Agent skill

Opensource Pipeline

by affaan-m in affaan-m/ECC

オープンソースパイプライン: プライベートプロジェクトをフォーク、サニタイズし、安全な公開リリースのためにパッケージ化する。3つのエージェント(フォーカー、サニタイザー、パッケージャー)を連鎖させる。トリガー: '/opensource'、'open source this'、'make this public'、'prepare for open source'。

MITAuto-check: notes

Install Opensource Pipeline

skills CLI
$ npx skills add affaan-m/ECC --skill opensource-pipeline -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install affaan-m/ECC opensource-pipeline --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/affaan-m/ECC.git skills-src && mkdir -p .claude/skills && cp -r skills-src/docs/ja-JP/skills/opensource-pipeline .claude/skills/opensource-pipeline && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
opensource-pipeline
GitHub stars
276k
Token cost
~1.5k tokens
SKILL.md length
132 words
Files
1
Skills in repo
683
Repo updated
First seen
Licence
MIT

At a glance

オープンソースパイプライン: プライベートプロジェクトをフォーク、サニタイズし、安全な公開リリースのためにパッケージ化する。3つのエージェント(フォーカー、サニタイザー、パッケージャー)を連鎖させる。トリガー: '/opensource'、'open source this'、'make this public'、'prepare for open source'。

  • Works in 5 steps: 「どのプロジェクト?」(見つからない場合) → 「ライセンス?(MIT / Apache-2.0 / GPL-3.0 /… → 「GitHubのorgまたはユーザー名?」(デフォルト: gh api user… → …
  • SKILL.md covers アクティベートするタイミング, コマンド, プロトコル and ステージングレイアウト, plus 3 more sections
  • Calls gh and git

What it does

Opensource Pipeline is an agent skill from affaan-m/ECC. オープンソースパイプライン: プライベートプロジェクトをフォーク、サニタイズし、安全な公開リリースのためにパッケージ化する。3つのエージェント(フォーカー、サニタイザー、パッケージャー)を連鎖させる。トリガー: '/opensource'、'open source this'、'make this public'、'prepare for open source'。

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with GitHub. The repository describes itself as: The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond. The licence is MIT.

Example prompts

  • “/opensource”
  • “open source this”
  • “make this public”
  • “/opensource-pipeline”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. 「どのプロジェクト?」(見つからない場合)
  2. 「ライセンス?(MIT / Apache-2.0 / GPL-3.0 / BSD-3-Clause)」
  3. 「GitHubのorgまたはユーザー名?」(デフォルト: gh api user -q .loginで検出)
  4. 「GitHubリポジトリ名?」(デフォルト: プロジェクト名)
  5. 「READMEの説明?」(提案のためにプロジェクトを分析)

What it can do on your machine

Read from SKILL.md and the folder at commit 4eb71d9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Opensource Pipeline loads about 1.5k tokens when it runs. Until then it costs about 51 tokens; SKILL.md has 132 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~51
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:244
    - ステージングディレクトリに`.env`、`*.pem`、または`credentials.json`を残すことは**絶対にしない**

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from affaan-m/ECC at commit 4eb71d9, republished under its MIT licence (© affaan-m). 132 words, ~1,503 tokens.

Download SKILL.mdSave it as .claude/skills/opensource-pipeline/SKILL.md (or your agent's skills folder).
name
opensource-pipeline
description
オープンソースパイプライン: プライベートプロジェクトをフォーク、サニタイズし、安全な公開リリースのためにパッケージ化する。3つのエージェント(フォーカー、サニタイザー、パッケージャー)を連鎖させる。トリガー: '/opensource'、'open source this'、'make this public'、'prepare for open source'。
origin
ECC

オープンソースパイプラインスキル

3段階のパイプラインを通じて任意のプロジェクトを安全にオープンソース化する: フォーク(シークレット除去)→ サニタイズ(クリーンな状態を確認)→ パッケージ(CLAUDE.md + setup.sh + README)。

アクティベートするタイミング

  • ユーザーが「このプロジェクトをオープンソース化する」または「これを公開する」と言うとき
  • ユーザーがプライベートリポジトリを公開リリースのために準備したいとき
  • ユーザーがGitHubにプッシュする前にシークレットを除去する必要があるとき
  • ユーザーが/opensource fork、/opensource verify、または/opensource packageを呼び出すとき

コマンド

コマンドアクション
/opensource fork PROJECT完全なパイプライン: フォーク + サニタイズ + パッケージ
/opensource verify PROJECT既存のリポジトリにサニタイザーを実行
/opensource package PROJECTCLAUDE.md + setup.sh + READMEを生成
/opensource listステージングされたすべてのプロジェクトを表示
/opensource status PROJECTステージングされたプロジェクトのレポートを表示

プロトコル

/opensource fork PROJECT

完全なパイプライン — メインワークフロー。

ステップ1: パラメータを収集する

プロジェクトパスを解決する。PROJECTに/が含まれる場合、パス(絶対または相対)として扱う。それ以外の場合: 現在の作業ディレクトリ、$HOME/PROJECTをチェックし、見つからない場合はユーザーに尋ねる。

SOURCE_PATH="<解決された絶対パス>"
STAGING_PATH="$HOME/opensource-staging/${PROJECT_NAME}"

ユーザーに尋ねる:

  1. 「どのプロジェクト?」(見つからない場合)
  2. 「ライセンス?(MIT / Apache-2.0 / GPL-3.0 / BSD-3-Clause)」
  3. 「GitHubのorgまたはユーザー名?」(デフォルト: gh api user -q .loginで検出)
  4. 「GitHubリポジトリ名?」(デフォルト: プロジェクト名)
  5. 「READMEの説明?」(提案のためにプロジェクトを分析)
ステップ2: ステージングディレクトリを作成する
bash
mkdir -p $HOME/opensource-staging/
ステップ3: フォーカーエージェントを実行する

opensource-forkerエージェントをスポーン:

Agent(
  description="Fork {PROJECT} for open-source",
  subagent_type="opensource-forker",
  prompt="""
Fork project for open-source release.

Source: {SOURCE_PATH}
Target: {STAGING_PATH}
License: {chosen_license}

Follow the full forking protocol:
1. Copy files (exclude .git, node_modules, __pycache__, .venv)
2. Strip all secrets and credentials
3. Replace internal references with placeholders
4. Generate .env.example
5. Clean git history
6. Generate FORK_REPORT.md in {STAGING_PATH}/FORK_REPORT.md
"""
)

完了を待つ。{STAGING_PATH}/FORK_REPORT.mdを読む。

ステップ4: サニタイザーエージェントを実行する

opensource-sanitizerエージェントをスポーン:

Agent(
  description="Verify {PROJECT} sanitization",
  subagent_type="opensource-sanitizer",
  prompt="""
Verify sanitization of open-source fork.

Project: {STAGING_PATH}
Source (for reference): {SOURCE_PATH}

Run ALL scan categories:
1. Secrets scan (CRITICAL)
2. PII scan (CRITICAL)
3. Internal references scan (CRITICAL)
4. Dangerous files check (CRITICAL)
5. Configuration completeness (WARNING)
6. Git history audit

Generate SANITIZATION_REPORT.md inside {STAGING_PATH}/ with PASS/FAIL verdict.
"""
)

完了を待つ。{STAGING_PATH}/SANITIZATION_REPORT.mdを読む。

FAILの場合: 結果をユーザーに表示する。「これらを修正して再スキャンしますか、それとも中止しますか?」と尋ねる。

  • 修正する場合: 修正を適用し、サニタイザーを再実行する(最大3回の再試行 — 3回のFAIL後、すべての結果を提示しユーザーに手動で修正するよう依頼する)
  • 中止する場合: ステージングディレクトリをクリーンアップする

PASSまたはWARNINGS付きPASSの場合: ステップ5に進む。

ステップ5: パッケージャーエージェントを実行する

opensource-packagerエージェントをスポーン:

Agent(
  description="Package {PROJECT} for open-source",
  subagent_type="opensource-packager",
  prompt="""
Generate open-source packaging for project.

Project: {STAGING_PATH}
License: {chosen_license}
Project name: {PROJECT_NAME}
Description: {description}
GitHub repo: {github_repo}

Generate:
1. CLAUDE.md (commands, architecture, key files)
2. setup.sh (one-command bootstrap, make executable)
3. README.md (or enhance existing)
4. LICENSE
5. CONTRIBUTING.md
6. .github/ISSUE_TEMPLATE/ (bug_report.md, feature_request.md)
"""
)
ステップ6: 最終レビュー

ユーザーに提示する:

Open-Source Fork Ready: {PROJECT_NAME}

Location: {STAGING_PATH}
License: {license}
Files generated:
  - CLAUDE.md
  - setup.sh (executable)
  - README.md
  - LICENSE
  - CONTRIBUTING.md
  - .env.example ({N} variables)

Sanitization: {sanitization_verdict}

Next steps:
  1. Review: cd {STAGING_PATH}
  2. Create repo: gh repo create {github_org}/{github_repo} --public
  3. Push: git remote add origin ... && git push -u origin main

Proceed with GitHub creation? (yes/no/review first)
ステップ7: GitHubへの公開(ユーザーの承認後)
bash
cd "{STAGING_PATH}"
gh repo create "{github_org}/{github_repo}" --public --source=. --push --description "{description}"

/opensource verify PROJECT

サニタイザーを独立して実行する。パスを解決: PROJECTに/が含まれる場合、パスとして扱う。それ以外の場合は$HOME/opensource-staging/PROJECT、$HOME/PROJECT、現在のディレクトリを確認する。

Agent(
  subagent_type="opensource-sanitizer",
  prompt="Verify sanitization of: {resolved_path}. Run all 6 scan categories and generate SANITIZATION_REPORT.md."
)

/opensource package PROJECT

パッケージャーを独立して実行する。「ライセンス?」と「説明?」を尋ねてから:

Agent(
  subagent_type="opensource-packager",
  prompt="Package: {resolved_path} ..."
)

/opensource list
bash
ls -d $HOME/opensource-staging/*/

FORK_REPORT.md、SANITIZATION_REPORT.md、CLAUDE.mdの存在でパイプラインの進捗を各プロジェクトと共に表示する。


/opensource status PROJECT
bash
cat $HOME/opensource-staging/${PROJECT}/SANITIZATION_REPORT.md
cat $HOME/opensource-staging/${PROJECT}/FORK_REPORT.md

ステージングレイアウト

$HOME/opensource-staging/
  my-project/
    FORK_REPORT.md           # フォーカーエージェントから
    SANITIZATION_REPORT.md   # サニタイザーエージェントから
    CLAUDE.md                # パッケージャーエージェントから
    setup.sh                 # パッケージャーエージェントから
    README.md                # パッケージャーエージェントから
    .env.example             # フォーカーエージェントから
    ...                      # サニタイズされたプロジェクトファイル

アンチパターン

  • ユーザーの承認なしにGitHubにプッシュすることは絶対にしない
  • サニタイザーをスキップすることは絶対にしない — これは安全ゲートである
  • 重大な結果をすべて修正せずにサニタイザーのFAIL後に続行することは絶対にしない
  • ステージングディレクトリに.env、*.pem、またはcredentials.jsonを残すことは絶対にしない

ベストプラクティス

  • 新しいリリースには常に完全なパイプライン(フォーク → サニタイズ → パッケージ)を実行する
  • ステージングディレクトリは明示的にクリーンアップされるまで持続する — レビューに使用する
  • 公開前に手動修正後にサニタイザーを再実行する
  • 削除ではなくシークレットをパラメータ化する — プロジェクトの機能を維持する

関連スキル

サニタイザーが使用するシークレット検出パターンについてはsecurity-reviewを参照。

© affaan-m, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in docs/ja-JP/skills/opensource-pipeline of affaan-m/ECC.

Open the folder on GitHubat commit 4eb71d9

Compare with similar skills

Opensource Pipeline next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Opensource Pipeline compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Opensource Pipeline this skillaffaan-m/ECC276k—~1.5kAutomated safety check: NotesMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Greplooponyx-dot-app/onyx32k4 repos~3.3kAutomated safety check: PassMIT
GitHub Deep Researchbytedance/deer-flow84k4 repos~1.3kAutomated safety check: PassMIT
Diagnosing Superpowers Sessionsobra/superpowers297k3 repos~1.7kAutomated safety check: PassMIT
Update V8 Versionopeninterpreter/openinterpreter69k2 repos~845Automated safety check: PassApache-2.0

Similar skills

  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed
  • GitHub Deep Research

    bytedance/deer-flow

    Researches a GitHub repository over four rounds using the GitHub API and web search, then writes a structured markdown report with timeline, metrics and Mermaid diagrams.

    84k GitHub starsUsed in 4 repos~1.3k tokens
    Research & ScienceAuto-check passed
  • Investigates a session where Superpowers went wrong, reads the transcripts on disk and produces an evidence-cited report, optionally prepared as a bug report for the maintainers.

    297k GitHub starsUsed in 3 repos~1.7k tokens
    Agent WorkflowsAuto-check passed
  • Update V8 Version

    openinterpreter/openinterpreter

    Bumps the pinned v8 and rusty_v8 versions in Codex, validates the release-candidate path with the v8-canary check, and traces failures to upstream build changes.

    69k GitHub starsUsed in 2 repos~845 tokens
    DevOps & CloudAuto-check passed
  • Last30days

    mvanhorn/last30days-skill

    Research what people actually say about any topic in the last 30 days.

    64k GitHub stars~7.9k tokensUpdated today
    Research & ScienceAuto-check: notes

More from affaan-m/ECC

All 683 skills in this repo
  • Skill Stocktake

    affaan-m/ECC

    Audits your installed Claude skills and commands for quality, with a quick mode for recently changed skills and a full mode that evaluates all of them through subagents.

    276k GitHub starsUsed in 5 repos~3.1k tokens
    Auto-check passed
  • Ingests, indexes, searches, edits and monitors video, audio and live streams through the VideoDB Python SDK, returning stream links, clips and timestamps.

    276k GitHub starsUsed in 3 repos~3.5k tokens
    Auto-check: notes
  • Docs Governance

    affaan-m/ECC

    Route broad documentation-governance requests to existing ECC skills and run an opt-in, read-only audit of mapped documentation roles, links, ADR indexes, and evidence references.

    276k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Rules Distillation

    affaan-m/ECC

    Scans installed skills for principles that recur across them and proposes rule-file changes: append, revise, add a section, create a file or leave as covered.

    276k GitHub starsUsed in 2 repos~2.3k tokens
    Auto-check passed
  • Builds DRAFT counterparty agreements from one markdown template and a small JSON spec per party, with clauses picked by the party's role.

    276k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Measures whether agents actually follow a skill, rule or agent definition by generating scenarios at three strictness levels and scoring tool-call traces.

    276k GitHub starsUsed in 1 repo~623 tokens
    Auto-check passed

Works with

Questions about Opensource Pipeline

What does Opensource Pipeline do?

オープンソースパイプライン: プライベートプロジェクトをフォーク、サニタイズし、安全な公開リリースのためにパッケージ化する。3つのエージェント(フォーカー、サニタイザー、パッケージャー)を連鎖させる。トリガー: '/opensource'、'open source this'、'make this public'、'prepare for open source'。. Opensource Pipeline is an agent skill from affaan-m/ECC.

How do I install Opensource Pipeline in Claude Code?

Run `npx skills add affaan-m/ECC --skill opensource-pipeline -a claude-code`. Or copy the skill folder (docs/ja-JP/skills/opensource-pipeline in affaan-m/ECC) into .claude/skills/opensource-pipeline in your project. Claude Code loads it when a task matches its description.

How do I install Opensource Pipeline in Codex?

Run `npx skills add affaan-m/ECC --skill opensource-pipeline -a codex`. Or copy the skill folder (docs/ja-JP/skills/opensource-pipeline in affaan-m/ECC) into .agents/skills/opensource-pipeline in your project. Codex loads it when a task matches its description.

Can I use Opensource Pipeline in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add affaan-m/ECC --skill opensource-pipeline -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/opensource-pipeline, .gemini/skills/opensource-pipeline, .github/skills/opensource-pipeline and .opencode/skills/opensource-pipeline in your project.

What does Opensource Pipeline need to run?

Going by SKILL.md and its folder, Opensource Pipeline needs the command-line tools its instructions call (gh and git).

Does Opensource Pipeline access the network?

SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Opensource Pipeline safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Opensource Pipeline use?

Opensource Pipeline is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Opensource Pipeline use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Opensource Pipeline?

Skills that share tags, products or a category with Opensource Pipeline: PR Babysitter (openinterpreter/openinterpreter, 69k stars), Greploop (onyx-dot-app/onyx, 32k stars), GitHub Deep Research (bytedance/deer-flow, 84k stars) and Diagnosing Superpowers Sessions (obra/superpowers, 297k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Opensource Pipeline?

affaan-m (a GitHub user) maintains it in affaan-m/ECC, which has 276,111 GitHub stars. The repository holds 683 skills in this directory. The repository was last updated on October 10, 2026.

Source: affaan-m/ECC on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.