LearnSAFE
🥷 Engineering habits you already know, turned into skills Claude can run.
Overview
🥷 Engineering habits you already know, turned into skills Claude can run.
9a1bc1900b35OBSERVED · 2026-10-07What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: learn description: "Runs a six-phase research workflow from source bundle to publish-ready output. Use when researching an unfamiliar domain or compiling materials into one reference. Not for quick lookups or single-file reads." when_to_use: "学习一下, 深入研究, 研究一下, 整理成文章, 把这批材料整理, 一站式参考, 一篇就够, 整理成长文, research, deep dive, help me understand, compile sources, unfamiliar domain" dispatch_intent: "Deep research, unfamiliar domain, compile sources into output" --- # Learn: From Raw Materials to Published Output Prefix your first line with 🥷 inline, not as its own paragraph. Support the user's thinking; do not replace it. ## Outcome Contract - Outcome: unfamiliar material becomes a reliable mental model, reference, article, or notes set the user can use. - Done when: primary sources are collected or supplied, contradictions are handled explicitly, and the final structure teaches the topic without hiding uncertainty. - Evidence: source URLs or files, fetched content, notes from digestion, outline decisions, and self-review against the requested output. - Output: research notes, outline, publish-ready draft, or canonical reference, matching the chosen mode. **Boundary**: single URL that only needs fetching belongs in `/read`. A single URL that needs summary or analysis can use `/read` as the fetch step, but the final answer should satisfy the user's requested summary or analysis. `/learn` is for multi-source research that produces a new structured output. ## Choose Mode Infer the mode from the requested artifact and supplied materials. Ask only when plausible modes would change the scope or deliverable and the user's intent does not resolve the choice: | Mode | Goal | Entry | Exit | |------|------|-------|------| | **Deep Research** | Understand a domain well enough to write about it | Phase 1 | Phase 6: publish-ready draft | | **Quick Reference** | Build a working mental model fast, no article planned | Phase 2 | Phase 2: notes only | | **Write to Learn** | Already have materials, force understanding through writing | Phase 3 | Phase 6: publish-ready draft | | **Canonical Article** | One article that covers a topic so thoroughly readers need nothing else | Phase 1 | Phase 6: single authoritative reference | If unsure, suggest Quick Reference. ## Canonical Article Mode Activate when: "一篇就够", "一站式参考", "整理成长文", "目的是大家只需要看这篇就好了", or the user wants a single authoritative reference on a topic. Goal: after reading the article, no one should need to search for anything else on this topic. Additional requirements on top of standard Deep Research: - Every major sub-topic must have its own section; nothing left as a footnote - Include worked examples, not just principles - Cover common mistakes and how to avoid them - Add a "Further Reading" section with the 3-5 sources that go deepest; flag which ones are the best starting points - Phase 6 self-review must confirm: "Could a reader implement/understand this from this article alone?" ## Phase 1: Collect Gather primary sources only: papers that introduced key ideas, official lab/product blogs, posts from builders, canonical "build it from scratch" repositories. Not summaries. Not explainers. Three ordered steps per source -- no shortcuts, no merging: 1. **Discover** -- use an installed search plugin to map the landscape, then deep-search the 2-3 most promising sub-topics. No plugin: use the environment's native web search. Output is a URL list; do not fetch content here. 2. **Fetch** -- every URL goes through `/read` when available. `/read` owns the proxy cascade, paywall detection, and platform routing (WeChat, Feishu, PDF, GitHub). Native fetch tools and raw `curl` silently fail on JS-heavy or paywalled sites and skip all of that. If `/read` is not installed, warn once without blocking, fall back to native fetch, and state the reduced coverage on paywalled, JS-heavy, and Chinese-platform pages. 3. **File** -- tell `/read` the research project's source directory when one exists. If no directory was specified, let `/read` use a per-session temp directory and return the saved path. Move or index saved files into sub-topic directories after fetch returns. Move, don't refetch. Target: 5-10 sources for a blog post, 15-20 for a deep technical survey. ## Phase 2: Digest Work through the materials. For each piece: read it fully, keep what is good, cut ruthlessly what is not. For key claims, ask before including in the outline: - Does this idea appear in at least two different contexts from the same source? - Can this framework predict what the source would say about a new problem? - Is this specific to this source, or would any expert in the field say the same thing? Generic wisdom is not worth distilling. Passes two or three: belongs in the outline. Passes one: background material. Passes zero: cut it. ### Conversation Or Review Distillation When the input is a recent conversation, project review, scorecard, or diagnostic report, treat it as raw material. Read distilled summaries, memory entries, and review outputs first; open raw transcripts only to verify a disputed detail or recover the exact source of a repeated pattern. Before editing durable guidance, build a candidate matrix (source/project, repeated failure, transferable rule, target layer, evidence count, redaction risk) and promote only candidates with cross-source support or a repeated failure in the same project family. Map each repeated workflow failure, invariant, or verifier surface to project docs, shared rules, skill references, or a deterministic script that can fail reliably without project context. Drop dated line numbers, current-score framing, private paths, one-machine setup, and repo-specific commands unless the output is for that same repo, and keep raw conversation history out of the final artifact. ## Phase 3: Outline Write the outline for the article. For each section: note the source materials it draws from. If a section has no sources, either it does n
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (1)
CLAUDE.md
Gates applied: no_behavioural_pass.
9a1bc1900b35full audit observations/trust-audit/skill/tw93__learn.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 9a1bc1900b35 | SAFE | B | 89 | first audit |
Questions
What does the Learn skill do?
🥷 Engineering habits you already know, turned into skills Claude can run.
Is Learn safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Learn access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
How current is this page?
The grade is for one exact copy of the source (9a1bc1900b35), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.