All skills
kkkkhazix avatar

/neat-freak

@2b4a645
by Khazixkkkkhazix/khazix-skills21k stars
2,235

Knowledge and governance closeout: reconcile project docs, rule files (CLAUDE.md/AGENTS.md), authorized agent memory, and workspace residue with what the code and runtime actually do, so the next session or the next person starts from one current answer. Trigger when the user names "neat-freak", "洁癖", or "/neat" — and also on clear knowledge-closeout intent without the name: syncing or tidying project docs/rules/memory after development ("把文档和记忆整理一下", "收尾时把文档同步掉", "docs 和代码对不上了"), stale or conflicting CLAUDE.md/memory, a clean handoff to a teammate or a fresh session, or auditing whether workspace rules are actually followed. Do not trigger for pure coding/refactoring/debugging tasks, tidying data or prose (JSON, 周报, changelog announcements), or a bare "整理" with no project-knowledge context.

Use this Skill: https://skilld.dev/gh/kkkkhazix/khazix-skills/neat-freak

This session only. Nothing lands on disk.

referencesgovernance.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

规范执行审计细则

核心原则:规则的内容来自现场层级文件,本 reference 只提供提取、核验和处置方法。系统、用户和项目规则的授权边界高于本 skill。

提取可机械核验约定

读实际生效的规则链时,找能够转成检查命令的祈使句,并记录原文出处。

类别 规则句式 核验证据
命名 “目录必须 kebab-case” 同级名字清单和例外条款
必备文件 “每个项目必须有 X” 文件存在性与最小内容
同源 “A 软链/导入 B”“只编辑 B” readlink、realpath、导入、加载诊断
安全红线 “密钥不进代码”“ignore 必须含 X” tracked files、ignore 规则、secret scanner
目录纪律 “根目录不放裸文件” 根目录 manifest 与白名单
声明一致 “启动命令/URL/服务名必须真实” package/config、服务或 live probe
发布流程 “完整汇报与用户确认先于清场” knowledge receipt、deploy marker、cleanup candidate、post-report user approval receipt

行为偏好如“结论先行”也要遵守,但不属于结构审计结果,除非存在可验证模板或门禁。

确定实际规则链

不要假设所有平台都从根目录读同一个文件:

  1. 识别当前 Agent 和 cwd。
  2. 从项目根到 cwd 查本平台的规则文件、override、fallback 和路径规则。
  3. 再查用户/组织级规则。
  4. 记录加载顺序和覆盖关系;同目录只采用平台实际会加载的文件。
  5. 若项目声明 CLAUDE.md/AGENTS.md 必须同源,再核对软链或导入;没有声明时只报告分叉风险,不擅自规定方向。

核验范围

  • 当前项目请求:审当前项目内容;上级规则和同级名字只读。
  • 跨项目变更:审实际受影响的 upstream/consumer 文档,先说明扩展依据。
  • 整个 workspace:用户明确授权后,逐项目做存在性、同源和规则检查;仍按风险决定是否读全文。
  • 全局配置:默认只读审计死引用、矛盾和加载漂移,不把项目细节写入全局。

处置等级

先服从现场规则;如果现场没有更具体规定,用下面的默认分级。

可直接修

必须同时满足:在请求范围内、安全、可逆、没有外部副作用,并且当前规则授权自动修复。例如:

  • 现场明确要求的软链/导入缺失;
  • .gitignore 缺少规则明文要求的敏感文件模式;
  • 文档里的明显笔误、确认已不存在的死链接;
  • 同一事实的过期摘要,可由当前代码/运行态唯一裁决。

先报告再决定

  • 目录或项目重命名、文件/目录删除;
  • 合并内容不同的规则文件且权威无法唯一确定;
  • 规则与稳定实践漂移,但不清楚该改规则还是实践;
  • 修改范围外项目、全局配置或其他人的工作区;
  • 停服、权限/密钥、不可逆迁移、对外消息等现场规则列出的风险动作;
  • 唯一证据在未合并/dirty lane 中,清理会丢失它。

只读报告

  • 用户明确限制为“看看/审计/报告”;
  • 发现问题位于请求范围外;
  • 平台生成文件禁止直接修改;
  • 事实无法验证或需要外部系统权限。

规则本身的质量

同时检查:

  • 死引用:路径、命令、服务、项目是否存在;跨设备路径拿不准时不能直接删。
  • 矛盾:上下级规则、override、skill 和实践是否给出互斥要求。
  • 不可执行:大量“保持整洁/注意安全”但没有判断标准。
  • 重复:同一红线在全局、项目和 skill 复制,导致未来分叉。
  • 过载:核心规则被历史叙事挤没;优先删/迁,而不是继续加目录。
  • 无门禁:同一违规第三次出现,说明散文约束不足。根据现场授权建议或实现 check/hook/test。

报告要求

每条未自动修复的问题必须包含:

  • 证据和规则出处;
  • 所在范围;
  • 对用户或协作流程的影响;
  • 推荐动作;
  • 为什么本次没有自动执行。

不要用“发现 N 个问题”代替判断材料,也不要把范围外问题混进“项目已清洁”的结论。

Source: SKILL.md on GitHub

No alerts16d3 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill 'neat-freak' is a project governance and documentation reconciliation tool designed to synchronize project documentation, agent rules, and memory with the actual state of the code. It includes strong safety guardrails, such as requiring explicit user confirmation for any destructive operations (like cleaning up temporary files or branches) and explicitly forbidding the exfiltration or storage of credentials discovered during audits. The skill uses a dedicated read-only Bash script to inventory project artifacts, and no malicious patterns or vulnerabilities were detected.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

Signed by skilld at 2b4a645. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 7 hours ago.

Activeupdated 2 months ago
metadata
{
  "version": "3.0.0",
  "category": "knowledge-governance"
}
Other metadata
compatibility
Requires filesystem read access. Writes and destructive actions follow the active agent, workspace, and user authorization rules. Git and rg improve verification; scripts/audit-inventory.sh needs Bash — without it, do the equivalent checks manually. Works on any Agent Skills platform.

README badge

README badge for kkkkhazix/khazix-skills/neat-freak