Lint NewCAUTION
Developer-first error tracking and performance monitoring
Overview
Developer-first error tracking and performance monitoring
42a3375c14f5OBSERVED · 2026-09-29What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
---
name: lint-new
description: Create a new ESLint rule with tests for eslintPluginScraps. Use when asked to "create a lint rule", "add an eslint rule", "scaffold a rule", "write a new scraps rule", or "new design system lint rule". Covers rule creation, test authoring, registration, and autofix implementation.
---
Create a new ESLint rule named `$ARGUMENTS` in the eslintPluginScraps plugin.
## Step 1: Choose Your Archetype
Read [references/rule-archetypes.md](references/rule-archetypes.md) and pick the archetype that matches your rule's intent:
| You want to... | Archetype | Reference to load |
| ------------------------------------------- | ---------------------- | ---------------------------------------------------------------- |
| Rewrite import paths | Import rewrite | Inline — simple pattern |
| Validate token/value usage per CSS property | Property validation | [style-collector-guide.md](references/style-collector-guide.md) |
| Restrict JSX elements in specific props | JSX structural | [rule-archetypes.md](references/rule-archetypes.md) §Archetype 3 |
| Detect patterns in static CSS text | Template text analysis | [rule-archetypes.md](references/rule-archetypes.md) §Archetype 4 |
Read the relevant reference before writing code. The archetypes document which AST visitors to use, which shared utilities apply, and which patterns are NOT appropriate for each approach.
## Step 2: Check Shared Utilities
Before writing AST traversal logic, check `static/oxlint/eslintPluginScraps/src/ast/` for reusable code:
| Utility | Location | Use for |
| ----------------------- | ---------------------------------------- | ------------------------------------------------------------------- |
| `getStyledCallInfo` | `src/ast/utils/styled.ts` | Classifying styled/css calls as element, component, or css |
| `createQuasiScanner` | `src/ast/scanner/index.ts` | Scanning static CSS text in template literals (Archetype 4) |
| `createImportTracker` | `src/ast/tracker/imports.ts` | Resolving where a local name was imported from |
| `createStyleCollector` | `src/ast/extractor/index.ts` | Collecting CSS-in-JS _dynamic value_ declarations (NOT static text) |
| `shouldAnalyze` | `src/ast/extractor/index.ts` | Fast pre-scan to skip files without Emotion usage |
| `normalizePropertyName` | `src/ast/utils/normalizePropertyName.ts` | Normalizing CSS property names |
| `decomposeValue` | `src/ast/extractor/value-decomposer.ts` | Breaking complex expressions into all possible values |
| Theme tracker | `src/ast/tracker/theme.ts` | Tracking `useTheme()` and callback theme bindings |
If another rule already solves a similar problem, extract shared logic into `src/ast/utils/` and reuse it.
## Step 3: Create Files
1. **Rule**: `static/oxlint/eslintPluginScraps/src/rules/$ARGUMENTS.ts`
2. **Test**: `static/oxlint/eslintPluginScraps/src/rules/$ARGUMENTS.spec.ts`
### Rule Template
```typescript
import {ESLintUtils} from '@typescript-eslint/utils';
export const $RULE_NAME = ESLintUtils.RuleCreator.withoutDocs({
meta: {
type: 'problem',
docs: {
description: '[Rule description]',
},
fixable: 'code', // include if rule has autofix — see Autofix Guidance
schema: [],
messages: {
forbidden: 'Error message shown to user',
},
},
create(context) {
return {
// AST visitor methods — see your chosen archetype
};
},
});
```
If your rule needs configurable options, load [references/schema-patterns.md](references/schema-patterns.md).
### Test Template
```typescript
import {RuleTester} from '@typescript-eslint/rule-tester';
import {$RULE_NAME} from './$ARGUMENTS';
const ruleTester = new RuleTester();
ruleTester.run('$ARGUMENTS', $RULE_NAME, {
valid: [
{
code: '// valid code',
filename: '/project/src/file.tsx',
},
],
invalid: [
{
code: '// invalid code',
filename: '/project/src/file.tsx',
errors: [{messageId: 'forbidden'}],
output: '// expected output after autofix', // REQUIRED for fixable rules
},
],
});
```
Run tests:
```bash
pnpm test-ci "static/oxlint/eslintPluginScraps/src/rules/$ARGUMENTS.spec.ts"
```
## Autofix Guidance
**Default stance: implement autofix** unless the transformation is ambiguous or could change runtime behavior.
### Safe autofix patterns
- Import path rewrites (see `no-core-import.ts` as canonical example)
- Adding/removing JSX attributes with known values
- Wrapping expressions in a known component
- Identifier renames with no shadowing risk
### Do NOT autofix when
- Multiple valid fixes exist and the right choice requires human judgment
- The fix requires type information not available from the AST alone
- The transformation alters control flow or runtime behavior
- The change spans multiple files
### Fixer API
```typescript
context.report({
node,
messageId: 'forbidden',
fix(fixer) {
return fixer.replaceText(node, newText);
// Also: fixer.replaceTextRange([start, end], text)
// fixer.insertTextBefore(node, text)
// fixer.insertTextAfter(node, text)
// fixer.remove(node)
// Return single fix or array of fixes
},
});
```
When a rule is fixable, every invalid test case MUST include `output` showing the expected code after the fix.
## Step 4: Register the Rule
### 1. Rule Index
Add to `static/oxlint/eslintPluginScraps/src/rules/index.ts`:
```typescript
import {$RULE_NAME} from './$ARGUMENTS';Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (2)
.claude/skills
api-docs/.node-version
Gates applied: no_behavioural_pass.
42a3375c14f5full audit observations/trust-audit/skill/getsentry__lint-new.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-29 | 42a3375c14f5 | CAUTION | B | 89 | first audit |
Questions
What does the Lint New skill do?
Developer-first error tracking and performance monitoring
Is Lint New safe to install?
With care. The audit graded it B (89/100) and found 2 things worth knowing before you trust this skill, listed below with the exact line each was found on.
What can Lint New access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
How current is this page?
The grade is for one exact copy of the source (42a3375c14f5), read on 2026-09-29. The repository is watched, and a new audit runs when it changes — this is the first audit.