Code Review Checklist
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
States load-bearing decisions, invariants, and weak points. An agent skill from athola/claude-night-market.
$ npx skills add athola/claude-night-market --skill night-market-architecture-contract -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install athola/claude-night-market night-market-architecture-contract --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/athola/claude-night-market.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/night-market-architecture-contract .claude/skills/night-market-architecture-contract && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "night-market-architecture-contract" agent skill from https://github.com/athola/claude-night-market/tree/master/.claude/skills/night-market-architecture-contract into .claude/skills/night-market-architecture-contract/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "night-market-architecture-contract", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/athola/claude-night-market/tree/master/.claude/skills/night-market-architecture-contractType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add athola/claude-night-market --skill night-market-architecture-contract -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install athola/claude-night-market night-market-architecture-contract --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/athola/claude-night-market.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/night-market-architecture-contract .agents/skills/night-market-architecture-contract && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "night-market-architecture-contract" agent skill from https://github.com/athola/claude-night-market/tree/master/.claude/skills/night-market-architecture-contract into .agents/skills/night-market-architecture-contract/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "night-market-architecture-contract", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add athola/claude-night-market --skill night-market-architecture-contract -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install athola/claude-night-market night-market-architecture-contract --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/athola/claude-night-market.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/night-market-architecture-contract .cursor/skills/night-market-architecture-contract && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "night-market-architecture-contract" agent skill from https://github.com/athola/claude-night-market/tree/master/.claude/skills/night-market-architecture-contract into .cursor/skills/night-market-architecture-contract/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "night-market-architecture-contract", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/athola/claude-night-market.git --path .claude/skills/night-market-architecture-contract--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add athola/claude-night-market --skill night-market-architecture-contract -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install athola/claude-night-market night-market-architecture-contract --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/athola/claude-night-market.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/night-market-architecture-contract .gemini/skills/night-market-architecture-contract && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "night-market-architecture-contract" agent skill from https://github.com/athola/claude-night-market/tree/master/.claude/skills/night-market-architecture-contract into .gemini/skills/night-market-architecture-contract/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "night-market-architecture-contract", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install athola/claude-night-market night-market-architecture-contractInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add athola/claude-night-market --skill night-market-architecture-contract -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/athola/claude-night-market.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/night-market-architecture-contract .github/skills/night-market-architecture-contract && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "night-market-architecture-contract" agent skill from https://github.com/athola/claude-night-market/tree/master/.claude/skills/night-market-architecture-contract into .github/skills/night-market-architecture-contract/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "night-market-architecture-contract", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add athola/claude-night-market --skill night-market-architecture-contract -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install athola/claude-night-market night-market-architecture-contract --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/athola/claude-night-market.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/night-market-architecture-contract .opencode/skills/night-market-architecture-contract && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "night-market-architecture-contract" agent skill from https://github.com/athola/claude-night-market/tree/master/.claude/skills/night-market-architecture-contract into .opencode/skills/night-market-architecture-contract/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "night-market-architecture-contract", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
night-market-architecture-contractStates load-bearing decisions, invariants, and weak points. An agent skill from athola/claude-night-market.
Night Market Architecture Contract is an agent skill from athola/claude-night-market. States load-bearing decisions, invariants, and weak points. Use when judging a design change. Do not use for gating; use night-market-change-control.
Its SKILL.md is about 4.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development. It works with Python. The repository describes itself as: 23 Claude Code plugins: TDD enforcement hooks, git/PR workflows, spec-driven development, code review, project lifecycle, fix-from-error, maintenance automation, context… The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 9f3eb00. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
rggitghuvpython3makemypyFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, gh and uv, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Night Market Architecture Contract loads about 4.8k tokens when it runs. Until then it costs about 46 tokens; SKILL.md has 2,253 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from athola/claude-night-market at commit 9f3eb00, republished under its MIT licence (© athola). 2,253 words, ~4,788 tokens.
.claude/skills/night-market-architecture-contract/SKILL.md (or your agent's skills folder).This skill records the design decisions that hold claude-night-market
together, the invariants that enforcement code keeps true, and the weak
points that are known and accepted. Read it before proposing a change
that crosses a plugin boundary, touches a hook, adds a skill, or bumps
a version. Every claim cites in-repo evidence: an ADR (Architecture
Decision Record, in docs/adr/), a commit hash, or a checked-in
enforcement file. Verify a citation before relying on it:
git log --oneline -1 <hash>
rg -n "Status" docs/adr/<file>.mdEach of the 23 plugins under plugins/ must install and run alone.
There is no shared registry and no root-level shared library that
plugins import at runtime (ADR-0001, Accepted). Plugins detect each
other at runtime via filesystem checks and must degrade gracefully when
a sibling is absent.
Cross-plugin DRY is an anti-pattern here, and that is settled by
experiment, not taste. Commit 054e2679 consolidated 1164 lines of
duplicated tasks_manager.py from attune, sanctum, and spec-kit into a
shared root script. It broke plugin self-containment and was reverted
in 29961cd2. The durable fix, d89a55c7, made the copies
per-plugin and intentionally different. docs/dependency-audit.md
records the per-plugin copies as the approved state. Do not re-propose
the consolidation.
Practical test before you extract shared code: if a user installs only one plugin from the marketplace, does your change still work? If not, duplicate the code into each plugin instead.
Claude Code copies an installed plugin into a cache directory and runs
its hooks under the host system Python, which can be as old as 3.9.
The repo itself is Python 3.12 (root pyproject.toml,
requires-python >= 3.12). Only hook scripts and their transitive
import chains carry the 3.9 constraint. Five contract rules follow,
each purchased with an outage:
| Rule | Why (evidence) |
|---|---|
| Hook code and every transitive import must be Python 3.9 compatible | datetime.UTC (a 3.11+ alias) broke the whole hook import chain repeatedly. ruff kept auto-reverting the fix until UP017 was globally ignored (pyproject.toml line 165) and an AST scan test held the line (plugins/leyline/tests/test_python39_compat.py) |
Read the hook payload as JSON on stdin, never from CLAUDE_TOOL_* env vars | Claude Code does not set those env vars, so env-reading hooks were silent no-ops for months (full record: night-market-failure-archaeology SB9). Canonical reader: read_hook_payload() in plugins/abstract/hooks/shared/hook_io.py |
| No relative paths in hooks | The cache directory is not the repo checkout. conserve's session-start hook broke on a relative path and now inlines its JSON utilities (CHANGELOG) |
| Hook entrypoints must import safely under a bare interpreter | An eager import yaml in gauntlet made every git commit emit ModuleNotFoundError. Guarded in 45dd77ef (#518), anthropic deferred in 9bfc0a7a |
Subprocess timeouts must sit below the budget registered in hooks.json | herald's LLM call once outlived its registered Stop-hook budget, so the harness killed the hook with no verdict at all (full record: night-market-failure-archaeology SB7). Guard test: plugins/herald/tests/unit/test_double_shot_latte.py |
CI enforcement: .github/workflows/python39-compat.yml runs two
gates with uneven coverage. Gate 1 (ruff UP007, flags 3.10+ union
syntax) covers 12 plugins' hooks/ dirs. Gate 2 (hook test suites
inside a real Python 3.9 venv) covers only 7 plugins: abstract,
conserve, egregore, imbue, leyline, memory-palace, sanctum. herald
ships a Stop hook yet appears in neither gate.
.claude-plugin/marketplace.json is the version source of truth
(1.9.15 as of 2026-07-02). Each plugin carries three manifests that
must stay in sync with it and with each other:
.claude-plugin/plugin.json (name, version, component arrays).claude-plugin/metadata.json (version plus dependency hints)openpackage.yml (cross-framework manifest)Plus pyproject.toml and any __init__.py carrying __version__.
Never hand-edit versions across files. Use the bumper, which finds and
rewrites all of them:
uv run python plugins/sanctum/scripts/update_versions.py <version>One trap: metadata.json dependencies (for example imbue declaring
"abstract": ">=2.0.0") is a separate semver namespace for capability
compatibility. It does not track the marketplace version and a 2.0.0
there does not mean marketplace 2.0.0 exists.
Claude Code loads every installed skill's description into context at 2% of the context window, with a 16,000-character fallback (ADR-0004, Accepted, updated 2026-05-21). Descriptions that exceed the budget make skills invisible with no error anywhere. That is why:
docs/skill-description-guide.md), enforced by the
validate-description-budget pre-commit hook backed by
plugins/abstract/scripts/validate_budget.py.DEFAULT_BUDGET in plugins/abstract/scripts/validate_budget.py,
overridable via SLASH_COMMAND_TOOL_CHAR_BUDGET). ADR-0004 and
docs/skill-description-guide.md still cite a stale 60,000 figure;
the script is the enforcer. Flag the ADR for an update through
change control.When adding a skill, spend the 160 characters on trigger phrases, not on restating the name.
Decisions, learnings, and audit syntheses are posted to GitHub
Discussions, which act as agent collective memory across sessions
(ADR-0007, Accepted). There is no gh discussion subcommand: all
Discussions access goes through gh api graphql. Release trust is
established by SLSA attestation (Supply-chain Levels for Software
Artifacts) of trust-report.json on master pushes
(.github/workflows/trust-attestation.yml). The original blockchain
design (ERC-8004) was dropped for cost. ADR-0008 is marked Superseded
2026-03-15 and now points at GitHub Attestations. See
night-market-collective-memory for the Discussions workflow.
docs/skill-integration-guide.md defines the role taxonomy used when
judging whether a skill is an orphan or a hub:
| Role | Inbound refs | Invoked directly | Example |
|---|---|---|---|
entrypoint | low (0-3) | yes | sanctum:do-issue |
library | high (4+) | rarely | imbue:proof-of-work |
hook-target | varies | no | imbue:vow-enforcement |
A skill with zero inbound Skill() references is only a problem if it
also has no command path and no hook that loads it. Check the role
before archiving anything.
Each row names the enforcement that keeps the invariant true. If you weaken the enforcement, you own the failure mode in the third column.
| Invariant | Enforced by | What breaks if violated |
|---|---|---|
| Hook import chains are Python 3.9 safe | .github/workflows/python39-compat.yml (2 gates) plus AST scan test plugins/leyline/tests/test_python39_compat.py | Total hook outage: one 3.11-only import kills every hook that transitively loads the module |
No bare except: and errors propagate by default | ruff E ruleset (root pyproject.toml) plus CONSTITUTION.md rule 10 | Scanners silently drop files and report success on garbage input, and failures become invisible |
| All manifests carry the same ecosystem version | plugins/sanctum/scripts/update_versions.py rewrites pyproject/plugin.json/metadata.json/openpackage.yml/__init__.py in one pass | Version drift across ~100 files, and marketplace.json stops being the source of truth |
book/src/reference/capabilities-reference.md matches plugin registrations | scripts/capabilities-sync-check.sh via make docs-sync-check and .github/workflows/capabilities-sync.yml | Published docs advertise components that do not exist, or hide ones that do |
No new dangling Skill(plugin:name) references | scripts/check_skill_graph_drift.py ratchet against scripts/skill_graph_baseline.json | A model tries to load the referenced skill and silently gets nothing |
Every SKILL.md has an ## Exit Criteria section | scripts/check_skill_exit_criteria_drift.py ratchet against scripts/skill_exit_criteria_baseline.json | Skills the model cannot tell when to stop executing (vague success criteria at scale) |
| Hook subprocess timeout < registered hook budget | Guard test in plugins/herald/tests/unit/test_double_shot_latte.py asserts LLM_TIMEOUT_SECONDS fits inside the hooks.json timeout | Harness kills the hook mid-flight and no verdict is emitted at all |
| Hook payloads are read stdin-first | plugins/abstract/hooks/shared/hook_io.py read_hook_payload() shared by hook scripts | Hooks become silent no-ops (this happened, and the only symptom was a starved learning digest) |
The two ratchet scripts share one mechanic: they fail a commit only
when the violation count rises above the committed baseline, and they
ask you to lower the baseline when the count drops. Never raise a
baseline to get a commit through. That is routing around change
control. One documented exception: a brand-new library skill
legitimately starts uncalled, and scripts/check_skill_graph_drift.py
(plus the _comment in scripts/skill_graph_baseline.json) instructs
you to raise max_uncalled_libraries to record the 30-day consumer
grace period that .claude/rules/shared-utility-consumer-rule.md
grants. See night-market-change-control.
Stated plainly so nobody rediscovers them the hard way. These are open by decision or by neglect, not secrets.
Skill-discovery overflow is silent. If total description overhead exceeds the context budget, skills vanish with no error (ADR-0004). The 160-char cap and validator ceiling are preventive guards. There is no runtime detection of overflow.
The quality-gate federation has one real orchestrator. The gate
skills (karpathy-principles, scope-guard, proof-of-work, justify,
rigorous-reasoning, vow-enforcement) are designed to compose, but
only egregore:quality-gate sequences the full pipeline today
(docs/quality-gates.md, "Who currently orchestrates"). Every
other consumer picks gates ad hoc.
docs/project-brief.md, docs/specification.md, and
docs/implementation-plan.md are overwritten each feature cycle.
The current contents describe only the latest cycle (insight-palace
bridge as of 2026-07-02). Past cycles survive only in git history.
Do not cite these files as a permanent record.
Duplicate module names across plugins force per-plugin mypy.
Running mypy plugins/ from the root collides on duplicate module
names (comment in .github/workflows/typecheck.yml). The same
constraint makes root pytest exclude plugins/*
(norecursedirs in root pyproject.toml, and root conftest.py
documents the ImportPathMismatchError). Always run plugin tests
and typechecks per plugin.
mdbook is unpinned in the deploy workflow.
.github/workflows/deploy-book.yml installs mdbook-version: 'latest', so an upstream mdbook release can break the book deploy
with no repo change. Candidate fix: pin a version. Not done as of
2026-07-02.
The autonomous loop rides an undocumented harness behavior.
Egregore continues across turns because its Stop hook returns
{"decision": "block", "reason": ...} and the harness feeds the
reason back as the next instruction. Upstream documents Stop hooks
as a gate on stopping, not as a continuation primitive, and the
sanctioned alternatives (/loop, CronCreate) are session-scoped.
ralph-wiggum rides the same behavior, bounded by an iteration
count. Egregore's cost is bounded as of 9f31a878 (stall
detection, default 3), and the reliance is not. No test can cover the
harness end of it. Full record:
docs/adr/0022-stop-hook-reinjection-as-continuation.md
(2026-08-23).
The reliance stands. What changed is that its failure is now
observable rather than silent.
plugins/egregore/scripts/continuation_baton.py has the session
record each handoff with the deadline by which the next turn should
have started, so reinjection quietly ceasing strands a baton with
the process still alive. That is a distinct signal, where before an
upstream change and a finished run looked the same from outside.
Stranded means stalled rather than old, so a long healthy run never
reads as one. The watchdog does not consume the baton yet, which is
accepted debt in
docs/adr/0023-continuation-baton-makes-a-dropped-turn-observable.md
(2026-08-25).
All 23 records live in docs/adr/. Statuses for 0001 to 0017 were
read from the files on 2026-07-02, and 0018 to 0022 on 2026-08-23.
| ADR | Title | Status | One-line takeaway |
|---|---|---|---|
| 0001 | Plugin Dependency Isolation | Accepted | No shared registry. Runtime filesystem detection with graceful degradation |
| 0002 | Extract QuotaTracker to Leyline | Accepted | Quota tracking moved from conjure into leyline for reuse |
| 0003 | Command Description Refactoring | Accepted | Two-part descriptions: short display line, rich identification text |
| 0004 | Skill Description Budget Optimization | Accepted (updated 2026-05-21) | 160-char cap. Budget is 2% of context, 16k fallback. Its 60k validator ceiling is stale: the enforcing script uses 90k |
| 0005 | Attune Plugin Discoverability Enhancement | Accepted (2026-02-05) | Superpowers-style trigger phrasing for attune components |
| 0006 | Self-Adapting Skill Health | Accepted (2026-02-15) | Homeostatic monitoring detects degrading skills |
| 0007 | GitHub Discussions as Agent Collective Memory | Accepted (2026-02-19) | Decisions and learnings posted to Discussions (GraphQL only) |
| 0008 | Behavioral Contract Verification Framework | Superseded (2026-03-15) | ERC-8004 blockchain dropped for cost. GitHub Attestations (SLSA) instead |
| 0009 | Sidecar Service Discovery via Port Files | Accepted | Sidecar daemons publish their ports through port files |
| 0010 | Stacked Diff Workflows | Accepted | git --update-refs plus gh pr create --base as zero-dependency stacking |
| 0011 | Shared Session-Capture Envelope | Accepted | One JSON envelope shape for friction and trace payloads, separate files |
| 0012 | Confidence-Tagged Agent Claims | Superseded by 0017 | VERIFIED/INFERRED/ASSUMPTION tags: no enforcement built |
| 0013 | Operationalizing Naur Theory-Building | Superseded by 0017 | Theory-building rituals: folded into 0017's lighter form |
| 0014 | Pensive Review-Skill Consolidation | Accepted (sequencing only) | 9 review skills, 5 sharing a verdict scaffold. Consolidation sequenced, not done |
| 0015 | Over-Built Orchestrator Skill Simplification | Accepted (data-collection phase) | Collect 30 days of usage data before simplifying over-built skills |
| 0016 | Wire-or-Archive for Three Orphan Skills | Accepted (decisions recorded) | Orphans judged on demand signal, wiring cost, and reference value |
| 0017 | Decisions on Confidence-Tagging and Theory-Building | Accepted (2026-06-18) | No enforcement mechanisms and voluntary use. Supersedes 0012 and 0013 |
| 0018 | Reuse memory-palace's Graph for the Tome Research Engine | Accepted | Tome builds on the existing graph instead of a second one |
| 0019 | Retire docs/superpowers/ and Record Its Shipped Design Decisions | Accepted | The design folder became ADR text; the folder is gone |
| 0020 | Detect a Thin Field with Positive Controls, Not Overlap Estimation | Accepted | Frontier detection uses positive controls, not overlap math |
| 0021 | PR Descriptions Carry Six Dimensions in Two Registers | Accepted (2026-08-12) | Six dimensions, but only some earn a heading |
| 0022 | The Autonomous Loop Continues by Riding the Stop Hook | Accepted, with a named open problem (2026-08-23) | Stop-hook re-injection is the loop. Cost bounded by stall detection; the reliance stays open |
| You actually need | Use instead |
|---|---|
| How a change is classified, gated, and reviewed | night-market-change-control |
| The full story of a past incident or revert | night-market-failure-archaeology |
| Commands to run tests, lint, release, publish | night-market-operations |
| Every config file, default, and env var | night-market-config-catalog |
| Plugin/skill/hook mechanics in the abstract | claude-code-plugin-reference |
| Triage for a live failure | night-market-debugging-playbook |
054e2679 and 29961cd2, and both
commits resolve via git log --oneline -1 <hash>.ls each path in the second column from the repo root with
zero errors.ls docs/adr/*.md | wc -l (17 as of 2026-07-02).rg -m1 '"version"' .claude-plugin/marketplace.json matches
the version in every plugin's plugin.json you spot-check.Compiled 2026-07-02 against repo v1.9.15 on branch
discussions-fix-1.9.14. Skill/plugin counts drift: 198 SKILL.md files
under plugins/ and 23 marketplace plugins at compile time.
Re-verify volatile facts:
# ADR count and statuses
rg -m1 -n "Status" docs/adr/*.md
# Ecosystem version source of truth
rg -m1 '"version"' .claude-plugin/marketplace.json
# Discovery budget numbers (2%, 16k fallback; the ADR still says 60k)
rg -n "16,000|60,000" docs/adr/0004-skill-description-budget-optimization.md
# Enforced validator ceiling (90,000 as of 2026-07-03)
rg -n "DEFAULT_BUDGET" plugins/abstract/scripts/validate_budget.py
# Who orchestrates the gate federation today
rg -n "orchestrat" docs/quality-gates.md
# mdbook still unpinned?
rg -n "mdbook-version" .github/workflows/deploy-book.yml
# Ratchet baselines still present
ls scripts/skill_graph_baseline.json scripts/skill_exit_criteria_baseline.json
# Plugin and skill counts
python3 -c "import json;print(len(json.load(open('.claude-plugin/marketplace.json'))['plugins']))"
find plugins -name SKILL.md | wc -l© athola, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/night-market-architecture-contract of athola/claude-night-market.
Open the folder on GitHubat commit 9f3eb00
Night Market Architecture Contract next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Night Market Architecture Contract this skillathola/claude-night-market | 341 | — | ~4.8k | Automated safety check: Pass | MIT | |
| Code Review ChecklistshareAI-lab/learn-claude-code | 78k | 4 repos | ~1.1k | Automated safety check: Pass | MIT | |
| Minimizing Ty Ecosystem Changesastral-sh/ruff | 50k | — | ~4.6k | Automated safety check: Pass | MIT | |
| Merge Dependabot PRsonyx-dot-app/onyx | 32k | 1 repos | ~2.2k | Automated safety check: Pass | MIT | |
| Summarise Ecosystem Resultsastral-sh/ruff | 50k | — | ~2.2k | Automated safety check: Pass | MIT | |
| Senior Architect Toolkitmaslennikov-ig/claude-code-orchestrator-kit | 260 | 8 repos | ~1.2k | Automated safety check: Notes | Custom licence |
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
astral-sh/ruff
A skill your agent uses when a user says "minimize this ty ecosystem change", "reproduce this ecosystem result", "investigate a primer difference", "investigate a mypyprimer difference"…
onyx-dot-app/onyx
Triages and lands a batch of open Dependabot PRs in the Onyx repo, where main is gated exclusively by GitHub's merge queue: approves and enqueues green PRs, closes superseded duplicates, fixes…
astral-sh/ruff
A skill your agent uses when a user says "summarise ecosystem results", "summarize this ty ecosystem report", "what changed in this ecosystem run?", or asks to summarise or summarize ty ecosystem…
maslennikov-ig/claude-code-orchestrator-kit
Comprehensive software architecture skill for designing scalable, maintainable systems using ReactJS, NextJS, NodeJS, Express, React Native, Swift, Kotlin…
kedro-org/kedro
Run Kedro's local lint / format / type-check / tests on changed files (uses the project's pre-commit hooks, ruff, mypy, pytest, lint-imports, detect-secrets, Make targets — in the right venv), or…
athola/claude-night-market
Run and interpret repo diagnostic scripts (ratchets, validators, token stats).
athola/claude-night-market
Evaluate Claude skill quality through auditing. An agent skill from athola/claude-night-market.
athola/claude-night-market
Coordinates Claude agent teams via filesystem protocol. An agent skill from athola/claude-night-market.
athola/claude-night-market
Delegates execution to eight CLIs (Gemini, Qwen, MiniMax, GLM, Muse, Codex, OpenCode, Glimmer).
athola/claude-night-market
Guide minimal code via a decision ladder with full safety, edge, and negative-case coverage.
athola/claude-night-market
Build a project skill library in .claude/skills/ via discovery, parallel authoring, and review.
Works with
Categories
States load-bearing decisions, invariants, and weak points. An agent skill from athola/claude-night-market. Night Market Architecture Contract is an agent skill from athola/claude-night-market. States load-bearing decisions, invariants, and weak points.
Night Market Architecture Contract fits situations like: judging a design change; use night-market-change-control.
Run `npx skills add athola/claude-night-market --skill night-market-architecture-contract -a claude-code`. Or copy the skill folder (.claude/skills/night-market-architecture-contract in athola/claude-night-market) into .claude/skills/night-market-architecture-contract in your project. Claude Code loads it when a task matches its description.
Run `npx skills add athola/claude-night-market --skill night-market-architecture-contract -a codex`. Or copy the skill folder (.claude/skills/night-market-architecture-contract in athola/claude-night-market) into .agents/skills/night-market-architecture-contract in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add athola/claude-night-market --skill night-market-architecture-contract -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/night-market-architecture-contract, .gemini/skills/night-market-architecture-contract, .github/skills/night-market-architecture-contract and .opencode/skills/night-market-architecture-contract in your project.
Going by SKILL.md and its folder, Night Market Architecture Contract needs the command-line tools its instructions call (rg, git, gh, uv, python3 and make). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use git, gh and uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Night Market Architecture Contract is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.8k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Night Market Architecture Contract: Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Minimizing Ty Ecosystem Changes (astral-sh/ruff, 50k stars), Merge Dependabot PRs (onyx-dot-app/onyx, 32k stars) and Summarise Ecosystem Results (astral-sh/ruff, 50k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
athola (a GitHub user) maintains it in athola/claude-night-market, which has 341 GitHub stars. The repository holds 152 skills in this directory. The repository was last updated on October 9, 2026.
Source: athola/claude-night-market on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.