Agent skill

Leapp New Artifact

by abrignoni in abrignoni/VLEAPP

Write, rework, review or audit a LEAPP artifact module. An agent skill from abrignoni/VLEAPP.

MITAuto-check passed

Install Leapp New Artifact

skills CLI
$ npx skills add abrignoni/VLEAPP --skill leapp-new-artifact -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install abrignoni/VLEAPP leapp-new-artifact --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/abrignoni/VLEAPP.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/leapp-new-artifact .claude/skills/leapp-new-artifact && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
leapp-new-artifact
GitHub stars
118
Token cost
~3.9k tokens
SKILL.md length
2,418 words
Files
1
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

Write, rework, review or audit a LEAPP artifact module. An agent skill from abrignoni/VLEAPP.

  • Works in 6 steps: Find the data before writing any code → Decide what is worth reporting → Check the siblings first → …
  • Adding support for an app
  • SKILL.md covers 1. Find the data before…, 2. Decide what is worth…, 3. Check the siblings first and 4. Write the module, plus 3 more sections
  • Calls python3

What it does

Leapp New Artifact is an agent skill from abrignoni/VLEAPP. Write, rework, review or audit a LEAPP artifact module. Use when adding support for an app or data source in iLEAPP, ALEAPP, RLEAPP, VLEAPP or DLEAPP, when asked to "add an artifact" or "parse <app", when a module needs new output types, media or a conversation view, and equally when fixing, validating or checking the forensic value of a module that already exists, including one already merged.

Its SKILL.md is about 3.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with SQLite. The repository describes itself as: Vehicle Logs Events And Properties Parser. The licence is MIT.

When your agent uses it

  • Adding support for an app
  • Data source in iLEAPP
  • Asked to add an artifact
  • A module needs new output types

Example prompts

  • “add an artifact”
  • “parse <app”
  • “/leapp-new-artifact”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Find the data before writing any code
  2. Decide what is worth reporting
  3. Check the siblings first
  4. Write the module
  5. Run it against real data
  6. Before opening the PR

What it can do on your machine

Read from SKILL.md and the folder at commit 87b2f9c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Leapp New Artifact loads about 3.9k tokens when it runs. Until then it costs about 104 tokens; SKILL.md has 2,418 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~104
When it runs · the whole SKILL.md, loaded when a task matches
~3.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from abrignoni/VLEAPP at commit 87b2f9c, republished under its MIT licence (© abrignoni). 2,418 words, ~3,936 tokens.

Download SKILL.mdSave it as .claude/skills/leapp-new-artifact/SKILL.md (or your agent's skills folder).
name
leapp-new-artifact
description
Write, rework, review or audit a LEAPP artifact module. Use when adding support for an app or data source in iLEAPP, ALEAPP, RLEAPP, VLEAPP or DLEAPP, when asked to "add an artifact" or "parse <app>", when a module needs new output types, media or a conversation view, and equally when fixing, validating or checking the forensic value of a module that already exists, including one already merged.
<!-- SHARED SKILL. Canonical copy lives in leapps-org/leapps-parity under skills/.
     Do not edit in place; edit the canonical copy and re-run the sync script. -->

Writing a LEAPP artifact module

admin/docs/artifact_info_block.md in the iLEAPP repo is the authority on every field of the __artifacts_v2__ block. Read it first. This skill is the order of operations around it.

1. Find the data before writing any code

Locate the app's files in a real extraction and confirm what is actually there. Do not start from the app's documentation or from another tool's output.

Inventory the stores by content, not by file name. The commonest Android SQLite files have no extension at all, so a scan keyed on .db/.sqlite misses them. Read the first sixteen bytes of every candidate and test for SQLite format 3\x00. The same test works in reverse: a file named .db need not be SQLite. Do this before writing any inventory down, because an early inventory becomes the summary you hand over.

Open the database read-only and dump the full .schema, not just PRAGMA table_info. SQLite keeps the original CREATE TABLE text including the developers' own inline comments, and a CHECK (x IN (...)) constraint is an enum definition for free. Note which tables carry timestamps, which carry identifiers, and which are empty in your sample. An empty table in one image is not evidence the feature is unused.

Read the file twice, with and without its write-ahead log, and compare. file:db?mode=ro applies the log; file:db?immutable=1 ignores it. Compare primary keys, not row counts: a table can hold the same number of rows in both reads with different rows in them. If they differ the sidecars are load-bearing and must be in your paths glob.

2. Decide what is worth reporting

The leapp-artifact-value rule is the bar. Read it before deciding anything here. This section is only the order of operations for clearing that bar with the extraction open.

  1. Enumerate every store in the extraction, across all file types, not just the ones that enumerate themselves. Inventory by extension with sizes alongside the magic-byte scan from step 1, so a format class you have not considered is visible.
  2. List every table with its row count and its full schema. Both, because the ranking that matters is what the columns promise and the counts rank it backwards.
  3. Sort the candidates by what a row would let an examiner do, then draw the line.
  4. Write down which side each table fell on, the excluded ones included, in the notes and in the PR body. Nothing else in the diff records that a table was considered, so an omission and a reasoned exclusion are indistinguishable without it.
  5. Turn every zero-row table you kept into a checked absence in sample_data.

3. Check the siblings first

Grep the other cores for the same app name and bundle or package identifier. If a copy exists, read it. You may be fixing a known problem, or inheriting one. See the leapp-cross-core rule.

4. Write the module

One file under scripts/artifacts/. The key in __artifacts_v2__ must exactly match the processing function's name, or the loader will not associate them.

Get these right, because they are the ones most often wrong:

  • paths is fnmatch, not glob. * crosses /. Matching is case-sensitive off Windows. See the leapp-artifact-paths rule and validate before committing.
  • author is unversioned: @YourHandle, or @YourHandle, Claude if an agent helped.
  • description and notes are examiner-facing and reach the report and the LAVA manifest. Say only what the data proves. See the leapp-claims rule.
  • output_types: "standard" for the usual fan-out, "all" to add KML when the artifact has coordinates, "lava_only" for a producer another module reads.
  • Column order: most relevant event timestamp first, any other timestamps immediately after, then identifiers, then descriptive fields.
  • Never write to evidence. Use open_sqlite_db_readonly(), and attach_sqlite_db_readonly() if you attach. See the leapp-evidence-readonly rule.

If the app has attachments, surface the media itself rather than its filename. See the lava-media rule. Link media by something the extraction records — a content hash, a foreign key, a cache index mapping address to file — not by correlating size and timestamp. An exact match can fail, and a failure is a real result; a ranked guess always returns something. When no recorded link exists, say so and say what you checked, so the next person does not re-derive the same dead ends.

The framework shortens one path and no others

Every seeker copies matched evidence into <report folder>/data/, so each files_found entry is an absolute path on the machine running the tool. artifact_processor splits the third element of your return tuple on \n and passes each piece through Context.get_relative_path. Nothing else is touched. A staged path placed in a data row goes verbatim into the HTML, the TSV, the timeline, the KML and the LAVA database, publishing the examiner's home directory, case folder and report layout to everyone who reads the report.

Shorten the path where it enters the row, not centrally afterwards:

python
data_list.append((timestamp, name, context.get_relative_path(file_found)))

Two things stop this showing up on its own:

  • get_relative_path returns its input unchanged when the data folder is unset, so wherever that state is missing a leaking artifact and a correct one produce byte-identical output. The committed test harness is one such place, which is why a fixture comparison cannot tell them apart. Read a report from a real run instead.
  • A module that builds its own ArtifactHtmlReport rather than returning to the wrapper skips the normalization entirely, including its own "located at" line.

The third element itself has to be real paths, newline joined, because that is what the wrapper splits. Placeholder prose ('see the Source File column'), several paths joined with '; ' or ', ', and an empty string on a run that parsed data are all silent defects: the report's "located at" line then points nowhere. Return '' only from a branch where no file was found. A file that exists but lacks the expected table still reports its path.

admin/scripts/check_report_local_paths.py and admin/scripts/check_source_path.py gate both halves in CI. Run them before opening the PR.

Three failure modes that are silent by construction

An index keyed on a bare name merges two app data directories. The moment you write index[name] = path over files_found, where name is a cache entry, a basename, a media id or a store label, two containers holding that name collide and the second silently overwrites the first. It drops rows, and worse, it can join one container's record to another container's bytes. Key on (container, name), where the container is resolved by matching a path segment equal to the package name, never a substring. The harness dedupe collapses the duplicate storage views of one file; it says nothing about a dict you build yourself.

A decoder that returns nothing on unrecognised input makes the table short, not loud. if value is None: continue is correct defensive code and it is silent: N sources become N-1 rows with no error. Prefer a decoder that degrades to the raw value over one that abstains, and log every skip. Count the inputs independently and assert the row count matches before recording that number anywhere.

A guard conditioned on the emptiness of the set it validates against is inverted. if roots and not in_container(path, roots) admits everything when roots is empty, which is precisely the case the guard exists for. Fail closed, and prove the branch by running the function with an empty set rather than by reading it.

Tolerate schema drift rather than relocating to it: resolve every spelling you have seen instead of replacing the old one, and let a missing table log and yield nothing rather than costing the artifact every row it would have returned.

5. Run it against real data

A module that imports cleanly has not been tested. Run the tool against an extraction that contains the app and confirm the row count, the column alignment, and that timestamps land in the right column with the right epoch.

Build a focused profile containing only the artifacts you changed so the run is fast.

Record what you verified in sample_data as "<corpus key>": "<OS> <ver> | <n> rows". Record zero-row corpora too: that a corpus was checked and had none is useful.

python3 admin/scripts/validate_sample_data.py --emit <image> --key <corpus key> prints these values for you: it runs the tool on a zip, tar, gz or extraction directory, asserts the completion marker and greps the error vocabulary itself, and emits paste-ready blocks for the modules changed on the branch (or --modules), with every zero flagged as unverified. Add the app name and version yourself, and confirm a zero against the source store before recording it. The two checks below still apply to any run you scrape by hand.

Assert the run finished. Scrape counts only from a log containing the tool's own end-of-work marker, and record a sentinel rather than zero when it is absent. A default of zero in an error path asserts a measurement that was never taken, and a zero is indistinguishable from a real empty result. Note that the log prints record singular at one row and prints nothing at all at zero.

Grep the raw output for the layer beneath the framework banner. Artifacts catch their own database errors and log them in their own format, so a clean banner is a statement about the reporting, not about the run. Search for no such column, no such table, malformed and file is not a database, and read how the artifact handled each: an error string inside a deliberate explanatory skip is the code working.

Show full SKILL.md (854 more words)Show less
Run the multi-container tree. It is the check that finds real defects.

A single-container sample cannot detect the commonest scoping bug, because the count it produces looks entirely reasonable. Build one tree containing all three of:

  1. the same container under two spellings, /data/data/<pkg> and /data/user/0/<pkg>, which must collapse to one;
  2. a genuinely different tenant, /data/user/10/<pkg> or a second account directory, with a known row delta, which must add its own rows;
  3. a decoy with an identical internal layout under a different package name, which must add nothing.

Then read the arithmetic per artifact. It needs no knowledge of the module:

resultmeaning
exactly 2x plus the known deltacorrect
1xa second tenant's rows are being dropped or merged
3xthe duplicate storage spellings are not collapsing
>2xa decoy or foreign container is leaking in

Assert exact multiplication. "More rows than before" passes a version that double counts, and "no crash" passes the broken version. Then check row contents per container, not just the count: a lost row is visible in arithmetic, but a surviving row wearing another container's data is not.

This is also the cheapest audit that exists for code already merged, and it finds defects the authoring session missed. Run it over a batch of new modules as routine.

Let the output checker read the report you cannot fully read yourself

admin/scripts/check_artifact_output.py REPORT_DIR reads the generated report and reports the column defects that source review and lint cannot see, because they are properties of a run against real data:

  • empty-column: no value on any row. The query never fills it, or the field is not what it was taken for.
  • constant-column: one value across every row. Sometimes the data is uniform; sometimes a derivation never ran.
  • identical-columns: two columns equal on every row where the values vary, which is what a derived column that equals its input looks like (a basename split on the wrong separator is the classic case).
  • sparse-lead: the table leads with a timestamp that is mostly blank.

Pass --compare MULTI_REPORT_DIR to add the multi-container arithmetic above as a check rather than a manual diff.

It is not a gate. A finding is a prompt, and the answer is usually one of two things: fix the column, or, when the blank or the constant is a real result, write that finding into the notes. What clears it is a sentence naming the column and saying what the checker says, so "ChargeLimit held 100 on all 247 rows" clears it and "ChargeLimit is an integer code reported as stored" does not. The key is the finding, not the column: naming a column for an unrelated reason does not silence a defect, and the name has to appear as a word, so "timestamp" and "timezone" do not stand in for a column named TIME. A one-word header has to be written as the header spells it, because most one-word headers are ordinary words: "Name held an empty string" clears an empty Name column, "a name not applied" does not. An empty column on a messages or location artifact is frequently a forensic negative worth stating (no group chats, no disappearing timers, coarse location denied), not a column to delete.

6. Before opening the PR

  • Re-derive every number in description, notes and sample_data from the finished run. Rereading your own prose does not find these; recomputing each claim does. A count written while building is a claim about the code as it was then, and any later change to what the module sees invalidates it. Check the arithmetic of joins especially: a count of matches is not a count of items when one item can match more than once, so print the distribution rather than the total.
  • State which tier each claim is: proven against real data, verified against the vendor's published source but unexercised here, or code-present and never run. Never let the second or third read as the first.
  • Say what the module does not do, in the same place you say what it does, and name the sample that would close the gap.
  • Run the full tool once. Duplicate artifact name values are rejected at load and nothing else catches it.
  • Reproduce lint locally. Warnings fail the build. See the leapp-ci rule.
  • Reread the PR body for values copied out of someone's real data.

When you change a merged module

Making a guard stricter creates false negatives in the same edit that removes false positives, and the two need opposite inputs. Run both controls: an extraction where the app is absent, proving the guard fires, and one where it is present, proving it does not over-fire. Diff the full row-count list, because the tell is often an artifact vanishing rather than reporting a smaller number.

Re-keying an index is not done when the write is patched: every read of that key has to move with it. Grep the module for remaining bare-key uses, then re-run the single-container case as well as the multi-container one. The single-container run is the control that must still pass, and it is the one that catches a half-applied fix.

© abrignoni, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/leapp-new-artifact of abrignoni/VLEAPP.

Open the folder on GitHubat commit 87b2f9c

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders. This page covers the copy in abrignoni/VLEAPP, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Leapp New Artifact next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Leapp New Artifact compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Leapp New Artifact this skillabrignoni/VLEAPP118—~3.9kAutomated safety check: PassMIT
MCP Server BuildershareAI-lab/learn-claude-code78k4 repos~1.2kAutomated safety check: PassMIT
Copilot Session Failure Analysisdotnet/maui23k—~3.4kAutomated safety check: PassMIT
RTK Rust Design Patternsrtk-ai/rtk83k—~1.9kAutomated safety check: PassApache-2.0
OpenWork Desktop CDP Driverdifferent-ai/openwork24k—~465Automated safety check: PassCustom licence
Add Memory KindEverMind-AI/EverOS13k—~2.6kAutomated safety check: PassApache-2.0

Similar skills

  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 4 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • Mines local Copilot CLI session logs for dotnet/maui to rank costly or failing runs, tag recurring failure modes, propose repo edits and emit guard evals.

    23k GitHub stars~3.4k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Describes seven Rust design patterns for the RTK CLI filter modules, with when to use each, RTK examples, and notes on when a pattern is overkill.

    83k GitHub stars~1.9k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • OpenWork Desktop CDP Driver

    different-ai/openwork

    Drives a running OpenWork desktop window over CDP from the shell to evaluate JS, take screenshots, start sessions and send prompts for hand checks.

    24k GitHub stars~465 tokensUpdated today
    Testing & QAAuto-check passed
  • Add Memory Kind

    EverMind-AI/EverOS

    Walks through adding a new persisted memory kind to EverOS: choose storage among Markdown, SQLite and LanceDB, pick a Markdown strategy, then wire schemas, repos and writers.

    13k GitHub stars~2.6k tokensUpdated today
    DatabasesAuto-check passed
  • Bd To Br Migration

    Dicklesworthstone/beads_rust

    Migrate docs from bd (beads) to br (beadsrust). An agent skill from Dicklesworthstone/beads_rust.

    1.1k GitHub stars~2.2k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed

More from abrignoni/VLEAPP

  • Lava Data View

    abrignoni/VLEAPP

    Wire up how an artifact renders in LAVA, end to end across the producer and the viewer.

    118 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Leapp Corpus Run

    abrignoni/VLEAPP

    Run a LEAPP tool end to end against a real extraction to validate artifact changes and produce a handoff.

    118 GitHub stars~792 tokensUpdated today
    Auto-check passed
  • Leapp Sweep Siblings

    abrignoni/VLEAPP

    After fixing an artifact in one LEAPP core, find and fix the same defect in the sibling cores.

    118 GitHub stars~695 tokensUpdated today
    Auto-check passed
  • Leapp Validate Globs

    abrignoni/VLEAPP

    Validate LEAPP artifact path globs against real extraction file listings before committing them.

    118 GitHub stars~776 tokensUpdated today
    Auto-check passed

Works with

Questions about Leapp New Artifact

What does Leapp New Artifact do?

Write, rework, review or audit a LEAPP artifact module. An agent skill from abrignoni/VLEAPP. Leapp New Artifact is an agent skill from abrignoni/VLEAPP. Write, rework, review or audit a LEAPP artifact module.

When should I use Leapp New Artifact?

Leapp New Artifact fits situations like: adding support for an app; data source in iLEAPP; asked to add an artifact; A module needs new output types.

How do I install Leapp New Artifact in Claude Code?

Run `npx skills add abrignoni/VLEAPP --skill leapp-new-artifact -a claude-code`. Or copy the skill folder (.claude/skills/leapp-new-artifact in abrignoni/VLEAPP) into .claude/skills/leapp-new-artifact in your project. Claude Code loads it when a task matches its description.

How do I install Leapp New Artifact in Codex?

Run `npx skills add abrignoni/VLEAPP --skill leapp-new-artifact -a codex`. Or copy the skill folder (.claude/skills/leapp-new-artifact in abrignoni/VLEAPP) into .agents/skills/leapp-new-artifact in your project. Codex loads it when a task matches its description.

Can I use Leapp New Artifact in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add abrignoni/VLEAPP --skill leapp-new-artifact -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/leapp-new-artifact, .gemini/skills/leapp-new-artifact, .github/skills/leapp-new-artifact and .opencode/skills/leapp-new-artifact in your project.

What does Leapp New Artifact need to run?

Going by SKILL.md and its folder, Leapp New Artifact needs the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Leapp New Artifact access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Leapp New Artifact safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Leapp New Artifact use?

Leapp New Artifact is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Leapp New Artifact use?

About 3.9k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Leapp New Artifact?

Skills that share tags, products or a category with Leapp New Artifact: MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars), Copilot Session Failure Analysis (dotnet/maui, 23k stars), RTK Rust Design Patterns (rtk-ai/rtk, 83k stars) and OpenWork Desktop CDP Driver (different-ai/openwork, 24k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Leapp New Artifact?

abrignoni (a GitHub user) maintains it in abrignoni/VLEAPP, which has 118 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 10, 2026.

Source: abrignoni/VLEAPP on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.