跳到主要内容
知仓学习社ZHICANG

sapcc-audit

Full-repo SAP CC Go compliance audit against review standards.

不碰外部(只输出文字)无严重或高危命中notque/vexjoy-agent

它会碰到什么

扫了多少4 个文本文件,17 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

SAPCC Full-Repo Compliance Audit v2

Review every package against established review standards. Not checklist compliance — code-level review that finds over-engineering, dead code, interface violations, and inconsistent patterns.


Reference Loading Table

| Signal | Load This File | When |

|--------|---------------|------|

| Phase 1 begins | references/phase-1-discover-commands.md | Detection commands, package mapping, segmentation table |

| Phase 2 begins | references/phase-2-dispatch-agents.md | Full dispatch prompt and per-domain review checklist (11 areas) |

| Phase 3 begins | references/output-templates.md | Report scaffold, per-finding format, severity guide |

Load each reference file at the start of its phase. Do not load all three upfront.


Instructions

Phase 1: DISCOVER

Goal: Map the repository and plan the package segmentation.

Read references/phase-1-discover-commands.md for the exact detection commands, segmentation table, and file-count queries.

Verify this is an sapcc project (sapcc imports in go.mod). If not, stop immediately.

Map all packages, count files per package, and produce a segmentation table (5–8 agents, 5–15 files each).

Gate: Packages mapped, agents planned. Proceed to Phase 2.


Phase 2: DISPATCH

Goal: Launch parallel agents that review packages against project standards.

Read references/phase-2-dispatch-agents.md for the full dispatch prompt (11 review areas: over-engineering, dead code, error messages, constructors, interface contracts, copy-paste, HTTP handlers, database patterns, type patterns, logging, mixed approaches).

Use the standard dispatch prompt verbatim, substituting the assigned package list.

Dispatch all agents in a single message using the Task tool with subagent_type=golang-general-engineer.

Gate: All agents dispatched. Proceed to Phase 3.


Phase 3: COMPILE REPORT

Goal: Aggregate findings into a code-level compliance report.

Read references/output-templates.md for the report scaffold, per-finding format, and deduplication rules.

Deduplicate by file:line. Write sapcc-audit-report.md. Display verdict, must-fix count, and top 5 findings inline.

Gate: Report complete.


Error Handling

| Scenario | Response |

|----------|----------|

| Not an sapcc project | Stop immediately. Print: "This does not appear to be an SAP CC Go project (no sapcc imports in go.mod)." |

| Agents cannot read a file | Log and continue. Flag in the report under "Warnings." |

| gopls MCP tools unavailable | Fall back to manual grep-based analysis. Note in the report. |

| Too many packages (>30) | Split into >8 agents. Ensure each still gets 5-15 files. |

| Agent finds no violations | Report is valid. Output empty sections for unused severity levels. |

Audit only: READS and REPORTS. Does NOT modify code unless explicitly asked with --fix.


Integration

  • Router: /do routes via "sapcc audit", "sapcc compliance", "sapcc lead review"
  • Pairs with: go-patterns (the rules), golang-general-engineer (the executor)

Per-agent reference loading (included in each agent's dispatch prompt based on assigned packages)

| Package Type | Reference to Load |

|-------------|-------------------|

| HTTP handlers (internal/api/) | api-design-detailed.md |

| Test files (*_test.go) | testing-patterns-detailed.md |

| Error handling heavy packages | error-handling-detailed.md |

| Architecture/drivers | architecture-patterns.md |

| Build/CI config | build-ci-detailed.md |

| Import-heavy files | library-reference.md |

Always available for calibration (load only when needed): quality-issues.md, review-standards-lead.md.

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

它属于哪个仓库

星标★ 419
本站分层T2
该仓技能数122
原文件路径skills/engineering/sapcc-audit/SKILL.md

同一个仓库里的其他技能

看这个仓库的全部 122 个技能