Ralphinho Rfc PipelineSAFE
The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.
Overview
The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.
649b2d7452ebOBSERVED · 2026-09-21What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: ralphinho-rfc-pipeline description: RFC駆動の複数エージェントDAG実行パターン、品質ゲート、マージキュー、ワークユニットオーケストレーション。 origin: ECC --- # Ralphinho RFC Pipeline [humanplane](https://github.com/humanplane) スタイルのRFC分解パターンと複数ユニットオーケストレーションワークフローにインスパイア。 単一エージェントパスでは大きすぎる機能を独立して検証可能なワークユニットに分割する必要がある場合、このスキルを使用します。 ## Pipeline Stages 1. RFC intake 2. DAG decomposition 3. Unit assignment 4. Unit implementation 5. Unit validation 6. Merge queue and integration 7. Final system verification ## Unit Spec Template 各ワークユニットに含める: - `id` - `depends_on` - `scope` - `acceptance_tests` - `risk_level` - `rollback_plan` ## Complexity Tiers - Tier 1: isolated file edits, deterministic tests - Tier 2: multi-file behavior changes, moderate integration risk - Tier 3: schema/auth/perf/security changes ## Quality Pipeline per Unit 1. research 2. implementation plan 3. implementation 4. tests 5. review 6. merge-ready report ## Merge Queue Rules - Never merge a unit with unresolved dependency failures. - Always rebase unit branches on latest integration branch. - Re-run integration tests after each queued merge. ## Recovery ユニットが stall した場合: - evict from active queue - snapshot findings - regenerate narrowed unit scope - retry with updated constraints ## Outputs - RFC execution log - unit scorecards - dependency graph snapshot - integration risk summary
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
649b2d7452ebfull audit observations/trust-audit/skill/affaan-m__ralphinho-rfc-pipeline.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-21 | 649b2d7452eb | SAFE | B | 89 | first audit |
Questions
What does the Ralphinho Rfc Pipeline skill do?
The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.
Is Ralphinho Rfc Pipeline safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Ralphinho Rfc Pipeline access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
How current is this page?
The grade is for one exact copy of the source (649b2d7452eb), read on 2026-09-21. The repository is watched, and a new audit runs when it changes — this is the first audit.