跳到正文

ooocooc

open-skill-sunset

Audit and safely retire stale generic AI agent instructions.

README 已保存到本站,可直接阅读

Documentation snapshot

README 快照

本页保存的是公开项目资料快照,阅读过程不需要连接 GitHub。

Skill Sunset

图片:CI 图片:npm version 图片:npm downloads 图片:license

English | 简体中文

Your AI evolved. Did your rules?

Audit accumulated AGENTS.md, CLAUDE.md, and generic SKILL.md instructions before stale workarounds keep consuming context.

npx skill-sunset@latest audit --codex --open

No global installation is required. The audit is local and read-only; the core does not call an AI API, consume model quota, or read provider credentials.

图片:Animated walkthrough of a real Skill Sunset report generated from the repository test fixture

The animation pans through a real report generated by the current CLI from test/fixtures/sample-setup: 5 files scanned, 11 findings, with duplicate retirement, stale-reference updates, progressive disclosure, and behavior hypotheses shown separately.

What it does

Skill Sunset combines deterministic checks with conservative review hypotheses:

  • finds broken local references, stale absolute paths, malformed Skill frontmatter, oversized always-loaded files, and possible plaintext credentials;
  • detects same-name Skills and verifies the complete bundle before recommending recoverable retirement;
  • marks model-era compensation rules as TEST instead of claiming they are obsolete;
  • produces bilingual HTML, Markdown, JSON, Codex/Claude handoff prompts, an experiment template, and a rollback manifest;
  • excludes domain knowledge, safety rules, authorization gates, and project invariants from automatic retirement.

No finding authorizes deletion. TEST means “evaluate this hypothesis,” not “a newer model made this rule unnecessary.”

Supported environments

AreaSupported and verified
Operating systemsUbuntu, macOS, and Windows in GitHub Actions
Node.js20, 22, and 24
Preset targetsCodex (~/.codex) and Claude Code (~/.claude)
Instruction filesAGENTS.md, CLAUDE.md, and SKILL.md
Agent handoffCodex and Claude Code prompt artifacts
Other setupsAny bounded directory passed explicitly to audit

Other Linux distributions are expected to work with Node.js 20+, but are not part of the current CI matrix.

Quick start

Scan Codex configuration:

npx skill-sunset@latest audit --codex --open

Scan Claude Code configuration:

npx skill-sunset@latest audit --claude --open

Scan any bounded directory and keep CI-friendly JSON output:

npx skill-sunset@latest audit /path/to/setup --format json --fail-on high

The CLI defaults to --lang auto. Use --lang en or --lang zh-CN to select the primary report language. Every bundle still contains portable English and Simplified Chinese HTML pages.

Complete example: input → finding → validation → rollback

Suppose AGENTS.md contains:

Always use Context7 for every task.
Deployment runbook

and docs/deploy.md does not exist.

  1. Input and snapshot. Keep a recoverable copy, then audit the directory.

    cp AGENTS.md AGENTS.md.skill-sunset.bak
    npx skill-sunset@latest audit . --out .skill-sunset --open
  2. Findings. The report can produce:

    • UPDATE / broken-reference: the runbook target cannot be resolved;
    • UPDATE / context7-assumption: current tool availability needs verification;
    • TEST / unconditional-tooling: “for every task” needs representative old-versus-new evaluation.
  3. Change and validate. Verify the real runbook path and current tool list first. Change only the confirmed stale reference; make unconditional tooling a separate candidate. Re-run the audit and the project tests:

    npx skill-sunset@latest audit . --out .skill-sunset --format json
    npm test

    For a TEST item, fill .skill-sunset/experiment-template.json. Validation runs no commands:

    npx skill-sunset@latest test .skill-sunset/experiment-template.json --root .

    Execution requires a separate --run. A passing experiment proves only its encoded acceptance criteria.

  4. Rollback. If references, tests, or task behavior regress, restore the saved file and re-run the audit:

    cp AGENTS.md.skill-sunset.bak AGENTS.md
    npx skill-sunset@latest audit . --out .skill-sunset

    The generated rollback-manifest.json is intentionally empty until an authorized execution agent records actual changes and hashes.

Report bundle

.skill-sunset/
├── index.html
├── index.en.html
├── index.zh-CN.html
├── audit-report.md
├── audit.json
├── execution-prompt-codex.md
├── execution-prompt-claude.md
├── eval-plan.md
├── experiment-template.json
└── rollback-manifest.json

Report contents redact targets below the user home as $HOME/...; other absolute targets are represented as $ABSOLUTE/. The terminal still prints the real local report location so the owner can open it.

Verdicts

  • MERGE: exact duplicates or conflicting same-name Skills.
  • UPDATE: stale paths, references, tools, or version-coupled instructions.
  • DEMOTE: useful always-loaded detail that belongs in progressive disclosure.
  • RETIRE: byte-identical complete generic Skill bundles with the same name inside one scan root; only recoverable archival is recommended.
  • TEST: an obsolescence hypothesis requiring old-versus-new behavioral evaluation before cleanup.

Behavioral experiment safety

Experiment manifests are validation-only unless --run is explicit. Commands run without a shell and receive a minimal non-secret environment allowlist by default. Full environment inheritance—including possible provider credentials—requires the additional --inherit-env flag and trusted commands.

Dry runs and result files retain executable names, argument counts, command hashes, output sizes, and output hashes instead of command arguments or output bodies. Never put credentials in an experiment manifest.

Local development

npm test
npm pack --dry-run
node ./bin/skill-sunset.js audit ./test/fixtures/sample-setup --out ./demo-report --open

GitHub Actions runs Gitleaks plus the full operating-system and Node.js matrix. Gitleaks is a publication guard, not proof that every possible credential format can be recognized.

See CHANGELOG.md, CONTRIBUTING.md, and SECURITY.md.

Maintenance

  • Source maintainer: @ooocooc
  • npm publisher: ooocoo
  • Bugs and feature requests: GitHub Issues
  • Contributions: CONTRIBUTING.md
  • Security reports: SECURITY.md
  • Release history: CHANGELOG.md

The project is maintained on a best-effort basis without a guaranteed response SLA.

Current boundary

Version 0.2.0 implements static checks, conservative duplicate retirement, localized reports, path redaction, a gated command experiment harness, CI severity exits, and adversarial output tests. Current-provider capability snapshots, session-usage adapters, and task-quality adapters remain future evidence layers.

Official distribution

获取与安装

以下地址来自本站保存的 README,并指向对应生态的官方软件包页面。本站不托管安装包或二进制文件。

安装前请在官方包页核对包名、维护者、版本和签名;具体命令以该项目 README 与官方文档为准。

使用前核验

本站保存公开资料用于阅读,不代表安全审计或功能背书。安装前请核对许可证、依赖来源和发布签名,不要直接运行来源不明的二进制文件或高权限脚本。