All skills
paulrberg avatar

/code-polish

@ccfca26
by Paul Bergpaulrberg/agent-skills94 stars
7

Polish changed code when the user explicitly asks, or when an active workflow requests post-implementation simplification and risk-profiled review over a fixed file scope.

Use this Skill: https://skilld.dev/gh/paulrberg/agent-skills/code-polish

This session only. Nothing lands on disk.

referencesprofilesnaming.md

≈251 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Naming Profile

Load last, after correctness and security checks; optional — skip with --skip-profile naming.

Checks

  • NM-001 Generic function names (MEDIUM): names like process/handle hide intent.
  • NM-002 Misleading identifiers (MEDIUM): name contradicts actual data shape or behavior.
  • NM-003 Boolean ambiguity (LOW): a boolean name conceals the condition it represents.
  • NM-004 File/export mismatch (LOW): filename and exported symbol diverge from project conventions.
  • NM-005 Constant intent loss (LOW): magic values or value-based constant names.
  • NM-006 Misleading filename (LOW): file's actual responsibility diverges from what its name implies (e.g., utils.ts that only formats dates → date-format.ts). Suggest a rename with rationale; flag as MEDIUM when the mismatch is likely to cause incorrect usage or placement of new code.

Guardrail

Only raise naming findings when they materially reduce maintainability in the touched code.

Source: SKILL.md on GitHub

1 warningtoday5 checks · Risk SAFE
  • Gen Agent Trust Hubtoday

    The skill is a code analysis and simplification tool that operates on local Git repositories. It uses various language-specific profiles to identify defects and suggest improvements. The primary security consideration is that the skill processes untrusted code changes and possesses the capability to execute shell commands (e.g., tests, linters, and formatters), making it a potential target for indirect prompt injection where malicious instructions in the code could influence the agent's behavior.

  • Sockettoday

    No alerts

  • Snyktoday

    Risk: LOW · No issues

  • Runlayer7mo

    1/1 file flagged

  • ZeroLeaks5mo

    1 finding · Score: 86/100

Signed by skilld at ccfca26. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last week
argument-hint
[paths] [--simplify] [--review] [--with-profile <name>] [--skip-profile <name>]

README badge

README badge for paulrberg/agent-skills/code-polish