Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
21 commits
Select commit Hold shift + click to select a range
04f15c5
docs: correct the skill count to 14,011
Patel230 Sep 26, 2026
9b5e2de
fix(registry): exclude bytecode from file_count so output is reproduc…
Patel230 Sep 26, 2026
5dc2034
chore: remove the stray root SKILL.md
Patel230 Sep 26, 2026
e16415e
fix(docker): make the published image's default command pass
Patel230 Sep 26, 2026
56920a7
fix(validate): make manifest-schema.toml the only schema the gate uses
Patel230 Sep 26, 2026
034e248
feat(registry): record license, author and source provenance per skill
Patel230 Sep 26, 2026
fa91524
fix(licenses): enforce the copyleft ban on frontmatter license values
Patel230 Sep 26, 2026
e5653d9
fix(plugin): publish one valid Claude Code plugin per category
Patel230 Sep 26, 2026
615c933
fix(governance): point CODEOWNERS at an owner that exists
Patel230 Sep 26, 2026
e8eea88
fix(setup): install skills where Rho actually loads them
Patel230 Sep 26, 2026
13effbb
build: align pyproject with Python 3.11 and Rho
Patel230 Sep 26, 2026
565bf01
ci: run every repository gate in the required CI job
Patel230 Sep 26, 2026
bc9812a
feat(schema): support the Agent Skills standard and measure the gap
Patel230 Sep 26, 2026
08c5473
feat(skills): add rho-workflow, rover-verify and across-checkpoint
Patel230 Sep 26, 2026
e3e6a9d
ci(duplication): make the required jscpd gate able to fail
Patel230 Sep 26, 2026
b58a22a
docs(agents): make the GitNexus rules optional and fix the dev commands
Patel230 Sep 26, 2026
1387ae2
docs: replace retired product names and false tooling claims
Patel230 Sep 26, 2026
444f4a1
chore(release): set the next version to 0.2.0
Patel230 Sep 26, 2026
d090c74
docs: make README, STATUS and CONTRIBUTING match the repository
Patel230 Sep 26, 2026
0c2a3a8
docs(changelog): record the unreleased 0.2.0 changes
Patel230 Sep 26, 2026
80463cf
fix(validate): do not fail list-form allowed-tools in the corpus gate
Patel230 Sep 26, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
70,311 changes: 250 additions & 70,061 deletions .claude-plugin/marketplace.json

Large diffs are not rendered by default.

6 changes: 4 additions & 2 deletions .claude-plugin/plugin.json
Original file line number Diff line number Diff line change
@@ -1,15 +1,17 @@
{
"name": "graycode-skills",
"version": "0.0.1",
"description": "Community skill packages for graycode \u2014 the AI coding agent. Security, code review, DevOps, and more.",
"version": "0.2.0",
"description": "GrayCode Skills: community Agent Skills (SKILL.md) packages for Rho, the terminal AI coding agent, and other skill-aware agents. Security, code review, DevOps and more.",
"author": {
"name": "GrayCode AI",
"url": "https://github.com/GrayCodeAI"
},
"repository": "https://github.com/GrayCodeAI/graycode-skills",
"license": "MIT",
"keywords": [
"rho",
"graycode",
"agent-skills",
"skills",
"code-review",
"security",
Expand Down
4 changes: 2 additions & 2 deletions .codex-plugin/plugin.json
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"name": "graycode-skills",
"version": "0.0.1",
"description": "Community skill packages for graycode \u2014 security, code review, DevOps, and more.",
"version": "0.2.0",
"description": "GrayCode Skills: community Agent Skills (SKILL.md) packages for Rho, the terminal AI coding agent, and other skill-aware agents. Security, code review, DevOps and more.",
"author": "GrayCode AI",
"repository": "https://github.com/GrayCodeAI/graycode-skills",
"license": "MIT"
Expand Down
4 changes: 2 additions & 2 deletions .cursor-plugin/plugin.json
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"name": "graycode-skills",
"version": "0.0.1",
"description": "Community skill packages for graycode \u2014 security, code review, DevOps, and more.",
"version": "0.2.0",
"description": "GrayCode Skills: community Agent Skills (SKILL.md) packages for Rho, the terminal AI coding agent, and other skill-aware agents. Security, code review, DevOps and more.",
"author": "GrayCode AI",
"repository": "https://github.com/GrayCodeAI/graycode-skills",
"license": "MIT"
Expand Down
11 changes: 7 additions & 4 deletions .env.example
Original file line number Diff line number Diff line change
@@ -1,5 +1,8 @@
# graycode-skills environment variables — copy to .env and fill in
# graycode-skills is a skill registry with no network service.
# graycode-skills environment variables (all optional).
# This repository has no network service and reads no secrets.

# Optional: override the default skills installation directory
GRAYCODE_SKILLS_DIR=~/.graycode/skills
# Where `./setup --host rho` copies skills: <RHO_STATE_DIR>/skills. Leave unset
# to use Rho's default state directory ($XDG_STATE_HOME/rho, else
# ~/.config/rho/state on Linux or ~/Library/Application Support/rho/state on
# macOS). This is the same variable Rho itself reads.
# RHO_STATE_DIR=
33 changes: 6 additions & 27 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -1,29 +1,8 @@
# CODEOWNERS for graycode-skills
#
# GitHub CODEOWNERS uses last-match-wins: more specific rules must come AFTER
# more general ones to actually take effect. /categories/ and /registry.json
# are deliberately listed after the blanket *.md rule below so skill content
# (the vast majority of this repo, nearly all of it .md) is owned by
# core-team, not docs-team — docs-team owns the repo's own docs, not the
# ~12k community-submitted skill files.
* @GrayCodeAI/maintainers

# CI / release / build tooling
/.github/ @GrayCodeAI/devops-team
/Makefile @GrayCodeAI/devops-team
/lefthook.yml @GrayCodeAI/devops-team
/scripts/ @GrayCodeAI/devops-team
/deploy/ @GrayCodeAI/devops-team
/Dockerfile @GrayCodeAI/devops-team

# Documentation (repo-level only — see /categories/ override below)
*.md @GrayCodeAI/docs-team
/docs/ @GrayCodeAI/docs-team

# Skill definitions and categories (wins over the blanket *.md rule above)
/categories/ @GrayCodeAI/core-team
/registry.json @GrayCodeAI/core-team

# Validation and tooling
/tools/ @GrayCodeAI/core-team
/tests/ @GrayCodeAI/core-team
# The GrayCodeAI organization has no teams yet, and @Patel230 is the only
# account with write access, so every path is owned by that account. When
# teams exist, split ownership again (CODEOWNERS is last-match-wins: put
# specific paths after general ones) and verify with:
# gh api repos/GrayCodeAI/graycode-skills/codeowners/errors
* @Patel230
4 changes: 2 additions & 2 deletions .github/ISSUE_TEMPLATE/bug-report.yml
Original file line number Diff line number Diff line change
Expand Up @@ -33,9 +33,9 @@ body:
id: environment
attributes:
label: Environment
description: "Autohand version, OS, and any relevant context"
description: "Rho (or other client) version, OS, and any relevant context"
placeholder: |
- Autohand version: 1.x.x
- Rho version: output of `rho version`
- OS: macOS 15
validations:
required: false
18 changes: 9 additions & 9 deletions .github/ISSUE_TEMPLATE/config.yml
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
blank_issues_enabled: false
contact_links:
- name: Browse Existing Skills
url: https://skilled.autohand.ai
about: Search and browse all community skills before submitting
- name: Submit via Web
url: https://skilled.autohand.ai/submit
about: Use the guided web form to submit a skill
- name: Discord Community
url: https://discord.gg/MWTNudaj8E
about: Ask questions and get help from the community
- name: Browse existing skills
url: https://github.com/GrayCodeAI/graycode-skills/tree/main/categories
about: Browse the categories (or run `rho skills search <topic>`) before proposing a skill
- name: Contribution guide
url: https://github.com/GrayCodeAI/graycode-skills/blob/main/CONTRIBUTING.md
about: How to submit a skill as a pull request
- name: Security reports
url: https://github.com/GrayCodeAI/graycode-skills/blob/main/SECURITY.md
about: Report vulnerabilities privately; do not open a public issue
10 changes: 5 additions & 5 deletions .github/ISSUE_TEMPLATE/new-skill.yml
Original file line number Diff line number Diff line change
@@ -1,15 +1,15 @@
name: Submit a New Skill
description: Propose a new community skill for the Autohand registry
description: Propose a new community skill for GrayCode Skills
title: "[New Skill]: "
labels: ["new-skill", "triage"]
assignees: []
body:
- type: markdown
attributes:
value: |
Thanks for contributing a new skill to the Autohand community! Please fill out the details below.
Thanks for contributing a new skill to GrayCode Skills! Please fill out the details below.

Before submitting, please check [existing skills](https://skilled.autohand.ai) to make sure your skill doesn't duplicate one that already exists.
Before submitting, search the existing skills (`rho skills search <topic>`, or browse [`categories/`](https://github.com/GrayCodeAI/graycode-skills/tree/main/categories)) to make sure your skill doesn't duplicate one that already exists.

- type: input
id: skill-name
Expand Down Expand Up @@ -117,7 +117,7 @@ body:
id: license
attributes:
label: License
description: "License for your skill (must be an OSI-approved license)"
description: "License for your skill: a permissive OSI-approved license such as MIT or Apache-2.0 (copyleft GPL/LGPL/AGPL is not accepted, see NOTICE)"
placeholder: MIT
validations:
required: true
Expand Down Expand Up @@ -146,4 +146,4 @@ body:
---
**What happens next?**

A maintainer will review your submission. If approved, we'll create the skill directory, add it to `registry.json`, and credit you as the author. You can also submit a PR directly — see [CONTRIBUTING.md](../CONTRIBUTING.md).
A maintainer will review your submission. If approved, we'll create the skill directory and record you as the author; `registry.json` is generated from it automatically. You can also submit a PR directly — see [CONTRIBUTING.md](../CONTRIBUTING.md).
53 changes: 46 additions & 7 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -35,14 +35,40 @@ jobs:
env:
BASE_REF: ${{ github.event.pull_request.base.sha || github.event.before }}
run: |
changed="$(git diff --name-only "$BASE_REF" HEAD)"
python3 tools/check_changed_scripts.py $changed
# github.event.before is all zeros for a new branch or a force-push,
# and may be missing from history; fall back to the parent commit.
if [ -z "$BASE_REF" ] || ! git cat-file -e "${BASE_REF}^{commit}" 2>/dev/null; then
BASE_REF="$(git rev-parse HEAD~1)"
fi
mapfile -t changed < <(git diff --name-only "$BASE_REF" HEAD)
python3 tools/check_changed_scripts.py "${changed[@]}"
- name: Validate all skills
run: >-
python3 tools/validate_skill.py --all
--warning-budget tools/validation_warning_budget.json
- name: Registry drift check
run: python3 tools/update_registry.py --check
- name: Registry build (schema and duplicate-name check)
# registry.json is generated, not committed, so there is no drift to
# detect here. Building it fails on duplicate skill names and on any
# entry that violates tools/registry_schema.py.
run: python3 tools/update_registry.py
- name: Version sync check
run: python3 tools/check_version_sync.py
- name: Marketplace sync check
# Fail if .claude-plugin/marketplace.json is stale vs categories/.
# Regenerate with: python3 tools/sync_marketplace.py
run: python3 tools/sync_marketplace.py --check
- name: Reference integrity
run: python3 tools/check_references.py
- name: Self-containment check
run: python3 tools/check_self_contained.py
- name: License compatibility gate
# Copyleft (GPL/LGPL/AGPL) content must not be vendored into the
# MIT-rooted repo, in LICENSE files or frontmatter. See NOTICE.
run: python3 tools/check_licenses.py
- name: Agent Skills conformance (first-party skills)
# GrayCode's own skills must follow agentskills.io exactly; the
# legacy corpus gap is reported by --all (see docs/AGENT_SKILLS.md).
run: python3 tools/check_agentskills.py --strict categories/graycode
- name: Run tests
run: python -m pytest tests/ -v --cov --cov-report=term-missing --cov-fail-under=88
- name: Packaging smoke check
Expand Down Expand Up @@ -94,8 +120,12 @@ jobs:
env:
BASE_REF: ${{ github.event.pull_request.base.sha || github.event.before }}
run: |
changed="$(git diff --name-only "$BASE_REF" HEAD)"
python3 tools/sandbox_run_changed_scripts.py --image graycode-skills-sandbox:ci $changed
# Same zero-SHA / force-push guard as the validate job.
if [ -z "$BASE_REF" ] || ! git cat-file -e "${BASE_REF}^{commit}" 2>/dev/null; then
BASE_REF="$(git rev-parse HEAD~1)"
fi
mapfile -t changed < <(git diff --name-only "$BASE_REF" HEAD)
python3 tools/sandbox_run_changed_scripts.py --image graycode-skills-sandbox:ci "${changed[@]}"

# -------------------------------------------------------------------------
# Duplication detection — jscpd (scan categories with reasonable thresholds).
Expand All @@ -109,6 +139,15 @@ jobs:
with:
node-version: '20'
- name: jscpd
# An enforced ceiling. This step used to pipe into `tail` without
# pipefail, so `--threshold 5` never failed the job: main reported
# "found too many duplicates (9.3%) over threshold (5.0%)" and still
# passed. jscpd 5.3.2 measures 11.4% duplicated lines on 2026-09-27,
# mostly in ingested prompt collections. Lower the ceiling as
# duplication is removed; never raise it. The version is pinned
# because percentages differ between jscpd releases.
shell: bash
run: |
npx jscpd --min-lines 15 --min-tokens 150 --threshold 5 --reporters console \
set -o pipefail
npx --yes jscpd@5.3.2 --min-lines 15 --min-tokens 150 --threshold 12 --reporters console \
--ignore "docs/**,plans/**,tools/**" . 2>&1 | tail -30
20 changes: 20 additions & 0 deletions .github/workflows/docker.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,9 +8,13 @@ on:
branches: [main]
paths:
- "Dockerfile"
- ".dockerignore"
- "categories/**"
- "tools/**"
- "pyproject.toml"
- "manifest-schema.toml"
- "VERSION"
- ".github/workflows/docker.yml"

permissions:
contents: read
Expand Down Expand Up @@ -49,6 +53,22 @@ jobs:
type=semver,pattern={{major}}.{{minor}}
type=sha,prefix=sha-

- name: Build image for the smoke test
uses: docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v7.2.0
with:
context: .
load: true
push: false
tags: graycode-skills:smoke
cache-from: type=gha
cache-to: type=gha,mode=max

- name: Smoke test the default command
# The image's CMD is the full-corpus zero-warning gate; it must pass
# as shipped (it previously validated the repo root and always
# exited 1).
run: docker run --rm graycode-skills:smoke

- name: Build and push
uses: docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v7.2.0
with:
Expand Down
69 changes: 0 additions & 69 deletions .github/workflows/validate-skills.yml

This file was deleted.

3 changes: 3 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -65,3 +65,6 @@ registry.json
# `gitnexus analyze` regenerates a root CLAUDE.md that would shadow AGENTS.md
# for tools that prefer it; keep the regenerated copy out of git.
/CLAUDE.md

# GitNexus code-intelligence index (regenerated locally; see AGENTS.md).
/.gitnexus/
Loading
Loading