跳到主要内容
知仓学习社ZHICANG

quality

AI code quality checks. The Big 5: input validation, edge cases, error handling, duplication, complexity. Triggers: quality, big 5, ai code, review,…

不碰外部(只输出文字)无严重或高危命中hashgraph-online/awesome-codex-plugins

它会碰到什么

扫了多少2 个文本文件,8 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

<skill id="quality">

<purpose>

AI code is 1.7x buggier. These 5 checks catch 80% of issues.

Load this skill for any review, validation, or implementation work.

</purpose>

<reference>

Verbose research: skills/quality/reference/quality-research.md

</reference>

<big5>

<check id="1" name="input_validation" detection="grep -r 'req\.body' | grep -v 'parse\|validate\|z\.'">

Every endpoint has Zod/Pydantic schema. Parameterized queries only.

</check>

<check id="2" name="edge_cases" detection="search for array access without length check">

Handle: null, empty array, zero-length string, timeout, unicode.

</check>

<check id="3" name="error_handling" detection="grep -r 'catch.*{}'">

No empty catch. Errors logged with context. User messages generic.

Silent swallowing is the worst variant: a catch/onError that returns a masked or

generic body without first logging method/path/cause hides the root failure behind

a 500 and costs a full re-diagnosis per incident. Every handler logs the cause

before it masks. Missing config/dependency is a NAMED condition in the response

(which var, which service), never a generic error.

</check>

<check id="4" name="duplication" detection="jscpd or manual review">

Same logic in 3+ places = extract to utility.

</check>

<check id="5" name="complexity" detection="eslint complexity rule">

Functions under 30 lines. No nested ternaries > 2 levels.

</check>

<check id="6" name="gate_integrity" detection="seed a known violation and confirm the gate goes red">

A gate nobody has seen fail is not a gate. Before trusting any check you ship or run:

  • Prove it red. Seed the exact violation it claims to catch, watch it fail, then unseed.

A gate that has only ever printed PASS is measuring nothing.

  • The checker re-derives its evidence. A hash, a "PASS" string, a file that merely exists,

or a count supplied by the thing being checked is an assertion, not evidence. Read the

bytes, run the command, fetch the remote.

  • Exit 0 with empty or blank output is a failure, not a pass. Never pipe a gate to

tail/head; the pipe reports the pager's exit code.

  • A gate that stays green after you delete the code it guards is blind. Delete-and-rerun

is the cheapest mutation test there is.

  • Randomness in a gate makes it a coin flip. Pin the seed or pin the input.
  • Absence of a run is red, not pending.

</check>

</big5>

<quick_checks>

# 1. Missing validation
grep -r "req\.body" --include="*.ts" --include="*.js" | grep -v "parse\|validate\|z\." | head -5

# 2. Empty catch blocks
grep -r "catch.*{}" --include="*.ts" --include="*.js" | head -5

# 3. String concat in queries (SQL injection)
grep -rE "SELECT.*\$\{|INSERT.*\$\{" --include="*.ts" --include="*.js" | head -5

</quick_checks>

<data_correctness>

For any pipeline that extracts or transforms figures (financial, metrics, counts):

  • Parse deterministically (a real parser, regex, typed loader). The LLM never

generates, transforms, or "fixes" numeric values.

  • Units are explicit at parse time (percent vs fraction, counts vs currency);

a value never crosses unit categories through arithmetic.

  • Tie-out gate: derived aggregates must reproduce the source's own totals before

any output is shown downstream. A delta between your output and the source is

assumed to be YOUR normalization bug until proven otherwise.

  • Silent-empty guard: "no findings" produced from an empty parse is a failure of

the parse, not a finding.

</data_correctness>

<verdict>

Any Big 5 violation = NOT READY

Fix before commit. No exceptions.

</verdict>

<on_complete>

agentdb write-end '{"skill":"quality","big5_checked":true,"violations":N}'

</on_complete>

</skill>

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

同名技能的其他版本

有 2 个不同仓库或目录里都有叫 quality 的技能。它们内容并不相同,别混用: