本文へ移動
cccskills
無料GitHub で公開

quality

AI code quality checks. The Big 5: input validation, edge cases, error handling, duplication, complexity. Triggers: quality, big 5, ai code, review, validate.

インストール方法を見る

含まれるファイル(2)

  • SKILL.md3.9 KB
  • reference/quality-research.md3.7 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

<skill id="quality"> <purpose> AI code is 1.7x buggier. These 5 checks catch 80% of issues. Load this skill for any review, validation, or implementation work. </purpose> <reference> Verbose research: skills/quality/reference/quality-research.md </reference> <big5> <check id="1" name="input_validation" detection="grep -r 'req\.body' | grep -v 'parse\|validate\|z\.'"> Every endpoint has Zod/Pydantic schema. Parameterized queries only. </check> <check id="2" name="edge_cases" detection="search for array access without length check"> Handle: null, empty array, zero-length string, timeout, unicode. </check> <check id="3" name="error_handling" detection="grep -r 'catch.*{}'"> No empty catch. Errors logged with context. User messages generic. Silent swallowing is the worst variant: a catch/onError that returns a masked or generic body without first logging method/path/cause hides the root failure behind a 500 and costs a full re-diagnosis per incident. Every handler logs the cause before it masks. Missing config/dependency is a NAMED condition in the response (which var, which service), never a generic error. </check> <check id="4" name="duplication" detection="jscpd or manual review"> Same logic in 3+ places = extract to utility. </check> <check id="5" name="complexity" detection="eslint complexity rule"> Functions under 30 lines. No nested ternaries > 2 levels. </check> <check id="6" name="gate_integrity" detection="seed a known violation and confirm the gate goes red"> A gate nobody has seen fail is not a gate. Before trusting any check you ship or run: - Prove it red. Seed the exact violation it claims to catch, watch it fail, then unseed. A gate that has only ever printed PASS is measuring nothing. - The checker re-derives its evidence. A hash, a "PASS" string, a file that merely exists, or a count supplied by the thing being checked is an assertion, not evidence. Read the bytes, run the command, fetch the remote. - Exit 0 with empty or blank output is a failure, not a pass. Never pipe a gate to `tail`/`head`; the pipe reports the pager's exit code. - A gate that stays green after you delete the code it guards is blind. Delete-and-rerun is the cheapest mutation test there is. - Randomness in a gate makes it a coin flip. Pin the seed or pin the input. - Absence of a run is red, not pending. </check> </big5>

<quick_checks>

# 1. Missing validation
grep -r "req\.body" --include="*.ts" --include="*.js" | grep -v "parse\|validate\|z\." | head -5

# 2. Empty catch blocks
grep -r "catch.*{}" --include="*.ts" --include="*.js" | head -5

# 3. String concat in queries (SQL injection)
grep -rE "SELECT.*\$\{|INSERT.*\$\{" --include="*.ts" --include="*.js" | head -5

</quick_checks>

<data_correctness> For any pipeline that extracts or transforms figures (financial, metrics, counts):

  • Parse deterministically (a real parser, regex, typed loader). The LLM never generates, transforms, or "fixes" numeric values.
  • Units are explicit at parse time (percent vs fraction, counts vs currency); a value never crosses unit categories through arithmetic.
  • Tie-out gate: derived aggregates must reproduce the source's own totals before any output is shown downstream. A delta between your output and the source is assumed to be YOUR normalization bug until proven otherwise.
  • Silent-empty guard: "no findings" produced from an empty parse is a failure of the parse, not a finding. </data_correctness>
<verdict> Any Big 5 violation = NOT READY Fix before commit. No exceptions. </verdict>

<on_complete> agentdb write-end '{"skill":"quality","big5_checked":true,"violations":N}' </on_complete>

</skill>

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Use AtomLane to compile and execute safe atomic parallel plans on macOS and native Windows Preview for worthwhile independent argv tasks, dependency DAGs, supported platform entrypoints, or Apple-silicon operators. Use at task start or an execution boundary when structured local work may contain two or more worthwhile units; skip plain answers, one quick command, and work whose effects cannot be safely bounded.

日本語の概要は準備中です。原文の説明を表示しています。

hashgraph-online/awesome-codex-plugins1,2732026年10月10日 更新

add

無料

Register a deferred decision in the debt registry. Trigger by judgment, not a marker scan, whenever a future reader would ask "why this way?": an unmade decision, stub, loosened type, bypassed check, swallowed error, a default picked "for now", or a TODO/FIXME/HACK/XXX marker. Trigger immediately whenever you defer work, or when the user invokes $add. Over-register freely; the developer drops with "drop A", "drop A,C", or "drop all".

日本語の概要は準備中です。原文の説明を表示しています。

hashgraph-online/awesome-codex-plugins1,2732026年10月10日 更新

ADK 框架适配层。为 LangChain / EINO / AutoGen / AgentScope / CrewAI 提供框架特定的 代码模板、惯用模式、API 映射和项目结构,供 agent-dev-workshop Phase 5 代码生成使用。 每个框架 reference 文件标注 verified_date 用于版本锁定。

日本語の概要は準備中です。原文の説明を表示しています。

hashgraph-online/awesome-codex-plugins1,2732026年10月10日 更新

中文调试修复技能。用于报错、测试失败、页面异常、功能不符合预期、需要定位根因并做最小修复时。触发语包括"进入调试模式""帮我修问题""报错了""测试失败""页面坏了""找根因"。

日本語の概要は準備中です。原文の説明を表示しています。

hashgraph-online/awesome-codex-plugins1,2732026年10月10日 更新

交互式 AI Agent 开发工作坊:通过 6 阶段深度协作对话,引导用户完成 Agent 需求分析、架构设计、 工具定义、Prompt 与编排设计、代码生成、验证迭代,产出可直接运行的 Agent 项目。 框架无关设计优先,支持 LangChain / EINO / AutoGen / AgentScope / CrewAI 等 ADK 框架。

日本語の概要は準備中です。原文の説明を表示しています。

hashgraph-online/awesome-codex-plugins1,2732026年10月10日 更新

中文漂移审计技能。用于项目或学习过程变乱、上下文漂移、任务分叉、多个方案冲突、命名不一致、Codex 可能顺手改多了时。触发语包括"漂移检查""感觉跑偏了""项目变乱了""检查是否失控""分叉太多""上下文漂移"。

日本語の概要は準備中です。原文の説明を表示しています。

hashgraph-online/awesome-codex-plugins1,2732026年10月10日 更新

hashgraph-online のスキルをすべて見る

このスキルの問題を報告する