Standards — focused engineering guidance
Load the smallest set of standards justified by the caller's files, language,
and risks. Do not preload the entire reference corpus.
Prompt
Check standards for the changed files in fleet-router PR #214: cli/internal/auth/token.go and cli/internal/auth/token_test.go, Go, a security-sensitive change. Load only the matching references and report cited findings with path and line plus checked and not-checked scope.
It's working if
- The report loads
common-standards.md plus only the matching Go reference, never the full reference corpus.
- Every finding cites a path and line, e.g.
cli/internal/auth/token.go:18.
- The response discloses
checked and not_checked scope explicitly, even when not_checked is empty.
git diff --stat shows no test, gate, or fixture file changed; standards reports findings only.
Procedure
- Record the supplied paths, language, change type, and risk cues.
- Load
common-standards.md plus only the matching language or checklist
references.
- Compare the supplied artifact to those sources.
- Return cited findings with path and line when possible, plus checked and
not-checked scope.
- Stop.
This skill provides context and findings. It does not edit, validate, retry,
approve, commit, release, deliver, or decide continuation.
Load-bearing conventions for produced code (MEASURED)
When the caller is about to WRITE code (not only review it), surface the
matching language rules INLINE in the working context — a behind-the-link
reference does not change behavior; an inline imperative does. The Go core:
- Wrap every propagated error with context:
fmt.Errorf("doing X: %w", err)
— never return a bare inner error.
- Multi-case functions get TABLE-DRIVEN tests (
[]struct cases + t.Run per
case), asserting exact expected values including the error cases.
For other languages, pull the matching reference below and inline its top
rules the same way.
Measured 2026-08-04, probe standards-go-conventions (gpt-5.6-luna, N=2,
directional): control produced the %w-wrapped + table-driven shape in 1/2
runs; with these rules inline, 2/2. Inline-imperative beats reference-link —
the graphify probe measured a linked doc instruction obeyed 0/2. Ledger:
evals/skill-probes/LEDGER.md.
Mutation-safety standards
When the supplied change rewrites existing files in bulk — formatters,
codemods, migration scripts, generators pointed at hand-written sources —
check it against three standards and report each as a finding when absent:
- Single audited mutation chokepoint. All rewrites flow through one named
command or script whose inputs, outputs, and dry-run mode can be inspected.
Edits scattered across ad-hoc one-liners and manual touch-ups are the
diffuse mutation failure mode: no single point can be audited, re-run,
or blamed. Finding: name every mutation path outside the chokepoint.
- Hash-witnessed backups before rewrite. Before the chokepoint runs, the
originals are preserved with content hashes recorded (a committed baseline
counts), so "the rewrite changed only what it claims" is checkable
byte-for-byte, not asserted. Finding: a bulk rewrite with no verifiable
before-state.
- Self-administered ambition gate. The change states what it deliberately
does not touch, and the diff respects it. A formatter run that also renames,
a codemod that also refactors, is the scope-creep rewrite failure mode.
Finding: any file class in the diff outside the change's own stated scope.
Stop condition for this check: all three standards have an explicit pass or
finding; a bulk-rewrite review that reports style nits but skips these is
incomplete.
References
- Common standards
- Go
- Python
- Rust
- TypeScript
- JavaScript
- Shell
- JSON
- YAML
- Markdown
- SQL safety
- Race conditions
- LLM trust boundaries
- Skill structure
- Test strategy
1---2name: standards3description: Load only the standards relevant to a caller-supplied change, then report concrete findings. Triggers: "check standards", "which standards apply".4---5# Standards — focused engineering guidance
6
7Load the smallest set of standards justified by the caller's files, language,
8and risks. Do not preload the entire reference corpus.
9
10## Prompt
11
12```text
13Check standards for the changed files in fleet-router PR #214: cli/internal/auth/token.go and cli/internal/auth/token_test.go, Go, a security-sensitive change. Load only the matching references and report cited findings with path and line plus checked and not-checked scope.
14```
15
16## It's working if
17
18- The report loads `common-standards.md` plus only the matching Go reference, never the full reference corpus.
19- Every finding cites a path and line, e.g. `cli/internal/auth/token.go:18`.
20- The response discloses `checked` and `not_checked` scope explicitly, even when `not_checked` is empty.
21- `git diff --stat` shows no test, gate, or fixture file changed; standards reports findings only.
22
23## Procedure
24
251. Record the supplied paths, language, change type, and risk cues.
262. Load `common-standards.md` plus only the matching language or checklist
27 references.
283. Compare the supplied artifact to those sources.
294. Return cited findings with path and line when possible, plus checked and
30 not-checked scope.
315. Stop.
32
33This skill provides context and findings. It does not edit, validate, retry,
34approve, commit, release, deliver, or decide continuation.
35
36## Load-bearing conventions for produced code (MEASURED)
37
38When the caller is about to WRITE code (not only review it), surface the
39matching language rules INLINE in the working context — a behind-the-link
40reference does not change behavior; an inline imperative does. The Go core:
41
42- Wrap every propagated error with context: `fmt.Errorf("doing X: %w", err)`
43 — never return a bare inner error.
44- Multi-case functions get TABLE-DRIVEN tests (`[]struct` cases + `t.Run` per
45 case), asserting exact expected values including the error cases.
46
47For other languages, pull the matching reference below and inline its top
48rules the same way.
49
50> Measured 2026-08-04, probe `standards-go-conventions` (gpt-5.6-luna, N=2,
51> directional): control produced the `%w`-wrapped + table-driven shape in 1/2
52> runs; with these rules inline, 2/2. Inline-imperative beats reference-link —
53> the graphify probe measured a linked doc instruction obeyed 0/2. Ledger:
54> `evals/skill-probes/LEDGER.md`.
55
56## Mutation-safety standards
57
58When the supplied change rewrites existing files in bulk — formatters,
59codemods, migration scripts, generators pointed at hand-written sources —
60check it against three standards and report each as a finding when absent:
61
62- **Single audited mutation chokepoint.** All rewrites flow through one named
63 command or script whose inputs, outputs, and dry-run mode can be inspected.
64 Edits scattered across ad-hoc one-liners and manual touch-ups are the
65 **diffuse mutation** failure mode: no single point can be audited, re-run,
66 or blamed. Finding: name every mutation path outside the chokepoint.
67- **Hash-witnessed backups before rewrite.** Before the chokepoint runs, the
68 originals are preserved with content hashes recorded (a committed baseline
69 counts), so "the rewrite changed only what it claims" is checkable
70 byte-for-byte, not asserted. Finding: a bulk rewrite with no verifiable
71 before-state.
72- **Self-administered ambition gate.** The change states what it deliberately
73 does not touch, and the diff respects it. A formatter run that also renames,
74 a codemod that also refactors, is the **scope-creep rewrite** failure mode.
75 Finding: any file class in the diff outside the change's own stated scope.
76
77Stop condition for this check: all three standards have an explicit pass or
78finding; a bulk-rewrite review that reports style nits but skips these is
79incomplete.
80
81## References
82
83- [Common standards](references/common-standards.md)
84- [Go](references/go.md)
85- [Python](references/python.md)
86- [Rust](references/rust.md)
87- [TypeScript](references/typescript.md)
88- [JavaScript](references/javascript.md)
89- [Shell](references/shell.md)
90- [JSON](references/json.md)
91- [YAML](references/yaml.md)
92- [Markdown](references/markdown.md)
93- [SQL safety](references/sql-safety-checklist.md)
94- [Race conditions](references/race-condition-checklist.md)
95- [LLM trust boundaries](references/llm-trust-boundary-checklist.md)
96- [Skill structure](references/skill-structure.md)
97- [Test strategy](references/test-pyramid.md)