mirror of
https://github.com/shipshitdev/skills.git
synced 2026-09-19 06:04:15 +08:00
9a403e230c
* feat!: consolidate test/scan/env/prompt/performance commands behind skills - merge /tests into /test run (scope tokens forwarded; /tests retired) - retire /performance; /refactor perf is the sole performance front door - rewire /scan as a thin security front door (security-audit + dependency-audit) - add env-setup skill; /env becomes a thin router to it - move the Lyra 4-D framework into prompt-engineering references; /prompt goes thin - document intentional command shortcuts (/qa, /deslop, PR-flow trio) in README - regenerate bundles + marketplace (185 skills, 30 commands, 198 plugins) * fix(test-dispatch,env-setup): correct router contract and env discovery scan Three CodeRabbit findings on #127, all verified against the source before fixing. test-dispatch understated what it routes into. Its Creates/Modifies claimed the router mutates "nothing directly" and its Confirmation Required listed only e2e/coverage/init as mutating — but `run` delegates to test-runner, whose auto-fix loop edits the code under test and its tests until green. A reader picking a route from the contract would have believed `/test run` was safe. The fix corrects the documentation rather than adding a gate: test-runner's unprompted edit of the file under test IS `/test run`, and `--no-fix` is the existing, designed way to ask for a report with no edits. Bolting a blanket confirmation onto the auto-fix loop would contradict both. The contract now names which routes mutate, and points at `--no-fix` instead of a gate test-runner does not have. env-setup's discovery command had a filter that silently filtered nothing: `grep -oh` prints only the matched text with the filename suppressed, so the downstream `grep -v node_modules` had no path to match against and dependency hits stayed in the inventory. Exclusion is now directory-scoped (`--exclude-dir`), the pattern also covers bracket access (`process.env["X"]`), and the surrounding prose states what the scan cannot see — helper functions, destructures, dynamic keys, and non-JS services in the same repo — so the output reads as a starting inventory, not an answer. `/test run unit | integration | e2e` sat inside a bash fence, where copy-paste runs a pipeline instead of picking a scope. Split into three commands in both the skill and commands/test.md. Verified: validate-changed-skills 0 errors/0 warnings, markdownlint 0 issues, biome clean, catalog regenerated to 186 skills / 199 plugins. The discovery grep was run against this repo and returns real variable names.