aif-rules-check
Run a standalone read-only rules compliance gate against changed files or a git ref. Use when you need a dedicated project-rules check without a ful…
它会碰到什么
逐条看命中(1 条严重或高危)
- 严重
SKILL.md:4perm-wildcardallowed-tools: Read Glob Grep Bash(git *) AskUserQuestion
这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。
技能内容
Rules Compliance Gate
Run a standalone read-only rules gate for project rules. This command checks rule compliance only; it does not replace /aif-review or /aif-verify.
Step 0: Load Contract
- Read
references/RULES-CHECK-CONTRACT.mdfirst. - Treat it as the canonical source for verdict semantics and report structure.
- If examples in this file drift from the reference, follow the reference.
Step 1: Load Config
FIRST: Read .ai-factory/config.yaml if it exists to resolve:
paths.rules_filepaths.rulespaths.planpaths.planslanguage.uigit.enabledgit.base_branchrules.base- named
rules.<area>entries workflow.plan_id_format(default:slug) — used by the optional branch-based plan-context lookup in Step 2.3.
Active values: slug and sequential. Plan context may be a root full-plan
file or direct child ultra index.md; numbered lookup covers both shapes.
timestamp and uuid are reserved values and currently behave like slug.
Treat any unknown value as slug.
If config is missing or partial, use defaults:
paths.rules_file:.ai-factory/RULES.mdpaths.rules:.ai-factory/rules/paths.plan:.ai-factory/PLAN.mdpaths.plans:.ai-factory/plans/git.enabled:truegit.base_branch: detect the repo default branch from git metadata; fall back tomainonly when detection is unavailablerules.base:.ai-factory/rules/base.mdworkflow.plan_id_format:slug
If paths.rules_file is missing from config, default to .ai-factory/RULES.md instead of treating config as incomplete.
If git.base_branch is missing from config, resolve the repository default branch from git metadata when possible; use main only as the final fallback.
Step 1.1: Load Skill Context
Read .ai-factory/skill-context/aif-rules-check/SKILL.md - MANDATORY if the file exists.
This file contains project-specific rules accumulated by /aif-evolve from patches,
codebase conventions, and tech-stack analysis. These rules are tailored to the current project.
How to apply skill-context rules:
- Treat them as project-level overrides for this skill's general instructions.
- When a skill-context rule conflicts with a general rule in this file, the skill-context rule wins.
- When there is no conflict, apply both.
- Skill-context rules apply to all outputs of this skill, including verdict wording and report structure.
Enforcement: Before presenting the final report, verify it against all skill-context rules and fix any drift.
Step 2: Resolve Inputs
Resolve two inputs before checking any rule:
- Changed scope - the diff and file list you are evaluating
- Resolved rule sources - the rule artifacts that may apply to that scope
Step 2.1: Resolve Changed Scope
If the user provided a git ref:
- Validate it first:
git rev-parse --verify <argument>
- If valid, use:
git diff --name-only <argument>...HEAD
git diff <argument>...HEAD
- If invalid, ask:
AskUserQuestion: `<argument>` is not a valid git ref. What should I check instead?
Options:
1. Check staged / working-tree changes
2. Cancel
Without arguments:
- Prefer staged work:
git diff --cached --name-only
git diff --cached
- If nothing is staged, fall back to working tree:
git diff --name-only
git diff
- If there is still no local diff and
git.enabled = true, fall back to branch diff:
git diff --name-only <resolved-base-branch>...HEAD
git diff <resolved-base-branch>...HEAD
If there are still no changed files, return WARN rather than a hard failure.
Step 2.2: Resolve Rule Sources
Load rule sources in this order:
- The resolved
paths.rules_fileartifact - The resolved
rules.basefile - Any named
rules.<area>files from config that clearly match the changed scope
Area rules are optional and scoped:
- Use changed file paths, folder names, and optional plan context to judge relevance.
- If relevance is ambiguous, mention the rule source as uncertain and keep the outcome at
WARN, notFAIL.
If no rules sources resolve, return WARN rather than a hard failure.
Step 2.3: Optional Plan Context
Optional plan context: use the active plan file only when it helps interpret scope or area relevance; absence of a plan is never a failure.
Plan resolution order:
- Compute the canonical branch stem the same way as
/aif-plan,
/aif-implement, and /aif-improve:
- get current branch via
git branch --show-current(git mode only); branch_stem= current branch with every/replaced by-
(for example feature/user-auth → feature-user-auth).
- Branch-based lookup using
<branch_stem>:
- when
workflow.plan_id_format = sequential, glob both
paths.plans/[0-9][0-9][0-9][0-9]_<branch_stem>.md and
paths.plans/[0-9][0-9][0-9][0-9]_<branch_stem>/index.md; Read every
directory candidate and retain it only when it contains exactly one
<!-- aif:plan-mode:ultra -->, then pick the highest-numbered valid
artifact and warn when multiple valid candidates exist; prefer ultra if
both shapes share the highest prefix;
- otherwise/fallback check
paths.plans/<branch_stem>/index.mdand
paths.plans/<branch_stem>.md; Read the directory entrypoint first, ignore
it unless it contains exactly one ultra marker, and warn/prefer ultra if
both valid shapes exist.
- A single named artifact in
paths.plans: count root*.mdfull plans and
direct child */index.md entrypoints containing
<!-- aif:plan-mode:ultra -->; exclude
the resolved fast-plan path and never count phase files.
- The fast plan at
paths.plan.
For ultra, read index.md first and only the linked phase files relevant to the
changed area when extra scope detail is needed. Do not fail the rules check
because a plan artifact is missing or ambiguous.
An automatically discovered directory entrypoint counts only when it contains
exactly one <!-- aif:plan-mode:ultra -->; ignore unrelated */index.md files.
Step 3: Evaluate Rules
Read the changed files from the resolved scope and compare them against the resolved rules.
Classification rules:
PASSwhen at least one applicable rule was checked and no clear violations were found.WARNwhen no applicable rules were resolved, the evidence is ambiguous, or there are no changed files to evaluate.FAILwhen an explicit hard rule is clearly violated by the inspected diff or changed files.
Only return FAIL when an explicit hard rule is clearly violated by the inspected diff or changed files.
Evidence rules:
- Tie every blocking violation to specific rule text and at least one concrete file/path or diff hunk.
- If a rule sounds like a preference, is too vague, or cannot be verified confidently from the diff, do not escalate it past
WARN. - Missing optional files or partially configured rules hierarchy are
WARN, notFAIL.
Step 4: Read-Only Boundary
This command is read-only: do not edit RULES.md, rules/base.md, rules.<area>, plan files, or source code.
If rules are missing, stale, or need refinement:
- Suggest
/aif-rules <rule text>for axioms - Suggest
/aif-rules area:<name>for area-specific rules
Step 5: Output
Use the exact verdict semantics and section order from references/RULES-CHECK-CONTRACT.md.
Required content:
- overall verdict
- files checked
- gate results
- blocking violations
- suggested fixes
- suggested rule updates
- final machine-readable
aif-gate-resultfenced JSON block
When useful, suggest the next best workflow:
/aif-reviewfor broader code review/aif-verifyfor full plan-completeness verification/aif-ruleswhen the underlying rules need to be captured or corrected
Machine-readable gate result:
- Append one final fenced
aif-gate-resultJSON block after the human-readable rules report. - Use
"gate": "rules". - Map the human rules verdict exactly:
PASS->pass,WARN->warn, andFAIL->fail. - Use
"blocking": true|false; set it totrueonly for explicit hard-rule violations that produce a humanFAIL. - Include only hard-rule violations in
"blockers": [. - Include changed or inspected paths in
"affected_files": [. - Set
"suggested_next": {to/aif-ruleswhen rules should be added or clarified,/aif-fixwhen code must change, ornullwhen no allowed next command fits. - Do not use
/aif-reviewin the JSONsuggested_next.command; it may appear only in human-readable workflow suggestions.
{
"schema_version": 1,
"gate": "rules",
"status": "warn",
"blocking": false,
"blockers": [],
"affected_files": [],
"suggested_next": {
"command": "/aif-rules",
"reason": "Rules are missing or ambiguous for the changed scope."
}
}
Schema reminder: "status": "pass|warn|fail", "blocking": true|false, "blockers": [, "affected_files": [, "suggested_next": {.
想直接用这个技能?
本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。