Atlas / Skills / runkids / Skillshare Implement Feature

Skillshare Implement FeatureSAFE

skills/runkids/skillshare-implement-feature

๐Ÿ“š Sync skills, agents, MCP, plugins to all AI CLI tools with one command and simplify team sharing.

Verdict
SAFE
Grade
B
Trust score
89 /100
Version
โ€”
Hosts
โ€”
License
MIT
Stars
2,749
01

Overview

๐Ÿ“š Sync skills, agents, MCP, plugins to all AI CLI tools with one command and simplify team sharing.

Read from source at commit 0d9340b2ca90OBSERVED ยท 2026-10-08
02

What it tells the agent

The instruction file, verbatim from the audited commit โ€” this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: skillshare-implement-feature
description: >-
  Implement a feature from a spec file or description using TDD workflow. Use
  this skill whenever the user asks to: add a new CLI command, implement a
  feature from a spec, build new functionality, add a flag, create a new
  internal package, or write Go code for skillshare. This skill enforces
  test-first development, proper handler split conventions, oplog
  instrumentation, and dual-mode (global/project) patterns. If the request
  involves writing Go code and tests, use this skill โ€” even if the user
  doesn't explicitly say "implement".
argument-hint: "[spec-file-path | feature description]"
metadata: 
  targets: [claude, universal]
---

Implement a feature following TDD workflow. $ARGUMENTS is a spec file path (e.g., `specs/my-feature.md`) or a plain-text feature description.

**Scope**: This skill writes Go code and tests. It does NOT update website docs (use `update-docs` after) or CHANGELOG (use `changelog` after).

Before acting, run `python3 scripts/ai-context.py cli-development testing`. Those topics are the source of truth for repository patterns, execution boundaries and verification; this skill retains the TDD orchestration.

## Workflow

### Step 1: Understand Requirements

If $ARGUMENTS is a file path:
1. Read the spec file
2. Extract acceptance criteria and edge cases
3. Identify affected packages

If $ARGUMENTS is a description:
1. Search existing code for related functionality
2. Identify the right package to extend
3. Ask the user only if ambiguity would materially change scope or public interfaces

### Step 2: Identify Affected Files

List all files that will be created or modified:

```bash
# Typical pattern for a new command
cmd/skillshare/<command>.go          # Command handler
cmd/skillshare/<command>_project.go  # Project-mode handler (if dual-mode)
internal/<package>/<feature>.go      # Core logic
tests/integration/<command>_test.go  # Integration test
```

Display the file list and continue.

### Step 3: Write Failing Tests First (RED)

Write integration tests using `testutil.Sandbox`:

```go
func TestFeature_BasicCase(t *testing.T) {
    sb := testutil.NewSandbox(t)
    defer sb.Cleanup()

    // Setup
    sb.CreateSkill("test-skill", map[string]string{
        "SKILL.md": "---\nname: test-skill\n---\n# Content",
    })

    // Act
    result := sb.RunCLI("command", "args...")

    // Assert
    result.AssertSuccess(t)
    result.AssertOutputContains(t, "expected output")
}
```

Verify tests fail (inside the devcontainer, see the `skillshare-devcontainer` skill):
```bash
docker exec "$CONTAINER" bash -c 'cd /workspace && go test ./tests/integration -run TestFeature_BasicCase -count=1'
```

### Step 4: Implement (GREEN)

Write minimal code to make tests pass:

1. Follow existing patterns in `cmd/skillshare/` and `internal/`
2. Use `internal/ui` for terminal output (colors, spinners, boxes)
3. Add oplog instrumentation for mutating commands:
   ```go
   start := time.Now()
   // ... do work ...
   e := oplog.NewEntry("command-name", statusFromErr(err), time.Since(start))
   oplog.Write(configPath, oplog.OpsFile, e)
   ```
4. Register command in `main.go` commands map if new command

Verify tests pass:
```bash
docker exec "$CONTAINER" bash -c 'cd /workspace && make test-int'
```

### Step 5: Refactor and Verify

1. Clean up code while keeping tests green
2. Run full quality check:
   ```bash
   docker exec "$CONTAINER" bash -c 'cd /workspace && make check'  # fmt-check + lint + test
   ```
3. Fix any formatting or lint issues

## Project Patterns Reference

These patterns appear throughout the codebase. Follow them when implementing new features.

### Handler Split Convention

Large commands are split by concern rather than kept in a single file. When a command handler grows beyond ~300 lines, split it:

| Suffix | Purpose | Example |
|--------|---------|---------|
| `<cmd>.go` | Flag parsing + mode routing (dispatch) | `install.go` |
| `_handlers.go` | Core handler logic | `install_handlers.go` |
| `_render.go` / `_audit_render.go` | Output rendering | `audit_render.go` |
| `_prompt.go` / `_prompt_tui.go` | Decision/prompt logic | `install_prompt.go` |
| `_tui.go` | Full-screen TUI (bubbletea) | `list_tui.go` |
| `_batch.go` | Batch operation orchestration | `update_batch.go` |
| `_resolve.go` | Target/skill resolution | `update_resolve.go` |
| `_context.go` | Mode-specific context struct | `install_context.go` |
| `_format.go` | Output formatting helpers | `log_format.go` |

**Principle**: dispatch file does ONLY flag parsing + mode routing. Logic goes in sub-files.

### Dual-Mode Command Pattern

Most commands support both global (`-g`) and project (`-p`) mode:

```go
func handleMyCommand(args []string) error {
    mode, rest, err := parseModeArgs(args)
    if err != nil { return err }

    switch mode {
    case modeProject:
        return handleMyCommandProject(rest)
    default:
        return handleMyCommandGlobal(rest)
    }
}
```

Create `<cmd>_project.go` for project-mode handler. Use `parseModeArgs()` from `mode.go`.

### TUI Components (bubbletea)

All interactive prompts use **bubbletea** (not survey). Key components:

- `checklist_tui.go` โ€” shared checklist/radio picker
- `list_tui.go` โ€” filterable list with detail panel
- `search_tui.go` โ€” multi-select checkbox list

Color palette: cyan `Color("6")`, gray `Color("8")`, yellow `#D4D93C`.

Dispatch order: JSON output โ†’ TUI (if TTY + items + no `--no-tui` flag) โ†’ empty check โ†’ plain text.

### Web API Endpoint

If the feature needs a Web UI endpoint, add `internal/server/handler_<name>.go`:

```go
func (s *Server) handle<Name>(w http.ResponseWriter, r *http.Request) {
    // ...
    writeJSON(w, result)       // 200 OK with JSON
    // writeError(w, 400, msg) // for errors
}
```

Register in `server.go` route setup. Branch on `s.IsProjectMode()` for mode-specific behavior.

### Oplog Instrumentation

All mutating commands log to `operations.lo
03

Trust audit

SAFEgrade B ยท trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeNA
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (1)

MEDIUMInventory / provenance ยท inv.symlink ยท CWE-1104
.devcontainer/bin/dev-servers
.devcontainer/bin/dev-servers
Why it matters. link not followed

Gates applied: no_behavioural_pass.

Audited 2026-10-08 ยท audit v0.4.1 ยท source sha 0d9340b2ca90full audit observations/trust-audit/skill/runkids__skillshare-implement-feature.json ยท Report an issue / request a re-scan
04

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-080d9340b2ca90SAFEB89first audit
05

Questions

What does the Skillshare Implement Feature skill do?

๐Ÿ“š Sync skills, agents, MCP, plugins to all AI CLI tools with one command and simplify team sharing.

Is Skillshare Implement Feature safe to install?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.

What can Skillshare Implement Feature access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

How current is this page?

The grade is for one exact copy of the source (0d9340b2ca90), read on 2026-10-08. The repository is watched, and a new audit runs when it changes โ€” this is the first audit.

Advertisement