Agent skill

Corvus Bytes To Bytes

by corvus-dotnet in corvus-dotnet/Corvus.JsonSchema

Eliminate hand-rolled POCO record<-document string seams — types/paths that materialize a managed string (or List<string/Dictionary) between a bytes SOURCE (a parsed UTF-8 body, a DB column, a…

Apache-2.0Auto-check passed

Install Corvus Bytes To Bytes

skills CLI
$ npx skills add corvus-dotnet/Corvus.JsonSchema --skill corvus-bytes-to-bytes -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install corvus-dotnet/Corvus.JsonSchema corvus-bytes-to-bytes --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/corvus-dotnet/Corvus.JsonSchema.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/corvus-bytes-to-bytes .claude/skills/corvus-bytes-to-bytes && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
corvus-bytes-to-bytes
GitHub stars
199
Token cost
~3k tokens
SKILL.md length
1,114 words
Files
1
Skills in repo
26
Repo updated
First seen
Licence
Apache-2.0

At a glance

Eliminate hand-rolled POCO record<-document string seams — types/paths that materialize a managed string (or List<string/Dictionary) between a bytes SOURCE (a parsed UTF-8 body, a DB column, a…

  • : deciding whether a string on a hot/warm path is justified
  • SKILL.md covers The genuine-leaf proof (run…, The fix recipe — bytes-native…, Walking a holder's UTF-8… and Pre-commit self-audit…, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Converting a bytes-string-bytes u-turn to bytes-to-bytes

What it does

Corvus Bytes To Bytes is an agent skill from corvus-dotnet/Corvus.JsonSchema. Eliminate hand-rolled POCO record<-document string seams — types/paths that materialize a managed string (or List<string/Dictionary) between a bytes SOURCE (a parsed UTF-8 body, a DB column, a directory/HTTP response) and a bytes SINK (a serialized JSON document, a generated model, a SecurityTagSet, a DB write). The fix recipe is bytes-native default + opt-in string extensibility, plus a decision procedure for telling a genuine string leaf from work you are avoiding. USE FOR: deciding whether a string on a…

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Support for Json Schema validation and entity generation. The licence is Apache-2.0.

When your agent uses it

  • : deciding whether a string on a hot/warm path is justified
  • Converting a bytes-string-bytes u-turn to bytes-to-bytes
  • Reviewing your own diff for hidden string materializations before committing
  • Building an identity/tag set from a UTF-8 source

Example prompts

  • “/corvus-bytes-to-bytes”

What it can do on your machine

Read from SKILL.md and the folder at commit b9e3040. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are csharp).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Corvus Bytes To Bytes loads about 3k tokens when it runs. Until then it costs about 256 tokens; SKILL.md has 1,114 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~256
When it runs · the whole SKILL.md, loaded when a task matches
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from corvus-dotnet/Corvus.JsonSchema at commit b9e3040, republished under its Apache-2.0 licence (© corvus-dotnet). 1,114 words, ~2,968 tokens.

Download SKILL.mdSave it as .claude/skills/corvus-bytes-to-bytes/SKILL.md (or your agent's skills folder).
name
corvus-bytes-to-bytes
description
Eliminate hand-rolled POCO record<->document string seams — types/paths that materialize a managed string (or List<string>/Dictionary) between a bytes SOURCE (a parsed UTF-8 body, a DB column, a directory/HTTP response) and a bytes SINK (a serialized JSON document, a generated model, a SecurityTagSet, a DB write). The fix recipe is bytes-native default + opt-in string extensibility, plus a decision procedure for telling a genuine string leaf from work you are avoiding. USE FOR: deciding whether a string on a hot/warm path is justified; converting a bytes->string->bytes u-turn to bytes-to-bytes; reviewing your own diff for hidden string materializations before committing; building an identity/tag set from a UTF-8 source. DO NOT USE FOR: the mechanics of building a generated model from spans without a closure (use corvus-builder-context-threading), raw pooling/stackalloc patterns (use corvus-buffer-and-pooling), constructing models from native values (use corvus-typed-model-construction).

Bytes-to-bytes: killing record<->document string seams

A record<->document string seam is the most expensive allocation anti-pattern in this codebase and the one most often re-introduced. It is a value that arrives as bytes, is materialized into a managed string (or List<string> / Dictionary<string,…> / a per-row POCO), and is then written back out as bytes — a u-turn through the managed heap. Both ends are bytes; the string is pure overhead, plus a closure if a non-static builder lambda is involved.

The cost is real and measured: a per-row row-security scan was 25.78 KB -> 1.56 KB (0.06x) once the filter walked the persisted UTF-8 instead of SecurityTagSet.ToList() per row; a directory grantee projection was 5.88 KB -> 2.01 KB (0.34x) once value/label flowed as spans instead of GetString.

The genuine-leaf proof (run this BEFORE you write a string)

The words "genuine leaf", "marginal", "admin-rare", "low-frequency", "pragmatic", "good enough", "consistency win", "too fragile", "edge case", "one X's worth" are red flags: they are usually a justification reached for first, to license skipping the bytes mechanism. Before any of them excuses a managed string on a warm/hot path, write a two-ended trace and check both ends:

Source endDestination end
String IS the leaf only ifa string-typed external API: ClaimsPrincipal claims, the Novell LDAP client (LdapAttribute.StringValue), a BsonValue.AsString (the driver pre-materialized it)a string-typed sink: an HttpRequestMessage URI, an LDAP filter, an HTTP Authorization header, a string-keyed store (store.GetAsync(string)), a human-facing audit/error message

If EITHER end is bytes/spans and a documented mechanism exists, it is NOT a leaf — it is work you are avoiding. A "constructed" value (e.g. first + " " + last, a prefix + dimension key) is never a leaf: assemble it into a pooled/stack UTF-8 buffer, not a string. The mechanism always exists:

NeedMechanismSkill
Build a tag set from UTF-8SecurityTagSet.Build + IdentityBuilder.Add(span)this skill
Build a key prefix + dimensionstackalloc/ArrayPool + Encoding.UTF8.GetBytes(prefix, key)corvus-buffer-and-pooling
Write UTF-8 into a generated model, no closureT.Build<TContext> / CreateBuilder<TContext>corvus-builder-context-threading
Compare UTF-8 vs a fixed stringpre-encode the string to u8/byte[] once, SequenceEqualthis skill
Re-transcode a holder's bytesUtf8JsonWriter -> TagSet.CopyFromJsonArraycorvus-mutable-documents
When the excuse is "too fragile" / "edge case" (a self-imposed invariant)

Sometimes the string (or the List + per-item concat that builds it) isn't defended as a leaf but as too risky to remove — "the sort has a '-' vs '.' edge case needing a careful comparer", "I'd have to reproduce the exact output bytes", "it's only one row's worth". That difficulty is almost always self-imposed: it comes from preserving the existing code's incidental output shape (an entry/element order, a container layout, an insertion order), not from the task itself. Before you skip it: (1) name the exact invariant making it fragile; (2) read the consumer — the reader, the sink, the comparer — and check whether it actually requires that invariant. An order-independent reader (finds entries by name/key, not position), a sink that re-normalises/re-canonicalises, or a content-addressed-by-hash artifact does not. When no consumer requires it, the invariant is incidental — drop it and the clean low-alloc form falls out. Example: WorkflowPackage.PackPooled sorts sources by key in a pooled scratch array and emits a fixed bucket order (workflow, sources, metadata), writing each entry name as UTF-8 directly ("sources/"u8 + key + ".json"u8, length back-patched) — instead of reproducing the old full-name sort, which removed the List + per-source name string outright (PackCanonicalPackage 0.73 -> 0.49 KB, scales per source). Treating incidental output shape as a contract is the anchoring-on-existing-code failure (deriving the replacement from what the old code happened to do) applied to behaviour instead of style.

Opaque tokens are a carrier seam too ("store-minted, so it stays a string" is a rationalization)

An opaque pagination/continuation token round-trips between two UTF-8 ends — emitted into a JSON response, carried back in the next JSON request (a CTJ JsonString) — so "it is store-minted, not domain data, so it stays a string" is a genuine-leaf rationalization: both ends are bytes. Encode it bytes-native with System.Buffers.Text.Base64Url (GetEncodedLength + EncodeToUtf8 straight into the destination; GetMaxDecodedLength + DecodeFromUtf8 from the request's pageToken.GetUtf8String().Span) — no EncodeToString/DecodeFromChars char detour, and no per-part ToString()/concat/GetBytes (assemble the key into a stackalloc/ArrayPool UTF-8 buffer with a separator byte). The token must survive into the response, but owned ≠ GC: pool it in a disposable carrier rather than minting a string (the only necessarily-GC form). The cross-root request→store JsonString is bridged with JsonString.From(...) (free rewrap). The lifetime that governs emitting it is the deferred-body rule — see corvus-ctj-handler-implementation.

Show full SKILL.md (393 more words)Show less

The fix recipe — bytes-native default + opt-in string

Mirror IdentityBuilder.Add(ReadOnlySpan<byte> key, ReadOnlySpan<byte> value) (the fast path) vs Add(ReadOnlySpan<byte> key, string value) (the opt-in for a value a deployment genuinely computed through a string API). The bytes path is the path; the string path is the explicit, documented exception — never the default.

csharp
// The bytes-native seam every adapter/handler builds an identity through. The value span is the
// unescaped UTF-8 the source already holds (reader.GetUtf8String().Span); no managed string per tag.
SecurityTagSet identity = SecurityTagSet.Build(
    in state,
    static (ref IdentityBuilder builder, in TState s) =>
    {
        builder.Add("sys:tenant"u8, s.TenantSpan);   // span path
        builder.Add("sys:sub"u8, s.SubSpan);
    });

A deferred holder (SecurityTagSet, TagSet) is the bytes form. Read it as ((JsonElement)x).GetUtf8String() (a ref struct; cannot cross an await) or .TakeOwnership(out byte[]? rented) for owned ReadOnlyMemory<byte> that can. Transcode to a string ONLY at the genuine leaf (e.g. Encoding.UTF8.GetString(value.Span) for a string-keyed store key).

Dual constructor for an extension-point contract

When a type is a deployment-authored extension point (e.g. ResolvedPrincipal, returned by an IDirectoryIdentityMapper), give it BOTH constructors — span for the built-in fast path, string for mapper ergonomics — and decode on demand for string consumers:

csharp
public readonly struct ResolvedPrincipal
{
    private readonly ReadOnlyMemory<byte> value;   // owned UTF-8

    // Span ctor — the built-in adapters' bytes-to-bytes fast path (copies the transient span to owned).
    public ResolvedPrincipal(GranteeKind kind, ReadOnlySpan<byte> value, ReadOnlySpan<byte> label, bool hasLabel, SecurityTagSet identity) { /* value.ToArray() */ }
    // String ctor — the ergonomic path a deployment mapper (or LDAP, a genuine string leaf) uses.
    public ResolvedPrincipal(GranteeKind kind, string value, string? label, SecurityTagSet identity) { /* Encoding.UTF8.GetBytes(value) */ }

    public ReadOnlyMemory<byte> ValueMemory => this.value;                 // server: bytes-to-bytes into the response
    public string Value => Encoding.UTF8.GetString(this.value.Span);       // CLI/tests: decode on demand
}
Constructed value -> pooled buffer (never a string)
csharp
// A "first last" display name has no single source span — assemble it into a REUSED pooled buffer
// (rented once outside the row loop, grown on demand), not Encoding.UTF8.GetString(...) + string concat.
int needed = first.Length + 1 + last.Length;
if (labelBuffer is null || labelBuffer.Length < needed)
{
    if (labelBuffer is not null) { ArrayPool<byte>.Shared.Return(labelBuffer); }
    labelBuffer = ArrayPool<byte>.Shared.Rent(needed);
}
first.CopyTo(labelBuffer);
labelBuffer[first.Length] = (byte)' ';
last.CopyTo(labelBuffer.AsSpan(first.Length + 1));
ReadOnlySpan<byte> labelSpan = labelBuffer.AsSpan(0, needed);   // the consumer copies it before the next row reuses the buffer

Walking a holder's UTF-8 instead of materializing it

When a path must evaluate over a tag set (not just copy it), parse the persisted UTF-8 once into a pooled scratch + slice table (SecurityTagSpanSort.Parse), compare on spans, and pre-encode the fixed side once. The string evaluator becomes a thin adapter that delegates via FromTags, so the existing tests lock the bytes evaluator's semantics. See SecurityRule.EvaluateAll(in SecurityTagSet, in Utf8ClaimSet) and SecurityRuleEvaluation.cs. Ordinal UTF-8 SequenceEqual IS ordinal string equality for the same code points.

Pre-commit self-audit (mandatory — see copilot-instructions.md pre-commit gate)

Before committing, scan your own diff and report each:

  • New managed string / List<string> / Dictionary on a path where bytes are available? -> apply the proof; fix or flag.
  • New non-static builder lambda (a closure) where a static + TContext form exists? -> corvus-builder-context-threading.
  • Reflection-based dispatch where a virtual/span seam exists? -> remove it.
  • Any work deferred / skipped / relocated? -> surface it under Decisions & deferrals + a task, never a buried comment.
  • Did a fix MOVE a cost (a transcode/alloc) elsewhere rather than remove it? -> state the before/after file:line.

Prove every warm path with a BenchmarkDotNet [MemoryDiagnoser] benchmark (baseline old vs new) — see SecurityFilterScanBenchmarks / GranteeProjectionBenchmarks for the shape. "Admin-rare" is not a licence to allocate.

Cross-References

  • corvus-builder-context-threading — write UTF-8 spans into a generated model with no closure (the Build<TContext> form).
  • corvus-buffer-and-pooling — the stackalloc/ArrayPool/thread-local pooling the span paths rent from.
  • corvus-typed-model-construction — constructing generated models from native values (the non-span common case).
  • ref-struct-delegates — why the build callbacks are named ref struct delegates, not Func<>/Action<>.
  • corvus-parsed-documents-and-memory — GetUtf8String() / TakeOwnership / the deferred-holder memory model.

© corvus-dotnet, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/corvus-bytes-to-bytes of corvus-dotnet/Corvus.JsonSchema.

Open the folder on GitHubat commit b9e3040

Compare with similar skills

Corvus Bytes To Bytes next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Corvus Bytes To Bytes compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Corvus Bytes To Bytes this skillcorvus-dotnet/Corvus.JsonSchema199—~3kAutomated safety check: PassApache-2.0
Recordingcodewhale-hq/Codewhale41k—~540Automated safety check: PassMIT
Architecture Decision Recordsaffaan-m/ECC275k4 repos~1.8kAutomated safety check: PassMIT
Architecture Decision Recordsaffaan-m/ECC275k1 repos~863Automated safety check: PassMIT
Architecture Decision Recordsaffaan-m/ECC275k—~1.1kAutomated safety check: PassMIT
Browser Recordruvnet/ruflo74k—~735Automated safety check: NotesMIT

Similar skills

  • Recording

    codewhale-hq/Codewhale

    Capture screenshots on registered computers, record on macOS or HarmonyOS, and manage saved captures.

    41k GitHub stars~540 tokensUpdated today
    Productivity & AutomationAuto-check passed
  • Capture architectural decisions as numbered ADR markdown files in docs/adr/ with context, alternatives considered, consequences, and an index README.

    275k GitHub starsUsed in 4 repos~1.8k tokens
    DevelopmentAuto-check passed
  • 在Claude Code会话期间,将做出的架构决策捕获为结构化的架构决策记录(ADR)。自动检测决策时刻,记录上下文、考虑的替代方案和理由。维护一个ADR日志,以便未来的开发人员理解代码库为何以当前方式构建。

    275k GitHub starsUsed in 1 repo~863 tokens
    DevelopmentAuto-check passed
  • コーディングセッション中にアーキテクチャ決定を構造化ADRとして記録し、自動的に決定の瞬間を検出し、コンテキスト、検討された代替案、根拠を記録します。今後の開発者がコードベースの形成理由を理解するためのADRログを維持します。

    275k GitHub stars~1.1k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Browser Record

    ruvnet/ruflo

    Open a named, traced browser session into an RVF cognitive container with a ruvector trajectory recording every action

    74k GitHub stars~735 tokensUpdated today
    Agent WorkflowsAuto-check: notes
  • Translation Strings

    thedaviddias/Front-End-Checklist

    A skill your agent uses when reviewing a codebase for internationalisation readiness, setting up an i18n library, or preparing strings for a new locale.

    74k GitHub stars~494 tokensUpdated yesterday
    Frontend & DesignAuto-check passed

More from corvus-dotnet/Corvus.JsonSchema

All 26 skills in this repo
  • Corvus Analyzers

    corvus-dotnet/Corvus.JsonSchema

    Understand and work with the Roslyn analyzers shipped with Corvus.Text.Json.

    199 GitHub stars~876 tokensUpdated today
    Auto-check passed
  • Corvus Benchmarks

    corvus-dotnet/Corvus.JsonSchema

    Run, interpret, and maintain BenchmarkDotNet benchmarks for JSON Schema validation and query languages.

    199 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Corvus Bowtie Testing

    corvus-dotnet/Corvus.JsonSchema

    Test Corvus.JsonSchema against the JSON Schema Test Suite using Bowtie, the cross-implementation meta-validator.

    199 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Corvus Buffer And Pooling

    corvus-dotnet/Corvus.JsonSchema

    Write allocation-efficient buffer code in Corvus.JsonSchema using the codebase's established three-tier pooling pattern: stackalloc → ArrayPool → ThreadStatic caches.

    199 GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Corvus Codegen

    corvus-dotnet/Corvus.JsonSchema

    Generate strongly-typed C from JSON Schema using the Roslyn source generator or the corvusjson CLI tool.

    199 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Corvus Ctj Handler Implementation

    corvus-dotnet/Corvus.JsonSchema

    Implement OpenAPI server handlers using Corvus.Text.Json generated types.

    199 GitHub stars~4.4k tokensUpdated today
    Auto-check passed

Questions about Corvus Bytes To Bytes

What does Corvus Bytes To Bytes do?

Eliminate hand-rolled POCO record<-document string seams — types/paths that materialize a managed string (or List<string/Dictionary) between a bytes SOURCE (a parsed UTF-8 body, a DB column, a…. JsonSchema. Eliminate hand-rolled POCO record<-document string seams — types/paths that materialize a managed string (or List<string/Dictionary) between a bytes SOURCE (a parsed UTF-8 body, a DB column, a directory/HTTP response) and a bytes SINK (a serialized JSON document, a generated model, a SecurityTagSet, a DB write).

When should I use Corvus Bytes To Bytes?

Corvus Bytes To Bytes fits situations like: : deciding whether a string on a hot/warm path is justified; converting a bytes-string-bytes u-turn to bytes-to-bytes; reviewing your own diff for hidden string materializations before committing; building an identity/tag set from a UTF-8 source.

How do I install Corvus Bytes To Bytes in Claude Code?

Run `npx skills add corvus-dotnet/Corvus.JsonSchema --skill corvus-bytes-to-bytes -a claude-code`. Or copy the skill folder (.github/skills/corvus-bytes-to-bytes in corvus-dotnet/Corvus.JsonSchema) into .claude/skills/corvus-bytes-to-bytes in your project. Claude Code loads it when a task matches its description.

How do I install Corvus Bytes To Bytes in Codex?

Run `npx skills add corvus-dotnet/Corvus.JsonSchema --skill corvus-bytes-to-bytes -a codex`. Or copy the skill folder (.github/skills/corvus-bytes-to-bytes in corvus-dotnet/Corvus.JsonSchema) into .agents/skills/corvus-bytes-to-bytes in your project. Codex loads it when a task matches its description.

Can I use Corvus Bytes To Bytes in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add corvus-dotnet/Corvus.JsonSchema --skill corvus-bytes-to-bytes -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/corvus-bytes-to-bytes, .gemini/skills/corvus-bytes-to-bytes, .github/skills/corvus-bytes-to-bytes and .opencode/skills/corvus-bytes-to-bytes in your project.

What does Corvus Bytes To Bytes need to run?

SKILL.md names no scripts, command-line tools or credentials: Corvus Bytes To Bytes is instructions for the agent only.

Does Corvus Bytes To Bytes access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Corvus Bytes To Bytes safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Corvus Bytes To Bytes use?

Corvus Bytes To Bytes is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Corvus Bytes To Bytes use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Corvus Bytes To Bytes?

Skills that share tags, products or a category with Corvus Bytes To Bytes: Recording (codewhale-hq/Codewhale, 41k stars), Architecture Decision Records (affaan-m/ECC, 275k stars), Architecture Decision Records (affaan-m/ECC, 275k stars) and Architecture Decision Records (affaan-m/ECC, 275k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Corvus Bytes To Bytes?

corvus-dotnet (a GitHub organization) maintains it in corvus-dotnet/Corvus.JsonSchema, which has 199 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on October 8, 2026.

Source: corvus-dotnet/Corvus.JsonSchema on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.