feat(skill-check): 稽核加入 marketplace 同步必經步驟與流程檢查四項
What:`skills/skill-check/SKILL.md` 兩處增修。第 2 步的稽核範圍明寫要逐項涵蓋準則的流程檢查四項,四項各列一條,完成條件改成「每個 domain 的稽核結果對所有清單項目都有結論,含這四項」;新增第 5 步「同步 marketplace 正本」,四個結束碼各自寫明怎麼處理,原本的複查與開 PR 順延為第 6、7 步。 Why:`sync-marketplace.sh` 原本沒有出現在任何技能流程裡,跑不跑全憑人記得。正本在 `plugins/meta`,每個 domain 存取庫各留一份位元組完全相同的副本,稽核改完不同步,就會有存取庫註冊到過期的 plugin 清單。流程檢查四項同理:準則加了項目,稽核不點名就沒有人會查,四項等於沒加。 How:同步列為必經步驟,不是選項。呼叫時拿既有項目自己現在的值重寫一次,重寫同一筆是冪等的,所以不必先判斷哪一筆該改。四個結束碼逐一分流:3 是寫好了但有 domain 沒 clone 到本機,先跑 `sync-domains.sh` 再重跑;2 是參數個數不對;1 是缺 python3、正本讀不到或副本位元組不一致;0 才代表每份副本完全相同,而且是腳本自己驗過的。 Who:`jsc-meta:skill-check` 的例行合規稽核流程。
This commit is contained in:
@@ -10,8 +10,21 @@ Single source of guidelines: [`../../references/guidelines.md`](../../references
|
||||
## Flow
|
||||
|
||||
1. Run `tools/sync-domains.sh` to sync every domain repo of the Gitea canonical marketplace. Completion condition: the script exits 0 and prints one `domain<TAB>path` line per marketplace domain — exit 0 is the only code that means every repo is present and current. Exit 3 means some repos were not updated: reconcile every path named on stderr (commit or stash the dirty tree, or fix the failing pull) and rerun; when the user confirms a dirty tree is intentional local work, record that decision and continue on the local version — never read exit 3 as current. Exit 2 means a domain could not be cloned and exit 1 means the canonical marketplace was unreadable — resolve either before continuing.
|
||||
2. Audit every skill of every domain against the guidelines.md audit checklist — this step MUST run as a sub agent, one sub agent per domain repo. Each sub agent reports its findings: skill, failed checklist item, evidence (file:line), proposed fix. Completion condition: every domain has an audit result.
|
||||
2. Audit every skill of every domain against the guidelines.md audit checklist — this step MUST run as a sub agent, one sub agent per domain repo. Each sub agent reports its findings: skill, failed checklist item, evidence (file:line), proposed fix. Cover the checklist's four flow checks by name, not only the naming and language items:
|
||||
1. Every step number, file path and section title the skill references — inside itself and in other files — really exists (the pointer points at something).
|
||||
2. Every step ends in a checkable completion condition, with no vague wording.
|
||||
3. Every external call (script, API, other skill) states what to do on failure and routes every exit code.
|
||||
4. No gate the skill installs blocks the only path that lifts that gate.
|
||||
|
||||
Completion condition: every domain has an audit result that names a verdict for all checklist items, the four flow checks included.
|
||||
3. Present each failed item via the `jsc-ask:ask` decision tree (apply the proposed fix / skip / custom fix). Every option states its impact scope (example: skipping leaves the skill non-compliant until the next audit). Completion condition: every finding has a recorded decision.
|
||||
4. Apply the confirmed fixes — the fix-application part MUST run as a sub agent, one sub agent per affected domain repo: modify the files per the confirmed fix. Then run `tools/sync-skill-manifest.sh {domain-path}` directly (no sub agent needed) for each affected domain repo to refresh that domain README's 「Skills 目錄」 section and bump the version in all three manifests. Completion condition: every affected repo carries the fixes and the manifest bump.
|
||||
5. Re-check the guidelines.md audit checklist for every touched skill. On any failure, **return to step 3**: confirm and fix again, until all items pass. Completion condition: all checklist items pass.
|
||||
6. Call `jsc-git:pr` once per affected domain repo to open a Push Request. Completion condition: every affected repo has a PR URL.
|
||||
5. Sync the canonical marketplace — a **required** step, never optional. The canonical pair lives in `plugins/meta` and every domain repo carries a byte-identical copy, so a fix that leaves the copies apart makes some repos register a stale plugin set. Run `tools/sync-marketplace.sh {domain} {repo-url} {description}` once with an existing entry's own current values (rewriting the same entry is idempotent); the script rewrites both canonical files and copies them into every domain repo. Route each exit code:
|
||||
- Exit 3 — written, but some domain repo is not present locally. Run `tools/sync-domains.sh`, then rerun this step.
|
||||
- Exit 2 — usage error: the script takes exactly three arguments. Fix them and rerun.
|
||||
- Exit 1 — missing python3, an unreadable canonical file, or a byte mismatch between copies. Read stderr, fix the named cause (install python3 for the first), then rerun.
|
||||
- Exit 0 — every copy holds identical bytes; the script verifies that itself.
|
||||
|
||||
Completion condition: the script exits 0 and prints the touched paths.
|
||||
6. Re-check the guidelines.md audit checklist for every touched skill. On any failure, **return to step 3**: confirm and fix again, until all items pass. Completion condition: all checklist items pass.
|
||||
7. Call `jsc-git:pr` once per affected domain repo to open a Push Request. Completion condition: every affected repo has a PR URL.
|
||||
|
||||
Reference in New Issue
Block a user