Atlas / Skills / florianbruniaux / Routines Discover

Routines DiscoverBLOCK

skills/florianbruniaux/routines-discover

The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Version
—
Hosts
1 documented
License
CC-BY-SA-4.0
Stars
6,123
01

Overview

The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.

Read from source at commit d90170da4369OBSERVED · 2026-10-07
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: routines-discover
description: "Analyzes the current project to surface high-value Routines use cases across the three trigger types (schedule, API, GitHub events). Usage: /routines-discover"
effort: medium
disable-model-invocation: true
---

# Routines use case discovery

Analyzes this codebase and surfaces actionable Routine candidates across the three trigger types.

**Usage**: `/routines-discover` - no arguments needed. Run it in the root of any project.

---

## What are Routines

A Routine is an autonomous Claude Code session running on Anthropic-managed cloud infrastructure, triggered in three ways:

| Trigger | How it fires |
|---------|-------------|
| **Schedule** | Recurring cron cadence (min 1 hour) |
| **API** | HTTP POST to a per-routine endpoint with bearer token |
| **GitHub events** | Repository events: PR opened/merged, push, issue, workflow run, etc. |

Each run clones a fresh copy of the GitHub repository, runs a full Claude Code session with configured MCP connectors (Slack, Linear, GitHub, Google Drive...), and can create branches, open PRs, post messages, and call external APIs. No local machine required.

**Daily limits**: Pro 5/day · Max 15/day · Team/Enterprise 25/day.

---

## Instructions

### Step 1: Read the codebase

Before generating any output, silently read:
- `README.md` or `CLAUDE.md` to understand the project purpose and stack
- `package.json`, `Cargo.toml`, `pyproject.toml`, or equivalent for dependencies
- `.github/workflows/` to understand existing CI/CD automation
- Any monitoring, deploy, or ops configuration you find

If MCP connectors are configured in `.claude/settings.json`, note which external services are connected.

### Step 2: Analyze against five dimensions

For each dimension, think concretely about this specific project before writing anything.

**1. Scheduled maintenance**
What recurring work currently requires a human to run manually or remember to do?
Think: dependency audits, stale issue/PR triage, test flakiness reports, coverage drift, TODO comment tracking, dead code detection, daily or weekly summaries.

**2. Event-driven reactions**
What should happen automatically when a PR is opened, merged, or closed, but doesn't today because no one gets to it?
Think: review checklists, changelog updates, cross-repo sync, Slack notifications with context, label enforcement, docs updates on API changes.

**3. Alert and incident response**
What monitoring signals exist? When something breaks, what is the first thing a developer does?
Think: correlating an alert with recent commits, triaging a failing build, drafting a postmortem skeleton, routing an error to the right team.

**4. Cross-system sync**
What drifts today because the sync between two systems is manual?
Think: keeping two SDKs in sync, updating a doc site when an API changes, syncing GitHub issues with Linear, keeping a README stats section current.

**5. Release and deploy automation**
What steps happen before or after a deploy that a human runs by hand?
Think: smoke tests, release notes, version bumps, stakeholder notifications, go/no-go summaries.

### Step 3: Output

For each use case identified, produce a card in this format:

---

**[Name]** · `schedule` / `api` / `github`

*Trigger*: [what fires it: cron expression, which event, which external system]

*Input*: [what Claude receives: repo state, event payload, alert body]

*Output*: [what Claude produces: PR opened, message posted, file updated, issue created]

*Value*: [time saved or risk reduced, be specific]

*Blockers*: [missing connector, secrets needed, GitHub App required, etc., or "none"]

---

Sort cards by **value-to-effort ratio**, highest first.

After all cards, add a **Quick Wins** section: the two or three use cases that could be set up in under 15 minutes with the current repo and connector configuration.

---

## Example Output (for reference only, do not copy, analyze the actual project)

**Nightly stale PR report** · `schedule`

*Trigger*: Every weekday at 8am

*Input*: Repo state: all open PRs older than 5 days

*Output*: Slack message to #engineering with list of stale PRs, assignee, and last activity

*Value*: Saves ~15min of manual triage each morning, reduces PR rot

*Blockers*: Requires Slack MCP connector
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeNA
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (3)

CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
SKILL.md:23
| **API** | HTTP POST to a per-routine endpoint with bearer token |
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
MEDIUMInventory / provenance · inv.symlink · CWE-1104
whitepapers/recap-cards/en/_extensions
whitepapers/recap-cards/en/_extensions
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
whitepapers/recap-cards/fr/_extensions
whitepapers/recap-cards/fr/_extensions
Why it matters. link not followed

Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.

Audited 2026-10-07 · audit v0.4.1 · source sha d90170da4369full audit observations/trust-audit/skill/florianbruniaux__routines-discover.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-07d90170da4369BLOCKD69first audit
06

Questions

What does the Routines Discover skill do?

The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.

Is Routines Discover safe to install?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What can Routines Discover access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Routines Discover work with?

Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (d90170da4369), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement