Atlas / Skills / affaan-m / Skill Comply

Skill ComplySAFE

skills/affaan-m/skill-comply

The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

Verdict
SAFE
Grade
B
Trust score
89 /100
Version
—
Hosts
—
License
MIT
Stars
264,831
01

Overview

The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

Read from source at commit fb3fb10d9622OBSERVED · 2026-09-22
02

Install

Commands as the repository documents them. They are shown, not run.

uv run python -m scripts.run ~/.claude/rules/common/testing.md
uv run python -m scripts.run --dry-run ~/.claude/skills/search-first/SKILL.md
uv run python -m scripts.run --gen-model haiku --model sonnet <path>
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: skill-comply
description: スキル、ルール、エージェント定義が実際に遵守されているかを可視化する——3種類のプロンプト厳格度レベルのシナリオを自動生成し、エージェントを実行し、動作シーケンスを分類し、完全なツール呼び出しタイムラインの遵守率をレポートする
origin: ECC
tools: Read, Bash
---

# skill-comply:自動化された遵守測定

コーディングエージェントがスキル、ルール、またはエージェント定義を実際に遵守しているかを以下の方法で測定する:

1. 任意の .md ファイルから期待される動作シーケンス(仕様)を自動生成する
2. プロンプトの厳格度が段階的に低下するシナリオを自動生成する(支持的 → 中立的 → 競合的)
3. `claude -p` を実行し、stream-json 経由でツール呼び出しトレースを取得する
4. 正規表現ではなくLLMを使用してツール呼び出しを仕様ステップに分類する
5. 決定論的に時系列順を確認する
6. 仕様、プロンプト、タイムラインを含む自己完結型レポートを生成する

## サポートされるターゲット

* **スキル**(`skills/*/SKILL.md`):検索優先、TDDガイドなどのワークフロースキル
* **ルール**(`rules/common/*.md`):testing.md、security.md、git-workflow.md などの強制的なルール
* **エージェント定義**(`agents/*.md`):エージェントが期待される場面で呼び出されるか(内部ワークフロー検証は未サポート)

## 起動条件

* ユーザーが `/skill-comply <path>` を実行する
* ユーザーが「このルールは本当に遵守されているか?」と尋ねる
* 新しいルール/スキルを追加した後、エージェントの遵守を確認する
* 品質メンテナンスの一環として定期的に実行する

## 使い方

```bash
# Full run
uv run python -m scripts.run ~/.claude/rules/common/testing.md

# Dry run (no cost, spec + scenarios only)
uv run python -m scripts.run --dry-run ~/.claude/skills/search-first/SKILL.md

# Custom models
uv run python -m scripts.run --gen-model haiku --model sonnet <path>
```

## 重要なコンセプト:プロンプト独立性

プロンプトが明示的にサポートしていない場合でも、スキル/ルールが遵守されるかどうかを測定する。

## レポートの内容

レポートは自己完結型で、以下を含む:

1. 期待される動作シーケンス(自動生成された仕様)
2. シナリオプロンプト(各厳格度レベルで尋ねる内容)
3. 各シナリオの遵守スコア
4. LLM分類ラベル付きのツール呼び出しタイムライン

### 高度な内容(オプション)

フックに精通したユーザー向けに、レポートには遵守率が低いステップに対するフック強化の推奨事項も含まれる。これは参考情報——主要な価値は遵守性自体の可視化にある。
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeNA
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (0)

No findings outside the package's declared scope.

Gates applied: no_behavioural_pass.

Audited 2026-09-22 · audit v0.4.1 · source sha fb3fb10d9622full audit observations/trust-audit/skill/affaan-m__skill-comply.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-09-22fb3fb10d9622SAFEB89first audit
06

Questions

What does the Skill Comply skill do?

The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

Is Skill Comply safe to install?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.

What can Skill Comply access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

How current is this page?

The grade is for one exact copy of the source (fb3fb10d9622), read on 2026-09-22. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement