All skills
paulrberg avatar

/code-polish

@ccfca26
by Paul Bergpaulrberg/agent-skills94 stars
7

Polish changed code when the user explicitly asks, or when an active workflow requests post-implementation simplification and risk-profiled review over a fixed file scope.

Use this Skill: https://skilld.dev/gh/paulrberg/agent-skills/code-polish

This session only. Nothing lands on disk.

referencesprofilesgo.md

≈383 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Go Profile

Load when the diff touches Go services, CLIs, concurrency, context propagation, error handling, modules, or tests.

Checks

  • GO-001 Context loss (HIGH): request-scoped, command-scoped, or shutdown work ignores cancellation, deadlines, or parent context.
  • GO-002 Goroutine/channel leak (HIGH): goroutines, timers, tickers, readers, or channels can block or outlive their owner.
  • GO-003 Error loss (HIGH): returned errors are ignored, wrapped without useful context, or replaced with unsafe zero values.
  • GO-004 Nil/zero-value trap (HIGH): nil pointers, nil interfaces, nil maps/slices, or zero-value structs break valid inputs or error paths.
  • GO-005 Loop/capture aliasing (MEDIUM): loop variables, pointer reuse, or shared buffers produce incorrect references for the module's Go version.
  • GO-006 Interface bloat (MEDIUM): broad interfaces, package-level globals, or hard-coded dependencies make behavior hard to test or substitute.
  • GO-007 Module/tool drift (MEDIUM): go.mod, go.sum, generated files, or tool versions change without a matching reason or reproducible command.
  • GO-008 Test blind spot (MEDIUM): table tests, race-sensitive paths, or error branches do not cover changed behavior.

Evidence Expectations

  • Show the failing input, cancellation path, concurrency schedule, or error branch.
  • Name the narrow Go command that proves the finding, such as go test ./pkg/foo, go test -race ./pkg/foo, go test ./..., or go mod tidy.

Source: SKILL.md on GitHub

1 warningtoday5 checks · Risk SAFE
  • Gen Agent Trust Hubtoday

    The skill is a code analysis and simplification tool that operates on local Git repositories. It uses various language-specific profiles to identify defects and suggest improvements. The primary security consideration is that the skill processes untrusted code changes and possesses the capability to execute shell commands (e.g., tests, linters, and formatters), making it a potential target for indirect prompt injection where malicious instructions in the code could influence the agent's behavior.

  • Sockettoday

    No alerts

  • Snyktoday

    Risk: LOW · No issues

  • Runlayer7mo

    1/1 file flagged

  • ZeroLeaks5mo

    1 finding · Score: 86/100

Signed by skilld at ccfca26. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last week
argument-hint
[paths] [--simplify] [--review] [--with-profile <name>] [--skip-profile <name>]

README badge

README badge for paulrberg/agent-skills/code-polish