All skills
mblode avatar

/dx-audit

@b690e67
by Matthew Blodemblode/agent-skills134 stars
12

Audits libraries, CLIs, and SDKs using 38 rules for public contracts, package exports, piped output, errors, and configuration. Use when asked to "audit my CLI", "review my SDK", or diagnose package type resolution. For public site or docs agent scores use agent-ready; for agentic product trust use ax-audit; for docs prose use ghostwriter.

Use this Skill: https://skilld.dev/gh/mblode/agent-skills/dx-audit

This session only. Nothing lands on disk.

rulesapi-stable-contract.md

≈413 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Keep the Public Contract Stable; Deprecate, Don't Break

Renaming or removing a public export, or changing its return or parameter shape, breaks every consumer who upgrades; a non-major bump breaks them silently. Add the new shape alongside the old, mark the old @deprecated naming the replacement, and remove it only on a major version.

Load this rule only when the current diff changes a public export, signature, parameter, or return shape. Compare that changed surface with the repository's normal base first. Use a release tag or published declaration only when the base cannot establish the prior contract. With no reliable prior contract, report this rule as not assessed; the mere absence of @deprecated tags or an aliasing convention is not evidence of a breaking change.

Incorrect (renamed export and changed return type in a minor bump, no shim):

// 1.4.0 had: export function getUser(id: string): User
// 1.5.0 (minor) ships:
export function fetchUser(id: string): Promise<User | null> {} // rename + shape change
// every caller of getUser() now throws "getUser is not a function"

Correct (additive change; old name kept as a deprecated alias):

export function fetchUser(id: string): Promise<User | null> {}

/** @deprecated since 1.5.0, use fetchUser. Removed in 2.0.0. */
export function getUser(id: string): Promise<User | null> {
  return fetchUser(id);
}

Source: SKILL.md on GitHub

No alerts9d3 checks · Risk SAFE
  • Gen Agent Trust Hub9d

    The dx-audit skill is a developer experience auditing tool designed to review public APIs, CLIs, and SDKs. It demonstrates a strong security posture by including explicit instructions to validate inputs against path traversal and shell injection, and by warning the agent to inspect potentially malicious lifecycle scripts in audited repositories before running packaging probes. All external tools mentioned are industry-standard utilities.

  • Socket9d

    No alerts

  • Snyk9d

    Risk: LOW · No issues

Signed by skilld at b690e67. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated last week

README badge

README badge for mblode/agent-skills/dx-audit