All skills
paulrberg avatar

/code-polish

@ccfca26
by Paul Bergpaulrberg/agent-skills94 stars
7

Polish changed code when the user explicitly asks, or when an active workflow requests post-implementation simplification and risk-profiled review over a fixed file scope.

Use this Skill: https://skilld.dev/gh/paulrberg/agent-skills/code-polish

This session only. Nothing lands on disk.

SKILL.md

≈46 tokens always: the name and description. ≈1.4k when used: this file. ≈2.6k more on demand in 10 files.

Code Polish

Resolve scope once, make only high-confidence simplifications, fix evidenced defects by risk, and verify the final state.

Modes

  • --simplify: simplify only.
  • --review: review and fix only.
  • Neither or both: simplify, then review the simplified result.
  • --with-profile <name> / --skip-profile <name>: add or suppress review profiles; skip wins.

Fixed Scope

  1. Require a Git repository.
  2. Use explicit paths, patterns, ranges, natural-language targets, or a supplied resolved-scope block when present. Otherwise use only files modified in this session; if session history is unavailable, use all uncommitted tracked and untracked files.
  3. Exclude lockfiles, generated outputs, vendored code, minified bundles, and large data snapshots from manual review unless explicitly requested. Validate relevant excluded outputs through their generator, schema, or invariants.
  4. Resolve and retain one authoritative scope set and optional exclusions for execution. Do not broaden or recompute scope later. Stop if it is empty.

Simplify

Preserve public contracts, inputs, outputs, side effects, error behavior, performance-sensitive characteristics, telemetry, and operational guards. Apply only changes with a concrete comprehension or defect-risk benefit:

  • flatten avoidable control-flow nesting;
  • clarify misleading names or dense transforms;
  • remove real duplication when the abstraction reduces total complexity;
  • tighten local types and contracts without broad churn;
  • remove only dead code caused by this session's edits.

Do not split by line count, perform architecture cleanup, convert sync/async APIs, add speculative configurability, or replace readable duplication with a one-use abstraction. A no-op is a valid result.

Review and Fix

Judge the diff against the user's request. Prioritize CRITICAL → HIGH → MEDIUM → LOW:

  • CRITICAL: exploitable security, data loss, or critical outage path.
  • HIGH: behavior, error-path, boundary, or performance defect affecting core behavior.
  • MEDIUM: resource leak, complexity hotspot, test gap, over-scoped change, speculative complexity, or weak success criterion likely to cause defects.
  • LOW: localized clarity or style issue with a real maintenance cost.

Every finding must cite a verified location, triggering input/state, failure mode, blast radius, and evidence in the changed code. Merge duplicates and apply the smallest defensible fix. When intent is ambiguous, stop or record the assumption instead of guessing.

Select every applicable profile and read it once:

Surface Profile
auth, secrets, crypto, external input/network, unsafe parsing security
env, config, timeouts, retries, pools, limits configuration
Go behavior, concurrency, context, errors go
Rust, Cargo/workspaces, async/concurrency, unsafe/FFI rust
TypeScript types, modules, packages, async behavior typescript
Python services, scripts, async, packaging, data IO python
shell, CI, deploy, installers, quoting shell
CSV/JSON/YAML/binary, schemas, migrations, generated data data-formats
naming and intent clarity naming unless skipped

Profiles live at references/profiles/<name>.md. Missing selected profiles are a stop condition.

Verification and Report

Run the narrowest formatter/lint, targeted tests, typecheck, and invariant checks that prove the final touched behavior. Broaden only for shared contracts. Name skipped checks and why.

Summarize scope with the file count and smallest useful repository-relative roots, globs, ranges, or user-supplied targets. Do not enumerate every file merely to prove scope; name individual paths only for a small explicit scope or to clarify exceptions and findings. Findings include severity, location, impact, evidence, fix, and confidence. A residual risk states the assumption, consequence if wrong, and how to check it. Under Issues and caveats, group verified fixes with evidence as Resolved, and remaining problems, limitations, or unverified assumptions as Open, with their impact and next step. Omit empty groups and report each item once; put neutral context and agreed decisions under changes or scope. Reserve blocker for something preventing required work and risk for a specific potential adverse outcome. A workaround leaves an item open when the underlying issue still affects the result. Completion requires fixed scope, traceable edits/findings, and validation evidence.

Render a successful report as ### ✨ Code polish — ✅ complete, a small summary-count table, a compact Scope summary, ### ✨ Simplifications, ### 🧪 Verification, and ### Issues and caveats, omitting inapplicable sections. When review ran and found no defects, state ✅ No verified review findings. If a stop condition below prevents completion, lead with ### ✨ Code polish — ⛔ blocked and report the evidence and required decision. Keep severity tokens, profile IDs, commands, locations, reproduction inputs, and security evidence exact and undecorated.

Stop when behavior parity or required high-risk validation cannot be established, or a fix requires an unrequested public-contract change or larger redesign.

Source: SKILL.md on GitHub

1 warningtoday5 checks · Risk SAFE
  • Gen Agent Trust Hubtoday

    The skill is a code analysis and simplification tool that operates on local Git repositories. It uses various language-specific profiles to identify defects and suggest improvements. The primary security consideration is that the skill processes untrusted code changes and possesses the capability to execute shell commands (e.g., tests, linters, and formatters), making it a potential target for indirect prompt injection where malicious instructions in the code could influence the agent's behavior.

  • Sockettoday

    No alerts

  • Snyktoday

    Risk: LOW · No issues

  • Runlayer7mo

    1/1 file flagged

  • ZeroLeaks5mo

    1 finding · Score: 86/100

Signed by skilld at ccfca26. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last week
argument-hint
[paths] [--simplify] [--review] [--with-profile <name>] [--skip-profile <name>]

README badge

README badge for paulrberg/agent-skills/code-polish