跳到主要内容
知仓学习社ZHICANG

behavior-contract

Bug condition/postcondition formalization as testable Behavior Contracts. Defines invariants that must be preserved across fixes.

执行命令严重 1 · 高危 0a5c-ai/babysitter

它会碰到什么

扫了多少2 个文本文件,3 KB
它会碰到什么执行命令
命中总数1 处
命中统计严重 1 · 高 0 · 中 0 · 低 0
逐条看命中(1 条严重或高危)
  • 严重 SKILL.md:3perm-wildcard
    allowed-tools: Bash(*) Read Write Edit Glob Grep

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

  • "Positive amounts still process correctly"
  • "Negative amounts still throw InvalidAmountError"
  • "Receipt format remains unchanged for all amount types"

Contract Document Template

# Behavior Contract: [Bug Title]

## Bug Condition
[Precise description of triggering conditions]

## Postcondition
[Expected correct behavior after fix]

## Invariants
- [ ] Invariant 1: [existing behavior to preserve]
- [ ] Invariant 2: [existing behavior to preserve]

## Testable Assertions
1. `expect(processPayment(0)).toEqual({ amount: 0, status: 'completed' })`
2. `expect(processPayment(100)).toEqual({ amount: 100, status: 'completed' })`
3. `expect(() => processPayment(-1)).toThrow(InvalidAmountError)`

Usage in Bugfix Workflow

  1. Bug analysis identifies root cause at file:line
  2. This skill formalizes the contract from the analysis
  3. tdd-enforcer writes failing test from Bug Condition
  4. tdd-enforcer writes preservation tests from Invariants
  5. Minimal fix applied, contract audited

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。