Ship a first-class OpenAI Codex plugin entry point. Mirrors the
existing Claude Code and Cursor plugin manifests and reuses the
shared ./skills/ directory - no skill duplication.
Manifest declares the spec-required interface block (displayName,
developerName, category, capabilities, logo, logoDark) and points
skills at the existing skills/ tree. The logo pair (Go cyan on
light, slate on dark) is a placeholder; the design is intentionally
neutral so a real brand mark can drop in without rework.
Version pins to 2.0.1 to match .claude-plugin/, .cursor-plugin/ and
gemini-extension.json - all four must stay in lockstep per CLAUDE.md
Plugin Configuration.
* docs: cap prose paragraphs at 3 sentences and clarify token budgets
CLAUDE.md constrained prose only at whole-file granularity, with three
conflicting per-SKILL.md token numbers and a "why" pattern that
tempted a second sentence per rule. Add a per-paragraph sentence cap,
a budget table clarifying which number measures what, and a mechanical
checker (scripts/check_prose_density.py) wired into the "After
updating a skill" checklist so verbose paragraphs get caught instead
of only whole-file token/line counts.
* docs: rewrite prose paragraphs over the new 3-sentence density cap
CLAUDE.md now caps standalone prose paragraphs at 3 sentences
(scripts/check_prose_density.py). Running it across every skill found
62 flagged paragraphs in 31 skills, dominated by a recurring
"library disclaimer" paragraph repeated near-verbatim across 17
library-specific skills. Restructure each flagged paragraph into
bullets, a table, or a tightened sentence per CLAUDE.md's Formats
guidance, preserving every fact, URL, and cross-reference. Re-scanning
the full repo now reports 0 flagged paragraphs across all skills.
Bump each touched skill's metadata.version by one patch version.
Update README token counts for the 31 touched skills to match.
* docs: drop the prose-density checker script
The script added mechanical enforcement but no CI wiring, so it never
ran anywhere but ad hoc. Keep the 3-sentence prose cap and the
clarified token-budget table in CLAUDE.md; drop the script and its
two call-outs, renumbering the "After updating a skill" checklist
back to a contiguous sequence.
* feat(golang-modernize): add Go 1.27 support, fix sibling skill drift
Go 1.27 shipped August 2026 and made several existing statements in
this plugin factually wrong, not just outdated - encoding/json/v2 is
now the default (was documented as experimental-only), the goroutine
leak profile is GA (was documented as GOEXPERIMENT-gated), and go
fix's modernizer suite changed. An agent loading these skills today
would give incorrect advice.
Rebased onto main, which had independently merged PR #98 (a smaller,
overlapping Go 1.27 pass on the same files). Reconciled rather than
overwritten: kept PR #98's stdlib-uuid/generic-methods/CutLast/
synctest-http evals (renumbered 20-23) alongside this branch's own,
folded its unique versions.md content (go fix modernizers, stdversion,
go mod tidy merge, small API preferences) into the merged Go 1.27
section, and corrected its json/v2 section, which claimed v1 behavior
is preserved while also stating v2 rejects duplicate keys - those two
claims contradict each other once v1 sits on top of v2 by default.
- golang-modernize: merged Go 1.27 section (generic methods with a
citation to the Go issue/spec after an eval showed models otherwise
distrust the claim, CutLast, URL/Values.Clone, math/big.Int.Divide,
stdlib uuid, json/v2 migration), a version-bump risk checklist for
changes that need verification rather than a rewrite (removed
GODEBUG keys, json/v2 strictness), stdversion workflow step, and
skill-library-version tracking so future drift gets caught by the
staleness check instead of by accident.
- 11 sibling skills (concurrency, troubleshooting, refactoring,
popular-libraries, performance, continuous-integration,
dependency-management, testing, benchmark, observability,
documentation): surgical corrections wherever Go 1.27 broke a prior
claim, plus additive Go 1.27 notes where directly relevant.
- evals.json: merged to 23 evals / 125 assertions (up from the 74 on
main before either PR) - this branch's evals plus PR #98's four,
renumbered to avoid ID collisions and kept rather than pruned as
redundant, since both authors' scenarios are independently useful.
- EVALUATIONS.md / README.md: single reconciled report replacing the
two competing v1.4.0 reports that resulted from the parallel work
(116/120 with, 65/120 without, +43pp pooled), a Total row recomputed
across all 41 skills, and a corrected TOC anchor. One eval's
without-skill condition could not be captured after five subagent
attempts and is reported as unmeasured rather than guessed.
* fix(golang-how-to): correct broken TOC anchor links from PR #100
markdownlint's MD051 rule strips emoji symbols when computing heading
slugs but keeps their variation selectors (U+FE0F), since those are
Unicode "Mark" characters, not "Symbol". The TOC entries assumed full
removal and linked to plain hyphenated anchors, so every heading
followed by ⭐️/⚙️ (both of which use a variation selector) produced a
link-fragment mismatch - failing lint repo-wide on every PR regardless
of what it touches, including this one.
Recomputed the correct URL-encoded anchors from markdownlint's own
slug algorithm and rewrote just the TOC hrefs; no visible text changed.
* docs: tighten skill description guidelines and fix overlap gaps
Description frontmatter is the only signal Claude Code reads before
deciding to load a skill, so under-specified triggers or missing
sibling boundaries directly cause mis-selection or silent skipping.
- add 8 description-writing rules to CLAUDE.md (ordering, point of
view, concrete nouns, pushy-but-scoped triggers, sibling scoping,
front-loading, no workflow narration, negative-clause siblings)
- add length-calibration guidance reserving long descriptions for
moment-triggered skills, distinct from topic-triggered ones
- retroactively apply the new rules to the 16 skills that violated
them: missing overlap disclaimers (golang-security, golang-safety,
golang-concurrency, golang-troubleshooting, golang-dependency-management,
golang-continuous-integration, golang-design-patterns, golang-modernize,
golang-project-layout, golang-popular-libraries, golang-lint,
golang-data-structures, golang-samber-mo), oversized descriptions
(golang-refactoring, golang-pkg-go-dev), and a too-abstract one
(golang-stay-updated)
* docs: add skill body writing style guidelines
Body content quality (voice, terminology, specificity, feedback
loops) was undocumented even though description quality already had
a dedicated section — leaving body-writing conventions to individual
judgment call by call.
- add a Body writing style section: imperative verb-first voice, one
term per concept, one default with an escape hatch, assume reader
competence, tables/checklists over prose, specificity matched to
fragility, copyable progress checklists, feedback loops over rule
enumeration
- fold the ALWAYS/NEVER-in-caps-as-a-smell refinement into the
existing Teach reasoning, not only rules section
- add the under-250-lines target and 147-line official median to
the existing Token budgets line-count bullet
* docs: apply new body writing style rules to 11 skill bodies
Retroactively applies CLAUDE.md's new Body writing style rules
(added earlier on this branch) after a read-only audit of all 46
active skill bodies flagged 10 real violations.
- add rationale to bare ALL-CAPS ALWAYS/NEVER items that weren't
actually order-dependent or destructive (golang-context,
golang-modernize, golang-samber-do, golang-project-layout,
golang-structs-interfaces, golang-testing, golang-troubleshooting)
- split oversized bodies into references/: golang-structs-interfaces
(386 -> 300 lines, new struct-fields.md and type-assertions.md)
and golang-testing (476 -> 417 lines, new benchmarks.md,
coverage.md, examples.md)
- trim golang-dependency-injection's duplicated 4-library comparison
down to a 2-way contrast, pointing to its existing reference files
for the rest
- merge golang-safety's two split Cross-References sections into one
- normalize the ASCII "->" arrow to "→" for consistency with the
rest of the repo (golang-samber-mo, golang-testing,
golang-concurrency)
* docs: add progressive disclosure guidance for skill bodies
The old Progressive disclosure section had a merge artifact (three
numbered items all labeled "Instructions" with three different,
overlapping token thresholds) and said nothing about why references
matter or how compaction and nested reads actually fail.
- reframe around the real asymmetry: body content is a recurring
per-turn cost, references/ is paid once and only if loaded
- fix the duplicate "Instructions" bullets by cross-referencing
Token budgets instead of restating three conflicting numbers
- document the nested-reference truncation failure mode (head -100
silently drops the deepest content) on the existing one-level-deep
rule in the Skill Body intro
- add the auto-compaction budget fact (~5,000 tokens survive per
skill, ~25,000 shared) and the table-of-contents-over-100-lines,
organize-by-domain, and explicit-load-pointer rules
* docs: add tables of contents to long reference files
CLAUDE.md's new progressive disclosure guidance requires a Table of
Contents on any reference file over 100 lines, so a partial read
(head -100, or truncation on a long file) still reveals the file's
full scope instead of silently hiding sections past the cutoff.
Generated mechanically for all 123 qualifying reference files (every
skills/*/references/*.md over 100 lines that didn't already have
one) with a one-off script: extract H2/H3 headings outside fenced
code blocks, build GitHub-compatible anchors, insert after the H1
title and intro paragraph. Idempotent - already-TOC'd files (the 4
golang-gopls reference files) were left untouched.
* docs: add bundling-scripts and security guidelines
Executable helpers and skill-level security had no dedicated home in
CLAUDE.md even though the plugin already ships scripts/ directories
and handles third-party library content that could carry injections.
- add a Bundling scripts section: when to bundle (deterministic,
repeated, or fragile operations), errors handled inside the
script, justified constants, forward-slash paths, explicit
dependencies, execute-vs-read framing, and plan -> validate ->
execute for batch or destructive work
- add a Security section anchored on the Principle of Lack of
Surprise: no credential handling or data exfiltration, no runtime
instruction-fetching, external content treated as data, allowed-
tools granting without prompting even in untrusted directories,
least-privilege tool scoping, and auditing bundled files (not just
SKILL.md) before installing a third-party skill
- cross-reference existing Snyk agent scanner compliance and
Library-specific skills sections instead of duplicating their
detailed patterns
* docs: add anti-patterns quick-reference table
A single lookup table naming every failure mode and pointing at the
section that owns the fix makes today's accumulated guidance
(description, body, progressive disclosure, scripts, security)
scannable in one pass instead of requiring a full read to recall
where a given rule lives.
- add the Anti-patterns table before Evaluation, cross-referencing
existing sections for rows already covered in full
- add net-new guidance where no existing rule covered the row:
version-relative facts over date-relative ones with a collapsed
<details> block for superseded patterns, forward slashes in body
examples (not just scripts), a verified frontmatter field-count
warning (confirmed against the Agent Skills spec: six fields -
name, description, license, compatibility, metadata, allowed-tools
- everything else is a harness extension), top-level version:
rejection, description YAML-quoting pitfalls, MCP tool name
server-qualification, allowed-tools as a pre-approval list rather
than a sandbox, @-mention force-loading of another skill, a
discovery-degradation ceiling around 20-50 installed skills, and
per-model eval validity
- add a short "facts in CLAUDE.md, procedures in skills" principle
to Project Overview, the CLAUDE.md-vs-skill counterpart to the
existing skill-vs-skill Atomic skills and deduplication rule
* fix: correct TOC anchor slugs and prettier/markdownlint findings
Running the documented lint pipeline (prettier, then
markdownlint-cli2) surfaced a real bug in the TOC-generation script
used earlier on this branch: its anchor slugger collapsed runs of
whitespace into a single hyphen and stripped inline emphasis markers
without excluding intraword underscores, producing anchors that did
not match GitHub's actual algorithm (each whitespace character maps
to its own hyphen, with no collapsing). This broke 306 link
fragments across 61 reference files whose headings contained an
em dash, ampersand, parentheses, or a snake_case identifier.
- fix the slugify algorithm and regenerate all 123 previously
generated TOCs; the fix is idempotent, so headings without special
punctuation are byte-identical to before
- fix two `MD038` violations in CLAUDE.md (` : ` code spans with
a trailing space) introduced by an earlier commit on this branch
- apply prettier's table-column alignment to two new reference files
(golang-testing/references/coverage.md, examples.md)
20 anchors across two files (golang-how-to/references/by-category.md,
project-config.md) remain flagged by markdownlint's MD051 rule for
headings containing emoji with variation selectors -- its own --fix
computes the identical anchor its checker then rejects, a stable
fixed point that is a markdownlint-cli2 limitation, not a defect in
the generated content (the heading text itself is unaffected; only
the anchor's exact string fails the linter's cross-check). Left as a
known limitation rather than chased further.
All other lint findings across the repository (515 total, MD022/
MD037/MD025/etc.) are pre-existing and outside every file this
branch touches -- confirmed by diffing the error file list against
this branch's changed-file list.
* chore: bump patch version on all 40 skills changed on this branch
* chore: bump plugin version to 2.0.1
* oops
Cross-reference samber/cc-skills@humanizer-en-asd-ste100 for projects
that need strict, controlled English prose (ASD-STE100) in their
documentation, on top of the existing writing principles.
Enables the GitHub "Cite this repository" button and gives Zenodo a
stable citation source instead of auto-generating one from the noisy
GitHub contributor list.
A few generic "the project's agent-config file" mentions in
golang-how-to and golang-project-layout kept the concrete examples
out, unlike the sibling mentions in the same files. Names CLAUDE.md
and AGENTS.md consistently everywhere, matching the pattern already
used at golang-how-to/SKILL.md:3,152 and golang-gopls/references/
settings.md:3.
* docs: fix remaining hardcoded tool/harness references found by a deep file-by-file audit
The mechanical grep-based pass in the previous commits only matched a
fixed set of phrases. A full read of every file in every skill
directory (not just SKILL.md, and not just grep) turned up a few
misses:
- golang-documentation (SKILL.md, references/code-comments.md,
references/library.md): named a specific MCP tool
(go-playground-mcp) as an instruction to call it, rather than
describing the capability.
- golang-how-to/SKILL.md: the native LSP tool was called "built-in"
without naming Claude Code, unlike golang-gopls's equivalent,
already-fixed section.
- golang-pkg-go-dev/SKILL.md: the MCP registration section presented
`claude mcp add` as the only path with no harness scoping.
- golang-refactoring/references/workflow.md: one Thinking mode line
(inside the Planning Gate section, not the top-of-body directive)
still used the old 'use `ultrathink` here' phrasing.
Everything else across all 46 skills — read in full, not grepped —
was already compliant.
* style: apply prettier formatting to straggler eval/asset files
These 8 files (7 evals.json, 1 .golangci.yml) had never been run
through prettier and had drifted from the rest of the repo's
formatting. Content is verified byte-for-byte semantically identical
(JSON parsed and compared, YAML diffed with comment lines excluded)
- whitespace/line-wrapping only, picked up incidentally while running
prettier on the directories touched by this audit.
Version bumps kept out of the content PRs (#91, #92, #93, #94) so
those stay reviewable on their own merits. This is a standalone
release marker: every skill moves to its next minor version, and the
plugin manifests (.claude-plugin, .cursor-plugin, gemini-extension)
move to 2.0.0 together.
* docs: broaden compatibility base string across all golang-* skills
Replace "Claude Code or similar AI coding agents" with "Claude Code,
Codex or similar harness" per the cross-harness portability rule in
CLAUDE.md, mirroring samber/cc-skills-golang#91.
* feat: scope Go-file skills with the paths frontmatter field
Adds the optional paths frontmatter field (documented in
samber/cc-skills-golang#91) to every skill whose subject matter is
Go source itself, so Cursor can sharpen triggering to **/*.go files.
Skills not tied to a file type (setup, CI, ecosystem-lookup,
orchestrator) are intentionally left without it.
golang-lint also scopes to .golangci.yml, since linter configuration
is as central to that skill as the Go source it lints.
* docs: drop hardcoded Agent-tool phrasing from skill body prose
Continues the cross-harness portability rule from
samber/cc-skills-golang#91 — sub-agent fan-out is a capability every
harness resolves its own way; naming Claude Code's Agent tool in body
prose is redundant on Claude Code and dead weight elsewhere.
* feat(golang-how-to): flatten Configure mode to 5 harnesses, fix Cursor bug
Configure mode previously wrote to CLAUDE.md, AGENTS.md,
.cursor/rules, and copilot-instructions.md with Claude Code framed as
the primary target. This flattens the harness list to equal standing
and adds GEMINI.md (Gemini CLI, Antigravity).
Fixes a real bug: .cursor/rules is a directory of .mdc files with
their own YAML frontmatter, not a single markdown file to grep and
append to. The old Step 2/4 logic assumed the latter and would not
have worked on Cursor. Adds a dedicated .mdc template
(assets/cursor-go-skills.mdc) and a Cursor-specific write path.
Also adds the new Questions top-of-body directive and drops the
remaining hardcoded AskUserQuestion/Glob/Edit tool names from
project-config.md and golang-project-layout's checklist, per the
cross-harness portability rule in samber/cc-skills-golang#91.
* docs(golang-continuous-integration): label CI review blocks as generated artifacts
Notes that the Claude Code and Copilot review blocks under
'AI-Driven Code Review' are generated artifacts targeting a CI
runner, not the developer's local harness — their literal tool names
and permission flags are intentional under the exemption in
samber/cc-skills-golang#91, so a future portability grep hit there
reads as expected rather than as a miss.
* docs: lead Thinking/Orchestration mode directives with universal instruction
Rewords the 8 Thinking mode and 12 Orchestration mode directives across
these skills to lead with the harness-neutral instruction ("Reason as
thoroughly as possible...", "Fan out N parallel sub-agents...") and
mention ultrathink/ultracode second, as the Claude Code-specific
accelerator rather than the instruction itself. Also drops the
remaining hardcoded "(via the Agent tool)"/"(Agent tool)" parentheticals
and EnterWorktree/ExitWorktree tool-name mentions from body prose in
favor of "an isolated worktree" — the tool stays declared in
allowed-tools, prose just describes the capability.
Mirrors the format adopted in samber/cc-skills-golang#91.
* docs: add Questions directive to golang-refactoring and golang-modernize
golang-refactoring gates several irreversible git operations behind
explicit sign-off (initial plan approval, then per-checkpoint mid-
refactor pauses). Adds a top-of-body Questions directive naming the
mechanism once, and removes a verbatim-duplicated 5-item checkpoint
list between SKILL.md and references/workflow.md — workflow.md now
points back to SKILL.md's list instead of restating it.
golang-modernize already had an ad hoc "Consent check" block for its
contextual-trigger mode, placed after the first heading rather than
with the other top-of-body directives. Renames it to the Questions
directive and moves it up next to Persona/Orchestration mode/Modes,
consistent with the convention in samber/cc-skills-golang#91.
* docs(golang-gopls): generalize MCP registration and settings storage
The MCP registration section named only Claude Code's 'claude mcp add'
command with no acknowledgement that gopls mcp is a harness-agnostic
launch command any MCP-capable host can point at. Notes the underlying
command is portable and that other harnesses use their own settings
file rather than a shared config format.
Also drops a stray 'Store the settings in CLAUDE.md' pointer for
gopls's editor-agnostic LSP settings — there was no reason that one
was Claude Code-only.
* chore: bump metadata.version on every skill touched by this branch
Patch bump per CLAUDE.md's version-discipline rule — no plugin
manifest version change, per standing preference to leave
.claude-plugin/plugin.json, .cursor-plugin/plugin.json, and
gemini-extension.json untouched for skill-level updates.
* docs: refresh README token counts for all touched skills
Re-measured Description/SKILL.md/Directory token counts via
tiktoken-cli after the cross-harness portability changes across all
46 golang-* skills.
* Revert "chore: bump metadata.version on every skill touched by this branch"
This reverts commit 28e6c898f0.
* docs(golang-gopls): name CLAUDE.md/AGENTS.md explicitly
Generic 'the project's agent-config file' phrasing lost the concrete
examples the equivalent line elsewhere in the repo keeps. Names the
two most common files while keeping 'or equivalent' for the rest.
* docs: make cross-harness portability the default for skill authoring
Skills in this repo are authored for Claude Code but installed on
Codex, Gemini CLI, Cursor, Copilot and OpenCode. Hardcoded tool names
in skill body prose (via the Agent tool, AskUserQuestion, Glob) only
resolve on the harness they name and degrade silently elsewhere.
- Makes capability-based prose the default authoring behavior, folded
into Allowed Tools, the frontmatter compatibility row, and the
top-of-body directives table, no separate portability section.
- Adds a new optional Questions top-of-body directive so interactive
skills declare it once instead of repeating a hardcoded tool name
at every question.
- Leads Thinking/Orchestration mode directives with the universal
reasoning/fan-out instruction; ultrathink/ultracode are mentioned
second, as the Claude Code-specific accelerator layered on top.
- Adds paths/globs and experimental dependencies as documented
optional frontmatter fields; explicitly does not adopt Antigravity's
turbo_safe field or Mistral Vibe's permission = always equivalent,
since both conflict with this project's confirm-before-risky-action
policy.
- Fixes a malformed inline checklist item in the after-updating-a-
skill workflow and an inaccurate Override-column reference.
Mirrors samber/cc-skills PR 40, applied to this repo's own structure.
This README keeps its Ultrathink/Ultracode columns, which cc-skills
does not have.
* docs: rename Ultracode policy heading to Deep thinking over parallel sub-agents policy
* ci: bump astral-sh/setup-uv to v10
* fix: pin astral-sh/setup-uv to v10.0.1
The action does not publish floating major-version tags (only full
semver like v10.0.1, v10.0.0) — v10 does not exist as a ref.
Configure mode now writes a standalone, unconfirmed always-load
directive for golang-how-to itself, separate from the optional
`## Required Go skills` block. golang-project-layout writes it
automatically during project initialization so the orchestrator
is guaranteed to load on every future Go session, not just when
its description happens to trigger.
samber/do converts a MustInvoke panic back into a returned error at the
enclosing Invoke call, so using MustInvoke inside provider functions
propagates errors without the extra if err != nil boilerplate.
The file-separation rationale claimed that splitting benchmarks out of
`parser_test.go` lets `go test -run . -short` skip "compiling
benchmark-only fixtures". That is not how the Go toolchain works: all
`*_test.go` files in a package are compiled into a single test binary
regardless of `-run`, `-bench` or `-short`.
Replace the claim with the two rationales that actually hold: cleaner
`-bench` output, and separation of measurement-sized fixtures from
correctness-sized ones.
Recompute Description/SKILL.md/Directory token counts for every skill
with tiktoken-cli (several skills grew since the last measurement, e.g.
golang-continuous-integration's assets/, golang-how-to's references/).
Also add missing golang-pkg-go-dev to the skills tree diagram.
Require test/benchmark files to mirror the source file name (foo.go ->
foo_test.go, foo_bench_test.go), not the individual function/method
under test, and to order test/benchmark functions in the same order
as the source file. Keeps file-to-file navigation and go test/-bench
output predictable.
* docs(golang-testing): warn against testify assert scope leaking into subtests
Reusing an assert/require instance built from the parent *testing.T
inside t.Run closures misattributes subtest failures to the parent
test, silently hiding which subtest actually broke.
* chore(golang-testing): bump skill version to 1.2.4
* feat(skills): add golang-refactoring skill
Adds a new skill covering the safe, at-scale process of refactoring
existing Go code: a coverage-adaptive safety net, tool-driven
behavior-preserving transforms (gopls Rename/Inline/Extract, gofmt -r,
eg, gopatch, go/analysis fixers), the Fowler refactoring catalog mapped
to Go, breaking import cycles and moving types across packages via
type-alias gradual code repair, and a human-in-the-loop workflow of
small staged PRs landed on a refactoring branch.
The workflow persists its plan in the code itself via `// REFACTOR(step
N): ...` markers (seeded when the refactoring branch is created, for
large refactors only) since a multi-step refactor outlasts any single
session's context, delegates each staged change to a sub-agent so the
orchestrating session only keeps short results, and keeps intermediate
PRs out of draft while the final merge-to-main PR is opened as one.
The skill owns the process; it cross-references golang-naming,
golang-project-layout, golang-code-style, golang-design-patterns,
golang-modernize, golang-security/golang-safety, golang-lint,
golang-testing, golang-benchmark, and golang-gopls for target-state
rules and mechanics owned elsewhere, and those first five skills
gained a reciprocal cross-reference back. golang-how-to's skill
loading table, categories, and competing-clusters disambiguation are
updated accordingly.
* docs(golang-refactoring): reformat skill body into concise bullet lists
Convert dense prose paragraphs across SKILL.md and all references/*.md
into nested bullet points for scannability, without changing any rule,
rationale, table, code block, or cross-reference.
* chore(skills): bump version of skills cross-referencing golang-refactoring
code-style, design-patterns, how-to, modernize, naming, and project-layout
each gained a cross-reference to the new golang-refactoring skill; bump
their patch version per the repo version-discipline convention.
* fix(golang-refactoring): correct grammar in persona line (land change -> land changes)
Add a targeted golang-gopls pointer at the rename/find-callers moment in
golang-naming, golang-structs-interfaces, golang-modernize,
golang-troubleshooting, and golang-code-style — gopls safe rename updates
every call site and refuses renames that break interface satisfaction,
which grep/sed/Edit-based renames silently miss.
Also fix golang-gopls's own docs: the capability matrix listed
goToTypeDefinition as a native LSP tool operation, but the native tool's
operation enum does not include it, so type-definition navigation has no
agent-invocable path today.
* feat(skills): add golang-gopls skill
Documents gopls (the official Go language server) as its own atomic
skill: the three ways to reach it (its MCP server, Claude Code's
native LSP tool, and its CLI), a capability-to-tool matrix, the full
feature catalog (navigation, diagnostics, refactors, web features),
and the efficient read/edit workflows from gopls's own MCP
instructions.
golang-how-to previously carried this content inline; it's now
reduced to a pointer, and the ~18 library skills that referenced
gopls navigation through golang-how-to are repointed to golang-gopls
directly, keeping each concept owned by exactly one skill.
* revert: do not bump plugin version for this PR
* refactor(skills): tighten golang-gopls, drop LSP-server-hosting CLI flags
Moves the capability-to-tool matrix out of SKILL.md into its own
references/matrix.md, cutting SKILL.md from ~3.5k to ~2.3k tokens
while keeping every row. Drops mentions of gopls's attached MCP mode
and the mcp -instructions flag, since neither applies to this skill's
agent-only usage. Trims the CLI global flags table down to the ones
that matter outside of running gopls as a long-lived LSP server
(-listen, -remote*, -debug, -otel, -mode removed), and documents the
remaining flags' full value sets exhaustively.
Also fixes the README's [!IMPORTANT] alert blockquote, which a prior
prettier run had collapsed onto one line, and adds golang-gopls to
the ASCII skill map.
* feat(skills): add ultracode orchestration directive to fan-out skills
The `ultracode` keyword (multi-agent workflow orchestration) didn't exist
when these skills were originally written. Add a Thinking-mode-style
Orchestration mode directive to the 12 skills that already describe a
parallel sub-agent fan-out mode for full-codebase audits/scans/cleanups,
so the agent knows to escalate to orchestration for broad sweeps.
Documents the new directive and its README flag (🤖) in CLAUDE.md, and
bumps each touched skill's patch version.
* fix(skills): bump patch version for security, performance, modernize
main already bumped these three skills to the same patch value for an
unrelated change (isolated-worktree workflow), so the rebase merge
landed on an identical version string and hid this branch own change.
Bump one more patch to reflect this branch additions.
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Adds a step to the new-skill checklist: dispatch parallel sub-agents to
read existing skills and add a "-> See" cross-reference where their
topic overlaps with the new skill, keeping the atomic-skill ownership
convention from drifting out of sync.
* feat(skills): add isolated-worktree workflow to 5 skills
Document when to use the native EnterWorktree/ExitWorktree tools for
workflows with genuine collision risk: parallel mutating sub-agents
(golang-documentation, golang-modernize), variant comparison with a
serial-measurement caveat (golang-benchmark, golang-performance), and
per-fix remediation branches during large audits (golang-security).
Read-only parallel audits (security scan, testing, troubleshooting,
etc.) were deliberately excluded — concurrent reads need no isolation.
* revert: keep plugin version at 1.7.0
The isolated-worktree workflow changes do not warrant a plugin-wide
version bump on their own.
* revert: drop worktree workflow from golang-documentation
Its parallel sub-agents write independent files/sections rather than
racing on shared state, so isolation is not warranted here.
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* docs(skills): clarify difference between godig/pkg.go.dev and gopls LSP server
golang-how-to now documents wiring gopls for Go code navigation, both as an
MCP server (agent-first: go_search, go_file_context, go_package_api,
go_symbol_references, go_diagnostics, go_vulncheck) and via Claude Code's
native LSP tool (ENABLE_LSP_TOOL=1 plus the official gopls-lsp plugin).
golang-pkg-go-dev now spells out when to reach for godig (published
ecosystem: versions, docs, importers, CVEs for packages not yet added) vs
gopls (your resolved local build) vs Context7 (fallback for libraries not
indexed on pkg.go.dev), with a task-to-tool matrix.
* fix(skills): route library skills to godig/gopls instead of Context7
17 library skills recommended Context7 as the discoverability fallback
for Go package facts, when godig (pkg.go.dev) and gopls (local code
navigation) are the better-suited tools for those tasks. Each skill's
disclaimer now points to golang-pkg-go-dev (godig) for package docs,
versions, symbols and vulnerabilities, and to golang-how-to (gopls)
for navigating the library's usage in local code, keeping Context7 as
a fallback for docs not indexed on pkg.go.dev. allowed-tools grants
Bash(godig:*), Bash(gopls:*), LSP, and mcp__gopls__* accordingly.
* fix(skills): route golang-popular-libraries to godig/gopls for exploration
The library-selection skill only referred developers to generic library
docs. Add godig for vetting candidate package facts (docs, symbols,
versions, importers, vulnerabilities) and gopls for browsing a
candidate library resolved source once added to the build, keeping
Context7 as a fallback for docs not indexed on pkg.go.dev.
* chore(skills): bump golang-graphql to v0.1.0
* fix(skills): grant gopls CLI and MCP tools in golang-how-to allowed-tools
The skill documents both the gopls MCP server and the native LSP tool
but only granted LSP, not the gopls MCP tools or the gopls CLI itself.
* docs(skills): move godig vs gopls vs Context7 boundary into golang-how-to
The comparison lived in golang-pkg-go-dev, but golang-how-to already owns
gopls wiring and is the orchestrator every Go task loads first, so the
tool-choice guidance belongs there instead. Also added govulncheck as a
fourth compared tool, distinguishing the whole-tree CI audit from gopls
go_vulncheck single-build check. golang-pkg-go-dev now carries a short
pointer instead of duplicating the table.
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* fix(skills): refresh golang-pkg-go-dev for godig v0.2.0
Sync the skill with the godig v0.2.0 CLI surface (was written against v0.1.0):
- vulns now reads the Go vulnerability database (vuln.go.dev, OSV) instead of
pkg.go.dev, so summary and per-range fix versions are populated. It dropped
--filter and --module (only --version and --limit remain).
- Document the new global --vuln-base-url flag.
- Drop vulns from the --filter command list, its filterable-fields row, and the
now-obsolete "vulns uses Go-style ID/Details" casing caveat.
- Update the sample vulns output (fixedVersion removed; ranges/aliases added).
Bump skill 1.0.0 -> 1.1.0, skill-library-version 0.1.0 -> 0.2.0, plugin 1.6.0 -> 1.7.0.
* docs(golang-pkg-go-dev): clarify vulns data source in sample-output intro
Addresses PR review: the intro claimed all field sets mirror the pkg.go.dev
API, but since v0.2.0 vulns is sourced from the Go vuln DB (vuln.go.dev).
* feat(skills): add golang-pkg-go-dev skill
Add a skill covering godig, a pkg.go.dev API client (CLI + MCP server)
for exploring Go packages and modules: docs, symbols, versions,
importers, licenses, and known vulnerabilities. Positioned to be
triggered in place of Context7 for Go packages.
- Complete project-required frontmatter (license, compatibility,
metadata/openclaw, user-invocable, allowed-tools)
- Cross-reference from golang-dependency-management
- Register in golang-how-to loading table + by-category reference
- Add row and description in README
* fix(skills): satisfy CI on golang-pkg-go-dev
- Fix markdownlint MD034/MD060 in sample-output tables
- Remove explicit MCP tool-calling instructions from the body
(drop the "MCP tool" column, keep MCP mentions passive) per the
W001 convention in CLAUDE.md
- Bump golang-how-to (1.0.1) and golang-dependency-management (1.2.4)
metadata.version (both modified)
- Bump plugin version to 1.6.0 in the three plugin manifests
- Update README token count
* chore: re-trigger CI
* feat(skills): cross-reference golang-pkg-go-dev across the catalog
Point library/tool skills and discovery-oriented skills to
golang-pkg-go-dev so pkg.go.dev lookups (docs, versions, symbols,
importers, vulnerabilities) are routed there instead of generic
Context7 doc fetching for Go packages.
- Family A (17 library skills): append a golang-pkg-go-dev pointer to
the "Context7 can help as a discoverability platform" disclaimer
- golang-popular-libraries: vet candidates via pkg.go.dev; use the
imported-by count as a popularity / indirect-quality signal
- golang-security: look up a module's known CVEs without a full scan
- golang-stay-updated: query versions/docs/vulns from the CLI
- golang-documentation: inspect how a published package renders
- Bump metadata.version on all 21 modified skills
- Refresh README token counts (incl. stale how-to / dependency-management rows)
* feat(skills): sync golang-pkg-go-dev with godig v0.1.0
Reviewed the godig CLI/MCP surface (v0.1.0) and updated the skill:
- New commands: dependencies, major-versions, symbol doc, symbol
examples, package imports, version
- Fix: `package info --imports` is now the `package imports` subcommand
- Document global flags (--base-url, --timeout, --log-level) + GODIG_* env
- Make --version / --module first-class per-command flags
- Add a Filter syntax section (operators, string functions, fields)
- Move sample output to references/sample-output.md and refresh formats
(overview, package info, versions, module info gained fields)
- Add skill-library-version 0.1.0; bump skill to 1.1.0
- Refresh README token counts
* chore(skills): keep golang-pkg-go-dev at initial version 1.0.0
* feat(skills): parallel lookups + package-lookup cluster boundary
- golang-pkg-go-dev: instruct parallel godig lookups (batched calls or
sub-agent fan-out) when querying docs/examples/versions for multiple
symbols, packages, or modules
- golang-how-to: add the "Package lookup / discovery" competing cluster
(pkg-go-dev vs popular-libraries vs dependency-management vs security)
to SKILL.md and disambiguation.md
* docs(skills): sync golang-pkg-go-dev with godig v0.1.1
Reflect v0.1.0 -> v0.1.1 changes:
- document exit codes (0 success, 1 runtime error, 2 usage error)
- replace flat filter field list with per-command filterable fields table
- drop undocumented matches() regex; fix example to hasPrefix()
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Revert "Potential fix for pull request finding"
This reverts commit f5e1a19544.
---------
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Add a **Dependencies:** block at the top of each skill body (after directives,
before the first heading) listing install commands for required binaries.
Update CLAUDE.md to document the new top-of-body directive.
Skills updated: golang-benchmark, golang-continuous-integration,
golang-dependency-management, golang-google-wire, golang-grpc, golang-lint,
golang-performance, golang-security, golang-swagger, golang-testing,
golang-troubleshooting.
* docs(uber-dig,uber-fx): add fx vs dig comparison section
Replace one-liner blockquotes with a dedicated comparison section in both
skills. Includes a feature table (lifecycle, modules, signal handling,
timeouts) and clear choose-X-when guidance pointing each skill at the other.
* chore(uber-dig,uber-fx): bump skill versions to 1.1.0
* feat: add golang-uber-dig and golang-uber-fx skills
Two new library skills covering uber-go's reflection-based DI ecosystem. golang-uber-dig covers the container, Provide/Invoke, dig.In/dig.Out, named values, value groups, dig.As, optional deps, Decorate, Scopes, error handling, and Visualize. golang-uber-fx covers fx.New/Run, lifecycle hooks, fx.Module, fx.Annotate, fx.Supply/Replace/Decorate, fxevent logging, and fxtest. Each skill ships recipes.md (end-to-end app examples) and testing.md (test patterns and CI graph validation), and cross-references golang-samber-do, golang-google-wire, and golang-dependency-injection.
* refactor(uber-dig,uber-fx): trim SKILL.md under 2,500 tokens
Both SKILL.md exceeded the project budget. Moved Decorate, Scopes, optional deps, error helpers, Visualize, and Quick Reference into references/advanced.md for both skills. dig: 3,744 -> 2,264 tok. fx: 4,466 -> 2,499 tok. README updated.
* test(uber-dig,uber-fx): add eval prompts and assertions
11 adversarial evals per skill targeting unique guidance: parameter objects, value groups (with flatten), named values, dig.As to hide concrete types, scopes for request locals, container at composition root, DryRun graph validation, Decorate, RecoverFromPanics, fx vs dig choice. fx evals additionally cover lifecycle non-blocking OnStart, fx.Annotate vs fx.Out, modules, fx.Supply, fx.Replace + fx.Populate in fxtest, fxevent.ZapLogger, manual lifecycle for CLI embedding.
* test(uber-dig,uber-fx): add preliminary eval results to EVALUATIONS.md
Ran 4 evals × 2 configs per skill (16 subagents total) with Claude Opus 4.7. Both skills score 100% with-skill. Without-skill: dig 90% (-10pp uplift), fx 95% (-5pp uplift). The base model has very strong baseline knowledge of both libraries; only adversarial evals targeting subtle API choices (Decorate vs scope-shadow Provide; fx.As interface binding) showed meaningful uplift. Full 11-eval suite (53/56 assertions) remains in evals.json for re-runs via /skill-creator.
* fix(uber-dig): clean up unused context import and fix handler signature in recipes
* fix(golang-uber-dig,golang-uber-fx): address PR #25 review comments and deep review findings
PR comments:
- dig/advanced.md: rephrase "module boundaries" to "scope/package wiring boundaries"
- dig/recipes.md: fix ignored repo.List error in HTTP handler (return 500)
- dig/recipes.md: remove unused context import and _ = context.Background hack
- dig/recipes.md: fix handle() signature to idiomatic (w, r) order
- fx/testing.md: assert net.Listen error before using listener
Deep review:
- dig/advanced.md: add code example for dig.Export(true) call site
- dig/advanced.md: clarify c.String() as text summary, not DOT output
- dig/recipes.md: add missing root.Provide(NewHandler) to request-scope recipe
- fx/advanced.md: add fx.ErrorHook to lifecycle quick reference
- fx/testing.md: add zaptest/observer import hint to observer example
- fx/testing.md: comment why lc.Start is used instead of RequireStart
Redesigned 116 eval groups that showed no delta between with/without
skill runs. Three failure modes addressed:
- Both-fail (adversarial override): removed explicit wrong instructions
from prompts; traps now make the wrong approach a natural default
- Both-pass (common knowledge): replaced widely-known patterns with
Go-specific, niche, or counterintuitive scenarios the model misses
without the skill
- Both-partial (mixed assertions): split homogeneous groups, removed
common-knowledge assertions, fixed coverage-gap ones
Also strengthened eval design principles in CLAUDE.md: clearer
adversarial framing rules, pre-flight gate, positive-trigger
preference, training-data saturation heuristic.
- Replace imperative "search for latest version / check URL" instructions
with passive availability hints in golang-continuous-integration,
golang-dependency-management, golang-modernize, and golang-samber-ro
- Replace `go install govulncheck@latest` with golang/govulncheck-action@v1
in CI security asset (W012)
- Remove `gh repo view` from dependency evaluation checklist (W011)
- Add golang-performance step: paste benchstat output in commit body
- Document W011/W012/W001 fix patterns in CLAUDE.md for future authors
- Add snyk-agent-scan step to the "After updating a skill" workflow
- Bump plugin to v1.2.5; bump affected skill versions
Introduce skill-library-version in openclaw metadata for skills covering
versioned third-party projects. Add workflow in CLAUDE.md for periodically
checking outdated skills against upstream changelogs. Apply to all 15
library-specific skills with latest upstream versions.
Add AskUserQuestion to the allowed-tools documentation table in
CLAUDE.md and to the allowed-tools frontmatter of all 24 existing
skills, enabling skills to clarify user intent before proceeding.
Bump patch version for all affected skills and plugin (1.2.3 → 1.2.4).
- Add clawhub-publish.sh to publish all skills with version > 0.0.0
- Refactor workflow to use the shared script
- Add WIP skills with version 0.0.0 (skipped by publish)