跳到主要内容
知仓学习社ZHICANG

codebase-sync

Convention discovery and rule generation from codebase analysis. Scans project structure, builds search indexes, identifies patterns, and generates …

执行命令严重 1 · 高危 0a5c-ai/babysitter

它会碰到什么

扫了多少2 个文本文件,3 KB
它会碰到什么执行命令
命中总数1 处
命中统计严重 1 · 高 0 · 中 0 · 低 0
逐条看命中(1 条严重或高危)
  • 严重 SKILL.md:3perm-wildcard
    allowed-tools: Bash(*) Read Write Edit Glob Grep

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

  • Scan directory structure for project type identification
  • Detect language, framework, package manager
  • Identify build tools, CI/CD config, test framework
  • Map high-level architecture (monorepo, microservices, etc.)

2. Semantic Index Building

Four parallel index domains:

  • Code Index: Source files with exports, purposes, dependencies
  • Test Index: Test files with cases, fixtures, patterns
  • Config Index: Configuration files with parsed rules
  • API Index: Public interfaces, types, data models

3. Convention Discovery

  • Code style patterns (naming, structure, organization)
  • Error handling conventions
  • Testing conventions (naming, structure, assertions)
  • Git commit message conventions
  • Documentation standards
  • Language-conditional standards

4. Rule Generation

Convert conventions into enforceable rules:

{
  "id": "ts-no-any",
  "category": "coding-standards",
  "description": "Avoid 'any' type; use 'unknown' and narrow",
  "severity": "error",
  "autoFixable": false,
  "language": "typescript"
}

Rule Categories

| Category | Examples |

|----------|---------|

| core | task-and-workflow, testing, verification |

| dev-practices | development-practices, context-management |

| tools | research-tools, cli-tools |

| coding-standards | Language-specific rules (conditional) |

Output Artifacts

  • artifacts/CONVENTIONS.md -- Discovered conventions
  • artifacts/SEARCH-INDEX.json -- Semantic search index
  • artifacts/RULES.md -- Generated project rules

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。