Doc MaintenanceCAUTION
The open-source app everyone uses to manage agents at work
Overview
The open-source app everyone uses to manage agents at work
59d017e6174aOBSERVED · 2026-09-23Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| cursor | mentioned | |
| openclaw | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: doc-maintenance description: > Audit README, SPEC, and PRODUCT docs against recent git history for drift and make minimal PR-ready edits. Use when asked to review docs for accuracy, after major feature merges, or on a schedule. --- # Doc Maintenance Skill Detect documentation drift and fix it via PR — no rewrites, no churn. ## When to Use - Periodic doc review (e.g. weekly or after releases) - After major feature merges - When asked "are our docs up to date?" - When asked to audit README / SPEC / PRODUCT accuracy ## Target Documents | Document | Path | What matters | |----------|------|-------------| | README | `README.md` | Features table, roadmap, quickstart, "what is" accuracy, "works with" table | | SPEC | `doc/SPEC.md` | No false "not supported" claims, major model/schema accuracy | | PRODUCT | `doc/PRODUCT.md` | Core concepts, feature list, principles accuracy | Out of scope: DEVELOPING.md, DATABASE.md, CLI.md, doc/plans/, skill files, release notes. These are dev-facing or ephemeral — lower risk of user-facing confusion. ## Workflow ### Step 1 — Detect what changed Find the last review cursor: ```bash # Read the last-reviewed commit SHA CURSOR_FILE=".doc-review-cursor" if [ -f "$CURSOR_FILE" ]; then LAST_SHA=$(cat "$CURSOR_FILE" | head -1) else # First run: look back 60 days LAST_SHA=$(git log --format="%H" --after="60 days ago" --reverse | head -1) fi ``` Then gather commits since the cursor: ```bash git log "$LAST_SHA"..HEAD --oneline --no-merges ``` ### Step 2 — Classify changes Scan commit messages and changed files. Categorize into: - **Feature** — new capabilities (keywords: `feat`, `add`, `implement`, `support`) - **Breaking** — removed/renamed things (keywords: `remove`, `breaking`, `drop`, `rename`) - **Structural** — new directories, config changes, new adapters, new CLI commands **Ignore:** refactors, test-only changes, CI config, dependency bumps, doc-only changes, style/formatting commits. These don't affect doc accuracy. For borderline cases, check the actual diff — a commit titled "refactor: X" that adds a new public API is a feature. ### Step 3 — Build a change summary Produce a concise list like: ``` Since last review (<sha>, <date>): - FEATURE: Plugin system merged (runtime, SDK, CLI, slots, event bridge) - FEATURE: Project archiving added - BREAKING: Removed legacy webhook adapter - STRUCTURAL: New .agents/skills/ directory convention ``` If there are no notable changes, skip to Step 7 (update cursor and exit). ### Step 4 — Audit each target doc For each target document, read it fully and cross-reference against the change summary. Check for: 1. **False negatives** — major shipped features not mentioned at all 2. **False positives** — features listed as "coming soon" / "roadmap" / "planned" / "not supported" / "TBD" that already shipped 3. **Quickstart accuracy** — install commands, prereqs, and startup instructions still correct (README only) 4. **Feature table accuracy** — does the features section reflect current capabilities? (README only) 5. **Works-with accuracy** — are supported adapters/integrations listed correctly? Use `references/audit-checklist.md` as the structured checklist. Use `references/section-map.md` to know where to look for each feature area. ### Step 5 — Create branch and apply minimal edits ```bash # Create a branch for the doc updates BRANCH="docs/maintenance-$(date +%Y%m%d)" git checkout -b "$BRANCH" ``` Apply **only** the edits needed to fix drift. Rules: - **Minimal patches only.** Fix inaccuracies, don't rewrite sections. - **Preserve voice and style.** Match the existing tone of each document. - **No cosmetic changes.** Don't fix typos, reformat tables, or reorganize sections unless they're part of a factual fix. - **No new sections.** If a feature needs a whole new section, note it in the PR description as a follow-up — don't add it in a maintenance pass. - **Roadmap items:** Move shipped features out of Roadmap. Add a brief mention in the appropriate existing section if there isn't one already. Don't add long descriptions. ### Step 6 — Open a PR Commit the changes and open a PR: ```bash git add README.md doc/SPEC.md doc/PRODUCT.md .doc-review-cursor git commit -m "docs: update documentation for accuracy - [list each fix briefly] Co-Authored-By: Paperclip <[email protected]>" git push -u origin "$BRANCH" gh pr create \ --title "docs: periodic documentation accuracy update" \ --body "$(cat <<'EOF' ## Summary Automated doc maintenance pass. Fixes documentation drift detected since last review. ### Changes - [list each fix] ### Change summary (since last review) - [list notable code changes that triggered doc updates] ## Review notes - Only factual accuracy fixes — no style/cosmetic changes - Preserves existing voice and structure - Larger doc additions (new sections, tutorials) noted as follow-ups 🤖 Generated by doc-maintenance skill EOF )" ``` ### Step 7 — Update the cursor After a successful audit (whether or not edits were needed), update the cursor: ```bash git rev-parse HEAD > .doc-review-cursor ``` If edits were made, this is already committed in the PR branch. If no edits were needed, commit the cursor update to the current branch. ## Change Classification Rules | Signal | Category | Doc update needed? | |--------|----------|-------------------| | `feat:`, `add`, `implement`, `support` in message | Feature | Yes if user-facing | | `remove`, `drop`, `breaking`, `!:` in message | Breaking | Yes | | New top-level directory or config file | Structural | Maybe | | `fix:`, `bugfix` | Fix | No (unless it changes behavior described in docs) | | `refactor:`, `chore:`, `ci:`, `test:` | Maintenance | No | | `docs:` | Doc change | No (already handled) | | Dependency bumps only | Maintenance | No | ## Patch Style Guide - Fix the fact, not the prose - If removing a roadmap item, don't leave a gap — remove the bullet cleanly - If adding a feature
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (2)
.claude/skills/company-creator
.claude/skills/paperclip
Gates applied: no_behavioural_pass.
59d017e6174afull audit observations/trust-audit/skill/paperclipai__doc-maintenance.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-23 | 59d017e6174a | CAUTION | B | 89 | first audit |
Questions
What does the Doc Maintenance skill do?
The open-source app everyone uses to manage agents at work
Is Doc Maintenance safe to install?
With care. The audit graded it B (89/100) and found 2 things worth knowing before you trust this skill, listed below with the exact line each was found on.
What can Doc Maintenance access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Doc Maintenance work with?
Its documentation mentions cursor and openclaw. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (59d017e6174a), read on 2026-09-23. The repository is watched, and a new audit runs when it changes — this is the first audit.