expand validator trigger patterns + fix 10 placeholder descriptions
Follow-up to v2.6.0. Uses the audit_skills.py tool (shipped in #646) to identify real bugs vs validator false-positives across 298 repo skills, then fixes both. Three coordinated changes: 1. Validator trigger pattern expansion (write-a-skill internal tools) - Old: only "Use when", "Use for", "Invoke when", "Trigger when" recognized - New: + "Use before/during/after/while", "Invoke before/after", "Apply when", "Run when/before" - Why: 11 legacy skills had semantically-valid triggers (e.g., gdpr-audit-prep says "Use before annual GDPR review") that the v2.6.0 validator wrongly flagged as missing. Natural English variants now accepted. - Impact: 30 skills reclassified from FAIL → WARN/PASS automatically. - Karpathy complexity: 100/100 (PASS) on both modified validators. 2. Ten placeholder descriptions fixed in engineering/skills/ The audit revealed 21 skills (~7% of repo) with broken descriptions that were literally just the skill name (e.g., description: "Migration Architect"). These were real bugs from a v2.0.0 batch import where the description field was never filled in. Top-10 fixed in this PR (POWERFUL-tier, high-visibility): - migration-architect: zero-downtime migration planning + rollback strategy - dependency-auditor: vulnerabilities + license + safe-upgrade audit - codebase-onboarding: codebase analysis + onboarding doc generation - ci-cd-pipeline-builder: pragmatic CI/CD from project stack signals - mcp-server-builder: MCP servers from OpenAPI contracts (Python + TS) - observability-designer: metrics + logs + traces + SLI/SLO design - api-design-reviewer: REST design review + breaking-change detection - performance-profiler: Node/Python/Go profiling + flamegraphs + load tests - changelog-generator: Conventional Commits → release notes automation - runbook-generator: operational runbooks from service name + templates Each new description: ≤1024 chars, third person, action verb in first sentence, "Use when ..." trigger in second sentence per Matt Pocock's rule. Remaining 11 placeholder descriptions tracked for v2.6.2. 3. Quality-gates reference updated (Option C: legacy advisory) quality_gates_for_skills.md now explicitly documents the binding-for-new vs advisory-for-legacy split. The 6-item checklist remains BLOCKING for post-v2.6.0 skills and ADVISORY for the 298 legacy SKILL.md files. Audit report drift is tracked separately; PASS count is the metric to grow, not a force-march-to-Friday deadline. Aggregate audit improvement (against the 298 real-skill cohort): - PASS: 4 (1%) → 7 (2%) - WARN: 111 (37%) → 134 (45%) - FAIL: 183 (61%) → 157 (53%) - "Missing trigger" failures: 119 (39%) → 79 (26%) 26 skills total lifted from FAIL → WARN/PASS in this PR. Highest-leverage fix per hour of any v2.6.x cleanup since the v2.6.0 release. https://claude.ai/code/session_01VFreMf7XLBqMgjsrG4wSYe |
||
|
|
a31dad3a44
|
feat(write-a-skill): derive from Matt Pocock (MIT) + add validation wrapper
Stream B PR 1 of 2 — the skill-author skill that gives us the meta-tool to build the rest of Matt Pocock's productivity skills (caveman, grill-me, handoff) with consistent quality gates. Derived from Matt Pocock's write-a-skill (MIT-licensed): https://github.com/mattpocock/skills/tree/main/skills/productivity/write-a-skill Matt's SKILL.md content + 3-phase workflow (Gather -> Draft -> Review) preserved verbatim per MIT license. Attribution: README.md + plugin.json description + SKILL.md frontmatter metadata + every file footer cites Matt + links to original. Additions on top of Matt's original (the "hybrid voice" approach): 3 stdlib Python validation tools: - skill_description_validator.py: 5-check verdict per Matt's 4 format rules (description present, <=1024 chars, third person, "Use when" trigger, action verb in first sentence). Action-verb vocabulary extracted as module constant. - skill_structure_validator.py: 6-check verdict (SKILL.md present, line count, references when split needed, one-level-deep, no circular refs, scripts/ folder note). Refactored to extract _list_md_in_subdir + _collect_links_for_file helpers to keep nesting depth <= 4 per karpathy-coder. - skill_review_checklist_runner.py: combined verdict running all 6 items from Matt's review checklist. Refactored _find_nested_md helper for nesting. 4 in-depth references (each citing 7-8 authoritative sources): - companion_tooling.md: tool catalogue + cs-* wrapper rationale - progressive_disclosure_principles.md: 100-line ceiling + one-level-deep rule with sources (Matt, Anthropic, Don Norman, Pirolli & Card, Maeda, DocOps) - description_design_patterns.md: good vs bad description patterns with sources (Matt, Anthropic, Garrett, Nielsen Norman, Karpathy) - quality_gates_for_skills.md: the 6 mandatory gates + CI integration with sources (Matt, Humble & Farley, Kim et al., Hyrum's Law) cs-skill-author persona agent + /cs:write-a-skill slash command: - Forcing-question interrogator pattern matching our cs-* convention - 6 forcing questions mirroring Matt's 6 review-checklist items - Routes to validators + karpathy-coder gate + attribution check Karpathy-coder validation (full sweep): - complexity_checker: 100/100 across all 3 tools (0 findings) - assumption_linter: CLEAN on all 3 tools - All 3 tools: PASS text + PASS JSON output - All 4 references cite >= 7 authoritative sources (range 7-8) Self-validation note: this skill's own SKILL.md is 141 lines (over Matt's 100-line ceiling) because it preserves Matt's full content verbatim + adds attribution + tooling references. The structure_validator + checklist_runner correctly WARN on this — documented in progressive_disclosure_principles.md as the wrapper-derived exception. README.md absorbs the attribution overhead so SKILL.md stays close to Matt's original size. 12 files, 1,689 insertions. License: MIT (matching Matt's upstream). https://claude.ai/code/session_01VFreMf7XLBqMgjsrG4wSYe |