Agent skill

Quality Gates

by andymai in andymai/brepjs

This skill should be used when a local brepjs quality gate or npm run validate step fails and the specific rule's fix or escape hatch is needed — ESLint errors like "no-explicit-any" or "Direct .oc…

Apache-2.0Auto-check passedTesting & QA

Install Quality Gates

skills CLI
$ npx skills add andymai/brepjs --skill quality-gates -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install andymai/brepjs quality-gates --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/andymai/brepjs.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/quality-gates .claude/skills/quality-gates && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
quality-gates
GitHub stars
115
Token cost
~3.2k tokens
SKILL.md length
1,148 words
Files
1
Skills in repo
21
Repo updated
First seen
Licence
Apache-2.0

At a glance

This skill should be used when a local brepjs quality gate or npm run validate step fails and the specific rule's fix or escape hatch is needed — ESLint errors like "no-explicit-any" or "Direct .oc…

  • Tasks that involve Quality gates
  • SKILL.md covers The gate map, ESLint failures, Pattern checker deep-dive and TRAP: an unbaselined violation…, plus 5 more sections
  • Calls npm, tsc and eslint
  • Tasks that involve Linting and formatting

What it does

Quality Gates is an agent skill from andymai/brepjs. This skill should be used when a local brepjs quality gate or npm run validate step fails and the specific rule's fix or escape hatch is needed — ESLint errors like "no-explicit-any" or "Direct .oc access is banned", pattern-checker "check:patterns" violations (no-double-cast, max-function-lines, require-using-for-handles), a pattern-baseline update, knip flagging an unused export, or the boundary check printing "Layer boundary violations found". Also covers the pattern-baseline trap where an unbaselined…

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Testing & QA, covering Quality gates and Linting and formatting. It works with ESLint, npm and Git. The repository describes itself as: Web CAD library with exact B-Rep geometry. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Quality gates
  • Tasks that involve Linting and formatting

Example prompts

  • “s fix or escape hatch is needed — ESLint errors like”
  • “Direct .oc access is banned”
  • “check:patterns”
  • “/quality-gates”

What it can do on your machine

Read from SKILL.md and the folder at commit 6e20740. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • tsc
    • eslint

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Quality Gates loads about 3.2k tokens when it runs. Until then it costs about 166 tokens; SKILL.md has 1,148 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~166
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from andymai/brepjs at commit 6e20740, republished under its Apache-2.0 licence (© andymai). 1,148 words, ~3,228 tokens.

Download SKILL.mdSave it as .claude/skills/quality-gates/SKILL.md (or your agent's skills folder).
name
quality-gates
description
This skill should be used when a local brepjs quality gate or `npm run validate` step fails and the specific rule's fix or escape hatch is needed — ESLint errors like "no-explicit-any" or "Direct .oc access is banned", pattern-checker "check:patterns" violations (no-double-cast, max-function-lines, require-using-for-handles), a pattern-baseline update, knip flagging an unused export, or the boundary check printing "Layer boundary violations found". Also covers the pattern-baseline trap where an unbaselined violation on main fails every open PR. Not for a red CI run in general (ci-triage) or for hook orchestration and merges (git-pr-workflow).

Quality gates

Pass npm run validate, understand every gate's failure output, and reach for the right escape hatch instead of --no-verify. CLAUDE.md already lists the headline rules and hook tiers; this skill adds the failure-output recipes, escape-hatch mechanics, and the traps those summaries omit.

The gate map

GateCommandRuns in validateRuns in pre-commitElsewhere
Typechecknpm run typecheck (tsc --noEmit)1/5Tier 1 (parallel)CI typecheck
ESLintnpm run lint (eslint src/)2/5Tier 1 via lint-stagedCI lint
Boundariesnpm run check:boundaries3/5Tier 1 (:staged)CI quality
Formatnpm run format:check4/5Tier 1 via lint-stagedCI lint
Changed testsnpm run test5/5Tier 2CI test (sharded, full)
Pattern checkernpm run check:patterns—lint-staged (staged src only)CI quality
knipnpm run knip——pre-push + CI quality

validate is scripts/validate-change.sh: five steps, in order, fail-fast (set -e) — it stops at the first red step and prints nothing after it. Fix step N before step N+1 is reachable. On success it prints === All checks passed ===.

Pre-commit (.husky/pre-commit) runs Tier 1's three checks in parallel, so their output interleaves — read carefully to attribute an error to the right gate. For hook anatomy, FULL_TESTS=1, pre-push, commit-msg, and --no-verify, see the git-pr-workflow skill. (Note: scripts/pre-commit-help.sh prints "coverage thresholds enforced at push time" — that line is stale; pre-push runs only knip.)

ESLint failures

Full config: eslint.config.js (flat config, strictTypeChecked base). Rules actually hit in practice and their sanctioned escapes:

SymptomRuleFix / escape
"Unexpected any"no-explicit-anyType it. Only for a real WASM type gap: // eslint-disable-next-line @typescript-eslint/no-explicit-any -- kernel WASM binding lacks type
"Forbidden non-null assertion"no-non-null-assertionNarrow with a guard; for noUncheckedIndexedAccess array reads, add a bounds check or disable-comment
"must be imported using a type-only import"consistent-type-importsUse import type { ... }
unused varno-unused-varsPrefix with _ (argsIgnorePattern/varsIgnorePattern = ^_)
"Unnecessary conditional"no-unnecessary-conditionThe condition is provably always true/false — remove it, don't disable
switch not exhaustiveswitch-exhaustiveness-checkHandle every union case; a default counts as exhaustive
"Do not use '// @ts-ignore'"ban-ts-commentUse // @ts-expect-error -- reason (the -- reason suffix is mandatory); @ts-ignore/@ts-nocheck are fully banned
console callno-consoleOnly console.error/console.warn are allowed
export let / enumno-restricted-syntaxUse a getter fn or const; use as const object + literal union

Two Layer-2+ bans — "Direct .oc access is banned" and "Direct method calls on .wrapped are banned" — fire in the domain/high-level dirs. The fix for both is getKernel().method(shape.wrapped), never a disable-comment. The rule mechanics and the exact directory list live in the architecture-navigation skill; for the correct kernel-method call pattern see kernel-abstraction.

npm run lint only covers src/. Tests are linted at commit time via lint-staged (.lintstagedrc.json), not by npm run lint. Prettier config (.prettierrc.json): semicolons, single quotes, trailingComma: es5, width 100, LF.

Pattern checker deep-dive

scripts/check-patterns.ts — AST checks ESLint can't express. Five rules, all severity error:

Rule idFires whenThreshold / excusal
no-double-castas unknown as T, as any as T, <T><unknown>exprUse a guard, generic, or branded constructor
no-async-withkernelasync callback passed to withKernel(id, fn) (bare or member call)Use getKernel(id) for async code (kernel-abstraction skill)
require-using-for-handlescreateHandle()/createKernelHandle() not bound with usingExcused when: returned, passed directly as a call argument, or placed in an object/array literal (memory-and-disposal skill)
max-function-linesfunction body > 60 effective linesBlanks, comments, and lone-brace lines don't count; extract helpers
max-nesting-depth> 4 levels of if/for/for-in/for-of/while/do/switch/tryDepth resets inside nested function bodies; use early returns

The rule id is require-using-for-handles (not "missing using") — that exact string goes in baselines and disable-comments.

Inline disable: // brepjs-patterns-disable: <rule-id> on the line above the violation or inline on the same line. <rule-id> may be a specific rule or * for all rules on that line.

Baseline (.pattern-baseline.json, version-2): only new (non-baselined) violations fail; exit 1 if any. Currently 30 entries (15 max-function-lines, 14 no-double-cast, 1 max-nesting-depth). Fingerprints are content-based (file|rule|normalized-80char-snippet|#occurrenceIdx), so:

  • Editing code above a violation does NOT reshuffle fingerprints.
  • Editing the violating line itself (rename, signature change, cast text) changes the fingerprint → it reports as "new". This is intended: touch it, own it.

Regenerate after intentionally adding/removing violations: npm run check:patterns:baseline (= --update-baseline). Other flags: --no-baseline (report everything, ignore baseline), --json, --sarif. Only src/**/*.ts is ever scanned (no .d.ts, no src/kernel/wasm/). Console failure output ends with the two escape hatches printed verbatim: the disable-comment format and the --update-baseline command.

Show full SKILL.md (447 more words)Show less

TRAP: an unbaselined violation on main fails every open PR

CI's quality job runs check:patterns over all of src/ and checks out the PR-merged-with-main commit. So a max-function-lines/no-double-cast violation that lands on main without a matching baseline entry fails the quality job — and thus the required ci-pass aggregate — on every open PR at once, even PRs that never touched that file.

Recovery: land a tiny baseline-bump PR first (npm run check:patterns:baseline, commit .pattern-baseline.json). That PR passes because its own merge commit contains the new baseline; once merged, the other PRs go green. This happens because lint-staged only runs the pattern checker on staged files locally, so a long function can slip in via a large refactor and only bite in full-src CI. See the ci-triage skill for other quality-job failure modes.

TRAP: function-lookup CI diff after adding a *Fns.ts export

Adding a *Fns.ts export makes CI's build job flag a docs/function-lookup.md diff unless the file is regenerated and prettier-normalized before commit — full recipe in the adding-operations skill.

knip (unused exports)

Runs on pre-push and in CI's quality job. Config: knip.config.ts.

  • Export used only by tests? knip can't trace tests/ (separate tsconfig, @/ alias). Tag it @testOnly in a JSDoc comment — tags: ['-testOnly'] treats it as used. This is the correct escape, not deleting the export.
  • ignoreExportsUsedInFile: true; duplicates and optionalPeerDependencies are off (intentional API aliases + the brepjs-opencascade optional peer).
  • Root workspace checks src/**/*.ts only. Companion workspaces (brepjs-opencascade, brepjs-voxel-wasm, brepjs-viewer, brepjs-cad, apps/playground) are fully ignored; brepjs-bim ignores examples/**. See companion-packages.

Boundary check

scripts/check-layer-boundaries.sh enforces downward-only imports (target layer ≤ source layer), handling both @/ alias and relative imports. Violation output:

Layer boundary violations found:

  VIOLATION: src/topology/foo.ts (layer 2: topology) imports from '@/sketching/bar.js' (layer 3: sketching)

The script's layer map is a superset of the CLAUDE.md table — it also places csg/voxel/implicit in Layer 2 and gear/ns/lattice in Layer 3. Unrecognized top-level dirs and root files (src/index.ts) are skipped. --staged mode (check:boundaries:staged, used by pre-commit) checks only staged files; env BOUNDARY_SRC_DIR overrides the scan root for fixture testing. For where new code belongs and how to restructure to fix a violation, see architecture-navigation.

Not gated locally (surfaces only in CI)

  • Coverage: test runs --changed (changed files, no coverage); test:full runs the whole suite with --coverage. Thresholds run on main pushes only, continue-on-error — informational, never a PR gate. See writing-tests.
  • Full test suite: only the sharded CI test job (test:ci, no coverage) runs everything. Pre-commit runs --changed only.
  • size / benchmark: PR-only CI jobs (.size-limit.json budgets; benchmark regression vs main). Not in validate.

Additional resources

Adjacent skills own the neighboring facts: git-pr-workflow (hook tiers, conventional commits, --no-verify), architecture-navigation (layer map, the .oc/.wrapped rule + directory list), kernel-abstraction (withKernel vs getKernel), memory-and-disposal (using handles), ci-triage (CI job failure modes), writing-tests (coverage and the vitest runner config), adding-operations (function-lookup gate), companion-packages (workspace layout).

© andymai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/quality-gates of andymai/brepjs.

Open the folder on GitHubat commit 6e20740

Compare with similar skills

Quality Gates next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Quality Gates compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Quality Gates this skillandymai/brepjs115—~3.2kAutomated safety check: PassApache-2.0
Antfuoyjt/uniapp-vue3-template627—~1.3kAutomated safety check: PassMIT
Devserithemage/serverless-openclaw196—~714Automated safety check: NotesNone
Michel Packmind Engineer ReviewPackmindHub/packmind317—~2.7kAutomated safety check: PassApache-2.0
Ad HooksCorridorTech/PoseCap224—~2.4kAutomated safety check: NotesApache-2.0
Ad HooksCorridorTech/PoseCap224—~1.7kAutomated safety check: PassApache-2.0

Similar skills

  • Antfu

    oyjt/uniapp-vue3-template

    Anthony Fu's {Opinionated} preferences and best practices for web development

    627 GitHub stars~1.3k tokensUpdated 4 mo ago
    DevelopmentAuto-check passed
  • Dev

    serithemage/serverless-openclaw

    Development workflow guide. An agent skill from serithemage/serverless-openclaw.

    196 GitHub stars~714 tokensUpdated 6 mo ago
    Testing & QAAuto-check: notes
  • Review an implemented GitHub issue the way a senior Packmind engineer would — the human-judgment checks that ESLint, the TypeScript compiler, and e2e tests cannot catch (authorization scoping…

    317 GitHub stars~2.7k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Ad Hooks

    CorridorTech/PoseCap

    Scaffold deterministic quality gates per WORKFLOW.md §11 — pre-commit (lint, format, secret-scan), pre-push (build, unit, integration).

    224 GitHub stars~2.4k tokensUpdated 2 days ago
    Testing & QAAuto-check: notes
  • Ad Hooks

    CorridorTech/PoseCap

    Scaffold deterministic quality gates per WORKFLOW.md §11 — pre-commit (lint, format, secret-scan), pre-push (build, unit, integration).

    224 GitHub stars~1.7k tokensUpdated 2 days ago
    Testing & QAAuto-check passed
  • Check Gates

    openshift-eng/ai-helpers

    Repeatedly validate and fix a Jira implementation until tests, lint, builds, requirements, production readiness, and repository cleanliness all pass.

    120 GitHub stars~818 tokensUpdated 3 days ago
    Testing & QAAuto-check passed

More from andymai/brepjs

All 21 skills in this repo
  • Implement

    andymai/brepjs

    A skill your agent uses when authoring or editing a brepjs .brep.ts part — writing the geometry with the functional API (box, cylinder, fuse, cut, fillet, sketch→extrude…), declaring an expected…

    115 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Memory And Disposal

    andymai/brepjs

    This skill should be used when managing WASM handle lifetimes or hunting memory leaks in brepjs — when a task mentions "createHandle() without using keyword risks WASM memory leak"…

    115 GitHub stars~3.1k tokensUpdated yesterday
    Auto-check passed
  • Polish

    andymai/brepjs

    A skill your agent uses when a valid brepjs part should look designed rather than glued-from-primitives (products, toys, mechanisms, anything a human eyeballs), and when exporting/handing off the…

    115 GitHub stars~588 tokensUpdated yesterday
    Auto-check passed
  • Wasm Interop

    andymai/brepjs

    This skill should be used when working across the JS/WASM boundary in brepjs — writing or debugging code in src/kernel/occt, src/kernel/occtWasm, or src/kernel/brepkit, or diagnosing symptoms like…

    115 GitHub stars~3k tokensUpdated yesterday
    Auto-check passed
  • Writing Tests

    andymai/brepjs

    This skill should be used when writing, running, or fixing tests in the brepjs repository — when a task says "add a test", "write a regression test", "tests are failing", "test timed out", "coverage…

    115 GitHub stars~4.3k tokensUpdated yesterday
    Auto-check passed
  • Adding Operations

    andymai/brepjs

    This skill should be used when adding or extending a geometric shape operation in brepjs — the end-to-end recipe once the target module is chosen (which is decided by architecture-navigation) — when…

    115 GitHub stars~4.4k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Quality Gates

What does Quality Gates do?

This skill should be used when a local brepjs quality gate or npm run validate step fails and the specific rule's fix or escape hatch is needed — ESLint errors like "no-explicit-any" or "Direct .oc…. Quality Gates is an agent skill from andymai/brepjs.oc access is banned", pattern-checker "check:patterns" violations (no-double-cast, max-function-lines, require-using-for-handles), a pattern-baseline update, knip flagging an unused export, or the boundary check printing "Layer boundary violations found".

When should I use Quality Gates?

Quality Gates fits situations like: tasks that involve Quality gates; tasks that involve Linting and formatting.

How do I install Quality Gates in Claude Code?

Run `npx skills add andymai/brepjs --skill quality-gates -a claude-code`. Or copy the skill folder (.claude/skills/quality-gates in andymai/brepjs) into .claude/skills/quality-gates in your project. Claude Code loads it when a task matches its description.

How do I install Quality Gates in Codex?

Run `npx skills add andymai/brepjs --skill quality-gates -a codex`. Or copy the skill folder (.claude/skills/quality-gates in andymai/brepjs) into .agents/skills/quality-gates in your project. Codex loads it when a task matches its description.

Can I use Quality Gates in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add andymai/brepjs --skill quality-gates -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/quality-gates, .gemini/skills/quality-gates, .github/skills/quality-gates and .opencode/skills/quality-gates in your project.

What does Quality Gates need to run?

Going by SKILL.md and its folder, Quality Gates needs the command-line tools its instructions call (npm, tsc and eslint).

Does Quality Gates access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Quality Gates safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Quality Gates use?

Quality Gates is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Quality Gates use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Quality Gates?

Skills that share tags, products or a category with Quality Gates: Antfu (oyjt/uniapp-vue3-template, 627 stars), Dev (serithemage/serverless-openclaw, 196 stars), Michel Packmind Engineer Review (PackmindHub/packmind, 317 stars) and Ad Hooks (CorridorTech/PoseCap, 224 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Quality Gates?

andymai (a GitHub user) maintains it in andymai/brepjs, which has 115 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on October 8, 2026.

Source: andymai/brepjs on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.