Agent skill

Opensource Pipeline

by affaan-m in affaan-m/ECC

开源流水线:fork、清理并打包私有项目以安全公开发布。串联3个代理(fork代理、清理代理、打包代理)。触发词:'/opensource'、'open source this'、'make this public'、'prepare for open source'。

MITAuto-check: notes

Install Opensource Pipeline

skills CLI
$ npx skills add affaan-m/ECC --skill opensource-pipeline -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install affaan-m/ECC opensource-pipeline --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/affaan-m/ECC.git skills-src && mkdir -p .claude/skills && cp -r skills-src/docs/zh-CN/skills/opensource-pipeline .claude/skills/opensource-pipeline && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
opensource-pipeline
GitHub stars
276k
Token cost
~1.2k tokens
SKILL.md length
158 words
Files
1
Skills in repo
683
Repo updated
First seen
Licence
MIT

At a glance

开源流水线:fork、清理并打包私有项目以安全公开发布。串联3个代理(fork代理、清理代理、打包代理)。触发词:'/opensource'、'open source this'、'make this public'、'prepare for open source'。

  • Works in 5 steps: "哪个项目?"(如果未找到) → "许可证?(MIT / Apache-2.0 / GPL-3.0 /… → "GitHub 组织或用户名?"(默认:通过 gh api user -q… → …
  • SKILL.md covers 何时激活, 命令, 协议 and 暂存布局, plus 3 more sections
  • Calls gh and git

What it does

Opensource Pipeline is an agent skill from affaan-m/ECC. 开源流水线:fork、清理并打包私有项目以安全公开发布。串联3个代理(fork代理、清理代理、打包代理)。触发词:'/opensource'、'open source this'、'make this public'、'prepare for open source'。

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with GitHub. The repository describes itself as: The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond. The licence is MIT.

Example prompts

  • “/opensource”
  • “open source this”
  • “make this public”
  • “/opensource-pipeline”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. "哪个项目?"(如果未找到)
  2. "许可证?(MIT / Apache-2.0 / GPL-3.0 / BSD-3-Clause)"
  3. "GitHub 组织或用户名?"(默认:通过 gh api user -q .login 检测)
  4. "GitHub 仓库名称?"(默认:项目名称)
  5. "README 的描述?"(分析项目以提供建议)

What it can do on your machine

Read from SKILL.md and the folder at commit 4eb71d9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Opensource Pipeline loads about 1.2k tokens when it runs. Until then it costs about 39 tokens; SKILL.md has 158 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~39
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:247
    * **绝不**在暂存目录中保留 `.env`、`*.pem` 或 `credentials.json`

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from affaan-m/ECC at commit 4eb71d9, republished under its MIT licence (© affaan-m). 158 words, ~1,170 tokens.

Download SKILL.mdSave it as .claude/skills/opensource-pipeline/SKILL.md (or your agent's skills folder).
name
opensource-pipeline
description
开源流水线:fork、清理并打包私有项目以安全公开发布。串联3个代理(fork代理、清理代理、打包代理)。触发词:'/opensource'、'open source this'、'make this public'、'prepare for open source'。
origin
ECC

开源流水线技能

通过三阶段流水线安全地开源任何项目:分叉(剥离密钥)→ 净化(验证清洁)→ 打包(CLAUDE.md + setup.sh + README)。

何时激活

  • 用户说"开源此项目"或"使其公开"
  • 用户希望将私有仓库准备为公开发布
  • 用户需要在推送到 GitHub 前剥离密钥
  • 用户调用 /opensource fork、/opensource verify 或 /opensource package

命令

命令操作
/opensource fork PROJECT完整流水线:分叉 + 净化 + 打包
/opensource verify PROJECT对现有仓库运行净化器
/opensource package PROJECT生成 CLAUDE.md + setup.sh + README
/opensource list显示所有暂存项目
/opensource status PROJECT显示暂存项目的报告

协议

/opensource fork PROJECT

完整流水线——主要工作流程。

步骤 1:收集参数

解析项目路径。如果 PROJECT 包含 /,则视为路径(绝对或相对)。否则检查:当前工作目录、$HOME/PROJECT,然后询问用户。

SOURCE_PATH="<resolved absolute path>"
STAGING_PATH="$HOME/opensource-staging/${PROJECT_NAME}"

询问用户:

  1. "哪个项目?"(如果未找到)
  2. "许可证?(MIT / Apache-2.0 / GPL-3.0 / BSD-3-Clause)"
  3. "GitHub 组织或用户名?"(默认:通过 gh api user -q .login 检测)
  4. "GitHub 仓库名称?"(默认:项目名称)
  5. "README 的描述?"(分析项目以提供建议)
步骤 2:创建暂存目录
bash
mkdir -p $HOME/opensource-staging/
步骤 3:运行分叉代理

生成 opensource-forker 代理:

Agent(
  description="将 {PROJECT} 分叉为开源项目",
  subagent_type="opensource-forker",
  prompt="""
将项目分叉以进行开源发布。

来源:{SOURCE_PATH}
目标:{STAGING_PATH}
许可证:{chosen_license}

遵循完整的分叉协议:
1. 复制文件(排除 .git、node_modules、__pycache__、.venv)
2. 清除所有机密和凭证
3. 将内部引用替换为占位符
4. 生成 .env.example
5. 清理 Git 历史记录
6. 在 {STAGING_PATH}/FORK_REPORT.md 中生成 FORK_REPORT.md
"""
)

等待完成。读取 {STAGING_PATH}/FORK_REPORT.md。

步骤 4:运行净化代理

生成 opensource-sanitizer 代理:

Agent(
  description="验证 {PROJECT} 的脱敏处理",
  subagent_type="opensource-sanitizer",
  prompt="""
验证开源分支的脱敏处理。

项目:{STAGING_PATH}
源(供参考):{SOURCE_PATH}

运行所有扫描类别:
1. 密钥扫描(严重)
2. 个人身份信息扫描(严重)
3. 内部引用扫描(严重)
4. 危险文件检查(严重)
5. 配置完整性(警告)
6. Git 历史审计

在 {STAGING_PATH}/ 目录下生成 SANITIZATION_REPORT.md 文件,并给出通过/未通过的判定结果。
"""
)

等待完成。读取 {STAGING_PATH}/SANITIZATION_REPORT.md。

如果失败: 向用户展示发现结果。询问:"修复这些问题并重新扫描,还是中止?"

  • 如果修复:应用修复,重新运行净化器(最多重试 3 次——3 次失败后,展示所有发现结果并请用户手动修复)
  • 如果中止:清理暂存目录

如果通过或带警告通过: 继续步骤 5。

步骤 5:运行打包代理

生成 opensource-packager 代理:

Agent(
  description="将项目 {PROJECT} 打包为开源项目",
  subagent_type="opensource-packager",
  prompt="""
为项目生成开源打包文件。

项目:{STAGING_PATH}
许可证:{chosen_license}
项目名称:{PROJECT_NAME}
描述:{description}
GitHub 仓库:{github_repo}

生成:
1. CLAUDE.md(命令、架构、关键文件)
2. setup.sh(一键引导脚本,设为可执行)
3. README.md(或增强现有文件)
4. LICENSE
5. CONTRIBUTING.md
6. .github/ISSUE_TEMPLATE/(bug_report.md、feature_request.md)
"""
)
步骤 6:最终审查

向用户展示:

开源分支就绪:{PROJECT_NAME}

位置:{STAGING_PATH}
许可证:{license}
生成的文件:
  - CLAUDE.md
  - setup.sh(可执行文件)
  - README.md
  - LICENSE
  - CONTRIBUTING.md
  - .env.example({N} 个变量)

清理:{sanitization_verdict}

后续步骤:
  1. 审查:cd {STAGING_PATH}
  2. 创建仓库:gh repo create {github_org}/{github_repo} --public
  3. 推送:git remote add origin ... && git push -u origin main

是否继续创建 GitHub 仓库?(是/否/先审查)
步骤 7:GitHub 发布(用户批准后)
bash
cd "{STAGING_PATH}"
gh repo create "{github_org}/{github_repo}" --public --source=. --push --description "{description}"

/opensource verify PROJECT

独立运行净化器。解析路径:如果 PROJECT 包含 /,则视为路径。否则检查 $HOME/opensource-staging/PROJECT,然后 $HOME/PROJECT,最后当前目录。

Agent(
  subagent_type="opensource-sanitizer",
  prompt="验证以下路径的清理状态:{resolved_path}。运行全部6类扫描,并生成 SANITIZATION_REPORT.md 文件。"
)

/opensource package PROJECT

独立运行打包器。询问"许可证?"和"描述?",然后:

Agent(
  subagent_type="opensource-packager",
  prompt="Package: {resolved_path} ..."
)

/opensource list
bash
ls -d $HOME/opensource-staging/*/

显示每个项目及其流水线进度(FORK_REPORT.md、SANITIZATION_REPORT.md、CLAUDE.md 是否存在)。


/opensource status PROJECT
bash
cat $HOME/opensource-staging/${PROJECT}/SANITIZATION_REPORT.md
cat $HOME/opensource-staging/${PROJECT}/FORK_REPORT.md

暂存布局

$HOME/opensource-staging/
  my-project/
    FORK_REPORT.md           # 来自 forker 代理
    SANITIZATION_REPORT.md   # 来自 sanitizer 代理
    CLAUDE.md                # 来自 packager 代理
    setup.sh                 # 来自 packager 代理
    README.md                # 来自 packager 代理
    .env.example             # 来自 forker 代理
    ...                      # 清理后的项目文件

反模式

  • 绝不在未经用户批准的情况下推送到 GitHub
  • 绝不跳过净化器——它是安全门
  • 绝不在净化器失败且未修复所有关键发现后继续
  • 绝不在暂存目录中保留 .env、*.pem 或 credentials.json

最佳实践

  • 对于新版本,始终运行完整流水线(分叉 → 净化 → 打包)
  • 暂存目录会持续存在直到显式清理——用于审查
  • 在发布前,任何手动修复后重新运行净化器
  • 参数化密钥而非删除它们——保留项目功能

相关技能

参见 security-review 了解净化器使用的密钥检测模式。

© affaan-m, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in docs/zh-CN/skills/opensource-pipeline of affaan-m/ECC.

Open the folder on GitHubat commit 4eb71d9

Compare with similar skills

Opensource Pipeline next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Opensource Pipeline compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Opensource Pipeline this skillaffaan-m/ECC276k—~1.2kAutomated safety check: NotesMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Greplooponyx-dot-app/onyx32k4 repos~3.3kAutomated safety check: PassMIT
GitHub Deep Researchbytedance/deer-flow84k4 repos~1.3kAutomated safety check: PassMIT
Diagnosing Superpowers Sessionsobra/superpowers297k3 repos~1.7kAutomated safety check: PassMIT
Update V8 Versionopeninterpreter/openinterpreter69k2 repos~845Automated safety check: PassApache-2.0

Similar skills

  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed
  • GitHub Deep Research

    bytedance/deer-flow

    Researches a GitHub repository over four rounds using the GitHub API and web search, then writes a structured markdown report with timeline, metrics and Mermaid diagrams.

    84k GitHub starsUsed in 4 repos~1.3k tokens
    Research & ScienceAuto-check passed
  • Investigates a session where Superpowers went wrong, reads the transcripts on disk and produces an evidence-cited report, optionally prepared as a bug report for the maintainers.

    297k GitHub starsUsed in 3 repos~1.7k tokens
    Agent WorkflowsAuto-check passed
  • Update V8 Version

    openinterpreter/openinterpreter

    Bumps the pinned v8 and rusty_v8 versions in Codex, validates the release-candidate path with the v8-canary check, and traces failures to upstream build changes.

    69k GitHub starsUsed in 2 repos~845 tokens
    DevOps & CloudAuto-check passed
  • Last30days

    mvanhorn/last30days-skill

    Research what people actually say about any topic in the last 30 days.

    64k GitHub stars~7.9k tokensUpdated yesterday
    Research & ScienceAuto-check: notes

More from affaan-m/ECC

All 683 skills in this repo
  • Skill Stocktake

    affaan-m/ECC

    Audits your installed Claude skills and commands for quality, with a quick mode for recently changed skills and a full mode that evaluates all of them through subagents.

    276k GitHub starsUsed in 5 repos~3.1k tokens
    Auto-check passed
  • Ingests, indexes, searches, edits and monitors video, audio and live streams through the VideoDB Python SDK, returning stream links, clips and timestamps.

    276k GitHub starsUsed in 3 repos~3.5k tokens
    Auto-check: notes
  • Docs Governance

    affaan-m/ECC

    Route broad documentation-governance requests to existing ECC skills and run an opt-in, read-only audit of mapped documentation roles, links, ADR indexes, and evidence references.

    276k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Rules Distillation

    affaan-m/ECC

    Scans installed skills for principles that recur across them and proposes rule-file changes: append, revise, add a section, create a file or leave as covered.

    276k GitHub starsUsed in 2 repos~2.3k tokens
    Auto-check passed
  • Builds DRAFT counterparty agreements from one markdown template and a small JSON spec per party, with clauses picked by the party's role.

    276k GitHub stars~2.9k tokensUpdated yesterday
    Auto-check passed
  • Measures whether agents actually follow a skill, rule or agent definition by generating scenarios at three strictness levels and scoring tool-call traces.

    276k GitHub starsUsed in 1 repo~623 tokens
    Auto-check passed

Works with

Questions about Opensource Pipeline

What does Opensource Pipeline do?

开源流水线:fork、清理并打包私有项目以安全公开发布。串联3个代理(fork代理、清理代理、打包代理)。触发词:'/opensource'、'open source this'、'make this public'、'prepare for open source'。. Opensource Pipeline is an agent skill from affaan-m/ECC.

How do I install Opensource Pipeline in Claude Code?

Run `npx skills add affaan-m/ECC --skill opensource-pipeline -a claude-code`. Or copy the skill folder (docs/zh-CN/skills/opensource-pipeline in affaan-m/ECC) into .claude/skills/opensource-pipeline in your project. Claude Code loads it when a task matches its description.

How do I install Opensource Pipeline in Codex?

Run `npx skills add affaan-m/ECC --skill opensource-pipeline -a codex`. Or copy the skill folder (docs/zh-CN/skills/opensource-pipeline in affaan-m/ECC) into .agents/skills/opensource-pipeline in your project. Codex loads it when a task matches its description.

Can I use Opensource Pipeline in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add affaan-m/ECC --skill opensource-pipeline -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/opensource-pipeline, .gemini/skills/opensource-pipeline, .github/skills/opensource-pipeline and .opencode/skills/opensource-pipeline in your project.

What does Opensource Pipeline need to run?

Going by SKILL.md and its folder, Opensource Pipeline needs the command-line tools its instructions call (gh and git).

Does Opensource Pipeline access the network?

SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Opensource Pipeline safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Opensource Pipeline use?

Opensource Pipeline is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Opensource Pipeline use?

About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Opensource Pipeline?

Skills that share tags, products or a category with Opensource Pipeline: PR Babysitter (openinterpreter/openinterpreter, 69k stars), Greploop (onyx-dot-app/onyx, 32k stars), GitHub Deep Research (bytedance/deer-flow, 84k stars) and Diagnosing Superpowers Sessions (obra/superpowers, 297k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Opensource Pipeline?

affaan-m (a GitHub user) maintains it in affaan-m/ECC, which has 276,111 GitHub stars. The repository holds 683 skills in this directory. The repository was last updated on October 10, 2026.

Source: affaan-m/ECC on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.