# Gcw

> Analyze, reproduce, recover, and creatively adapt authorized public websites through a staged, evidence-driven workflow. Use for GCW, website teardown or cloning, faithful baselines, design-DNA extraction, WebGL/Canvas/shader reverse engineering, source-loss recovery, route reconstruction, and source-versus-local visual regression.

- Skill: `idonafraid-create/gcw` (Agent Skill, multi-file: 10 files)
- Install (CLI): `npx skillmds@latest add idonafraid-create/gcw`
- Raw SKILL.md: https://api.skillmd.com/api/skills/idonafraid-create/gcw/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Productivity
- Author: idonafraid-create (https://skillmd.com/u/idonafraid-create)
- Updated: 2026-09-22
- Page: https://skillmd.com/skills/idonafraid-create/gcw

---


# GCW — Gao Copy Website

Find evidence before implementation. Make it run before refactoring. Compare before polishing.

## Boundaries

- Proceed only for user-owned, licensed, or explicitly authorized targets. Ask when authorization is ambiguous.
- Exclude private/authenticated content unless explicitly authorized. Never bypass access controls or handle credentials.
- Check code, font, image, model, and brand rights separately. Label claims `SOURCE`, `PARTIAL`, or `GUESS`.
- Treat deployed bundles as evidence, not original authoring source.
- Treat this skill as the workflow authority when the user explicitly selects GCW. A question about an adjacent skill is not an instruction to invoke it. Do not add or substitute skills unless this file requires them or the user explicitly requests them.
- `design-dna` is mandatory for every teardown. `web-shader-extractor` is additionally mandatory when evidence detects Canvas, WebGL, WebGPU, or shaders. No other design, URL-to-code, or image-to-code skill satisfies either companion gate.

## 1. Route the workflow visibly

Read `references/clone-modes.md`. Show this preflight before using tools:

```markdown
- Outcome:
- Final deliverable:
- Editability target:
- Current phase:
- Site type:
- Ownership/authorization:
- Source availability:
- Baseline scope:
- Implementation path:
- Approximate or excluded scope:
```

Before every build-type reconstruction, ask the ordinary user to choose exactly one final delivery contract; never infer or default it from a user profile:

- A: research/runnable replay only (`RESEARCH_OR_RUNNABLE_REPLAY`, `RUNNABLE_REPLAY`).
- B: editable faithful clone (`EDITABLE_FAITHFUL_CLONE`, `MAINTAINABLE_SOURCE`).
- C: editable faithful clone, then Creative after review (`EDITABLE_FAITHFUL_CLONE_THEN_CREATIVE`, `MAINTAINABLE_SOURCE`).

Choice B is a durable accepted baseline, not a permanent opt-out from Creative. The user may explicitly upgrade B to C at `REVIEW_GATE` or later resume Creative from a completed B delivery. Ask one additional path-changing question when intent or ownership is unclear. Use the single flow `TEARDOWN_PHASE -> FAITHFUL_CLONE -> REVIEW_GATE -> CREATIVE_REBUILD`. A teardown-only outcome stops after the first phase. Editability for B/C is a `FAITHFUL_CLONE` requirement; `CREATIVE_REBUILD` only performs approved post-review content, brand, and feature innovation. Never silently expand scope.

Choose the faithful implementation path from evidence: `SOURCE_ADAPT`, `CLEAN_REBUILD`, or `PRODUCTION_RECOVERY`. Enable recovery only when the user confirms ownership/authorization and maintainable source is unavailable.

## 2. Establish the specification

Read workspace agent instructions (`AGENTS.md` or `CLAUDE.md`), if present. Let `<skill-root>` mean the directory containing this SKILL.md, then initialize without overwriting evidence:

```text
python <skill-root>/scripts/init_reconstruction.py <workspace> --url <canonical-url> --authorization <owned|licensed|authorized>
```

For build work, also pass the recorded choice with `--final-deliverable A|B|C` and a matching `--outcome`. The initializer refuses build work without that explicit contract. Teardown-only initialization may omit it.

Choose `--teardown-depth minimal` only for a simple non-GPU page: it uses a four-section SITE_SPEC but still requires Design DNA. `standard` is the default complete 12-section teardown. Use `deep` for complex rendering or recovery evidence; GPU targets cannot use `minimal`.

Read `references/site-spec.md`. Create `.gcw/SITE_SPEC.md` as a draft; do not finalize it until teardown evidence and required companion-skill results have been integrated. Mark absent capabilities `N/A`. Represent every implementation-critical conclusion in the section 9 subsystem table with fidelity and truth labels; never hide differences behind one percentage.

For a URL-only `CLEAN_REBUILD`, do not create or modify candidate implementation source before `finalize_teardown.py` passes. Capture the full public runtime first: desktop/mobile geometry, decoded assets and fonts, critical interactions, stable loading states, and every required companion result. Existing candidate code does not waive this gate; quarantine it until teardown is final.

## 3. Gather real evidence

Search official repositories, source maps, framework metadata, and public deployment evidence first. Verify licenses. Keep source, deployed artifacts, and editable implementation separate. GCW rejects credential-bearing URLs and document redirects outside the configured origin.

Run inventory where Playwright is available:

```text
node <skill-root>/scripts/site_inventory.mjs --url <canonical-url> --out <workspace>/.gcw/evidence/site-inventory.json
```

This command also writes `.gcw/evidence/route-map.json`, `.gcw/evidence/network/requests.json`, and `.gcw/evidence/source-maps.json`. Source-map evidence records response-header or comment directives, conventional `.map` probes, redacted URLs, bounded body size, and whether the response is a valid Source Map v3 object. HTTP reachability alone does not count as an accessible Source Map. The default body limit is 20 MiB; override it explicitly with `--source-map-max-bytes` when authorized evidence requires more.

Generate a narrow interaction-state draft where Playwright is available:

```text
node <skill-root>/scripts/detect_interaction_states.mjs --url <canonical-url> --out <workspace>/.gcw/evidence/interaction-states.json
```

The detector records observed `:hover`, `:focus`/`:focus-visible`, and common `aria-expanded` toggles with before/after screenshots. Its output is deliberately `reviewStatus: pending`: remove false positives, add important script-driven states it cannot discover, then set `reviewStatus` to `confirmed`. Finalization rejects an unreviewed generated draft.

Verify routes, breakpoints, DOM roots, overlays, scroll containers, input states, loading/stable states, GPU/media/workers/iframes, and external data manually. Cross-origin CSS, pseudo-element-only changes, canvas state, and multi-step interactions remain manual discovery scope.

Before using a source screenshot as a baseline, prove readiness and repeat the capture. If repeated captures differ, fix readiness/seed/time controls or classify the phase-sensitive region and compare it separately. Never build against a loading, decoding, lazy, or transitional frame merely because it is the first screenshot available.

During every `TEARDOWN_PHASE`, invoke `design-dna` and preserve its complete JSON at `.gcw/evidence/design-dna/design-dna.json`, including minimal teardown and study-only work. Summarize implementation-critical findings in `SITE_SPEC.md`; do not copy the sibling schema into a second GCW document. If `design-dna` is unavailable, stop and tell the user what must be installed; do not substitute an unstructured guess.

If Canvas, WebGL, WebGPU, or shaders are detected, also invoke `web-shader-extractor`. Preserve its native artifacts under `.gcw/evidence/web-shader-extractor/` and reach `TARGET_LOCKED` plus `REPLAY_READY`; teardown does not require Raw Replay or QA Report. If the required companion is unavailable, stop before finalization. When reconnaissance confirms no qualifying GPU surface, set `gpu-decision.json` to `not-applicable` and reference the supporting inventory evidence.

Only after these decisions and calls are complete, integrate their results into `SITE_SPEC.md`, remove every `REQUIRED` placeholder, then run:

```text
python <skill-root>/scripts/finalize_teardown.py <workspace>
```

The finalizer validates companion artifacts, updates `teardown-manifest.json` and `evidence-index.json`, and marks SITE_SPEC final. Apply the same contract when teardown is the final outcome; study-only work changes the stopping point, not teardown depth.

## 4. Build the scoped faithful baseline

Restore only agreed pages, components, and states. Preserve deep links and responsive behavior. Replace unavailable services with explicit fixtures. Verify production build and preview, then run route checks:

```text
python <skill-root>/scripts/route_smoke.py --base-url <preview-url> --route / --route /example
```

SPA HAR fixtures are explicit opt-in. Set a narrow `harFixture.urlFilter` in the reviewed capture config, add third-party API origins to `harFixture.rebaseOrigins` when needed, then record and replay per-scenario fixtures:

```text
node <skill-root>/scripts/capture_compare.mjs --config <capture-scenarios.json> --output <record-results> --record-har <har-dir>
node <skill-root>/scripts/capture_compare.mjs --config <offline-capture-scenarios.json> --output <replay-results> --replay-har <har-dir>
```

Recording strips credential headers/cookies, redacts sensitive query/body fields, and rebases captured service origins to the candidate origin before persisting each HAR. Replay blocks Service Workers, serves HAR matches first, blocks non-local misses, and records fallbacks/blocked requests in `capture-manifest.json`. For a fully offline fixture check, point both replay URLs at the local candidate preview and verify no candidate-side API path appears in `harFixtures.fallbacks`.

For asset-heavy or offline work, read `references/asset-provenance.md` and generate a non-overwriting draft from inventory:

```text
python <skill-root>/scripts/generate_asset_manifest.py <workspace>/.gcw/evidence/site-inventory.json --out <workspace>/.gcw/asset-manifest.json
```

The generator classifies and deduplicates static resources, proposes deterministic local paths, excludes API noise, and redacts unsafe URLs. It writes `reviewStatus: pending`; confirm reuse rights, purpose, attribution, scope, and paths before changing the status to `confirmed` and running `download_assets.py`. It never downloads or overwrites an existing manifest.

For final maintainable-source and creative builds, read `references/runtime-independence.md`. Recovery configuration instead reads `references/recovery-tiers.md` and `references/gates.md` and adds provenance, hashes, replay strategy, route/deploy continuity, Known Gaps, and maintained CI. Use `MAINTAINABLE_REBUILD` for a recovered maintainable implementation; `EDITABLE_REBUILD` is a migrated legacy alias only.

For B/C, `ARTIFACT_REPLAY` may be built first as an independent oracle but cannot be the final candidate. Before formal review, complete `.gcw/editability-evidence.json` and `.gcw/REPLACE_GUIDE.md`. Prove a maintainable source entrypoint, one controlled content change without editing deployed bundles, and runtime independence. A production-artifact-only replay cannot pass the delivery gate.

## 5. Verify matched states

Read `references/qa-scenarios.md` and `references/tooling.md`:

```text
node <skill-root>/scripts/capture_compare.mjs --config <capture-scenarios.json> --output <results-dir>
python <skill-root>/scripts/batch_image_diff.py <results-dir> --diff-dir <results-dir>/diff
```

Match viewport, DPR, route, pointer, scroll, seed, readiness, and time phase. Inspect screenshots and Diff images. Complete `CLONE_REPORT.md` with the delivery contract, subsystem fidelity, editability evidence when required, and Known Gaps. Leave a local `faithful-baseline` checkpoint only when the user permits commits.

Before entering `REVIEW_GATE`, complete `.gcw/quality-gate.json`. It must confirm a stable source baseline, passed desktop/mobile/key-state verification, and no open P0/P1/P2 issue. A failed visual or interaction gate keeps the task in `FAITHFUL_CLONE`: continue fixing unless the user explicitly pauses or terminates the work. A status report by itself is not a stopping condition.

For large or multi-session work, read `references/continuity.md`. Keep one compact `.gcw/PROGRESS.md`, validate persisted state before review/resume/handoff, and use only user-authorized local Git checkpoints. Do not create per-tweak reports or automatic commits.

## 6. Stop at REVIEW_GATE

Present the baseline, preview, screenshots, Diff, `CLONE_REPORT.md`, and Known Gaps. Do not begin creative changes until the user chooses:

- A: fidelity insufficient; return to `FAITHFUL_CLONE`.
- B: baseline accepted; stop.
- C: baseline accepted for innovation; create `.gcw/CREATIVE_BRIEF.md`, then enter `CREATIVE_REBUILD`.

Use `scripts/advance_workflow.py` to record transitions. Entering `REVIEW_GATE` requires a completed `CLONE_REPORT.md`; B/C additionally require confirmed editability evidence and reject final strategy `ARTIFACT_REPLAY`. Leaving the gate revalidates the delivery contract, requires `--decision A|B|C`, and the selected destination must match the list above. Decision C may upgrade an accepted B baseline to C and requires a completed `CREATIVE_BRIEF.md`; the script never creates or fills that proof itself. After a B delivery reaches `COMPLETE`, the user may later resume with `--to CREATIVE_REBUILD --decision C`; this revalidates the accepted B decision and editability evidence before upgrading the persisted contract. Choice A cannot use this path. The script refuses to leave teardown until `finalize_teardown.py` has passed.

## 7. Close out honestly

Re-run promised QA, report skipped checks, and distinguish observed behavior, licensed reuse, and original implementation. Remove tracking and original-brand residue before publishing an adaptation. Never push, tag, release, or deploy without user authorization.

