Agent skill

Skill Governance

by daymade in daymade/claude-code-skills

Governs the Claude Code/Codex Skill surface: reconciles source/install/catalog-visibility drift without losing cold capability.

MITAuto-check passed

Install Skill Governance

skills CLI
$ npx skills add daymade/claude-code-skills --skill skill-governance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install daymade/claude-code-skills skill-governance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/daymade/claude-code-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/daymade-skill/skill-governance .claude/skills/skill-governance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
skill-governance
GitHub stars
1.4k
Token cost
~2k tokens
SKILL.md length
972 words
Files
10 (incl. scripts, references)
Skills in repo
103
Repo updated
First seen
Licence
MIT

At a glance

Governs the Claude Code/Codex Skill surface: reconciles source/install/catalog-visibility drift without losing cold capability.

  • Works in 5 steps: Canonical source — where owned behavior… → Installed inventory — bundles and… → Discovery policy — what Claude or Codex… → …
  • Users ask how many Skills load
  • SKILL.md covers Required outcome contract, System model, Authority order and Route the request, plus 5 more sections
  • Runs Python scripts from its folder; calls python3, codex and claude

What it does

Skill Governance is an agent skill from daymade/claude-code-skills. Governs the Claude Code/Codex Skill surface: reconciles source/install/catalog-visibility drift without losing cold capability. Use when users ask how many Skills load, why the catalog is truncated, want routers visible while other bundles stay cold, or need duplicate/superseded-Skill or old-cache cleanup. Not for building a marketplace manifest (use marketplace-dev) or repo audits (use marketplace-health-check).

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 12 other files, including scripts and reference files (for example `references/skill-surface-governance.md`, `scripts/audit_claude_skill_surface.py` and `scripts/audit_codex_skill_surface.py`).

The repository describes itself as: Professional Claude Code skills marketplace featuring production-ready skills for enhanced development workflows. The licence is MIT.

When your agent uses it

  • Users ask how many Skills load
  • Why the catalog is truncated
  • Want routers visible while other bundles stay cold
  • Need duplicate/superseded-Skill

Example prompts

  • “Use the skill-governance skill to govern the Claude Code/Codex Skill surface: reconciles source/install/catalog-visibility drift without losing cold…”
  • “/skill-governance”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Canonical source — where owned behavior may be edited.
  2. Installed inventory — bundles and versions that exist on disk.
  3. Discovery policy — what Claude or Codex may discover.
  4. Model-visible catalog — metadata in a fresh model prompt.
  5. Runtime resources — hidden scripts, references, and assets a router still

What it can do on your machine

Read from SKILL.md and the folder at commit 872127b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 4 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3
    • codex
    • claude

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Skill Governance loads about 2k tokens when it runs, and up to ~9.2k if it reads all its reference files. Until then it costs about 108 tokens; SKILL.md has 972 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~108
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~9.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from daymade/claude-code-skills at commit 872127b, republished under its MIT licence (© daymade). 972 words, ~2,021 tokens.

Download SKILL.mdSave it as .claude/skills/skill-governance/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.
name
skill-governance
description
Governs the Claude Code/Codex Skill surface: reconciles source/install/catalog-visibility drift without losing cold capability. Use when users ask how many Skills load, why the catalog is truncated, want routers visible while other bundles stay cold, or need duplicate/superseded-Skill or old-cache cleanup. Not for building a marketplace manifest (use marketplace-dev) or repo audits (use marketplace-health-check).

Skill Governance

Govern the Skill surface the user actually experiences: the intended hot or router entries are fully visible in a fresh host, cold capabilities remain reachable, editable behavior has one canonical owner, and every retirement is recoverable. A smaller directory count is not the outcome.

Required outcome contract

Before acting, state in one sentence:

  • which entries or routers must be model-visible;
  • which capabilities must remain available cold;
  • which layer the user authorized changing;
  • what fresh-host evidence will prove success.

If the request is only “how many / what is loaded / why”, stay read-only.

System model

Never collapse these layers into one:

  1. Canonical source — where owned behavior may be edited.
  2. Installed inventory — bundles and versions that exist on disk.
  3. Discovery policy — what Claude or Codex may discover.
  4. Model-visible catalog — metadata in a fresh model prompt.
  5. Runtime resources — hidden scripts, references, and assets a router still needs.

Installed does not mean active; active does not prove visible; visible does not prove usable. Counts and byte totals are diagnostic values only.

Authority order

Use current runtime truth, not remembered conventions:

  • owned source repos and their manifests for editable Skill behavior;
  • claude plugin ... --json for current Claude marketplace/install state;
  • the explicit source-sync activation manifest for managed Daymade links;
  • ~/.agents/skills as Codex's current user Skill root;
  • exact-path ~/.codex/config.toml policy for Codex discovery disables;
  • codex debug prompt-input for the actual fresh Codex catalog;
  • the installed vendor bundle for third-party cold resources.

~/.codex/skills is legacy/system compatibility unless a current local contract explicitly assigns it another role. Never move third-party inventory into an owned-source activation manifest just to make ownership look complete.

Route the request

Read the named section of references/skill-surface-governance.md completely before using that workflow.

RequestRead and use
Explicit delivery contract; verify source owner, registration and installed route§16, then requested fresh-host gate in §14
What Codex really loads; count, truncation, duplicate identity, missing router§3–4, then §11
Reconcile owned source links or ~/.agents/skills activation§2–5, then §11
Keep gstack/Lark/IMA/UiPath or another bundle cold behind a router§2–4, §6, then §11
Claude marketplace/plugin source or installed-state drift§2–3, §7, then §11
Old cache versions§2 and §7 “Exceptional manual cache repair”
Standalone plugins superseded by a suite§7–8, then §11
Project .claude/skills vs .agents/skills drift§9, then §11
Retire loose or duplicate Skill directories§2–3, §10–11
Decide which Skills stay model-visible vs user-invocable-only§15, then §11

Fast read-only Codex audit

For a newly registered Skill whose local use is part of the delivery, run the target-name checks in references/skill-surface-governance.md §14 before calling it ready. This covers Claude's fresh command catalog and Codex's fresh prompt. The name must come from the requested delivery, not only the active whitelist.

Run from this Skill bundle:

bash
python3 scripts/audit_codex_skill_surface.py --json

Only add policy the user or activation SSOT actually declared:

bash
python3 scripts/audit_codex_skill_surface.py \
  --require-visible gstack-router \
  --json

The script compares codex debug prompt-input with the complete metadata parsed by Codex's own app-server skills/list, plus exact activation/discovery policy. Exit 0 is clean, 1 is pressure or drift to classify, and 2 means the evidence is invalid. It is read-only. Do not convert exit 1 into automatic pruning.

For a project's dual roots:

bash
python3 scripts/audit_project_skill_roots.py <project-root> --json

That audit pairs direct child bundles by frontmatter name, recognizes only its explicit fail-visible compatibility-router contract, and distinguishes shared targets, identical copies, real drift, and invalid state.

Show full SKILL.md (430 more words)Show less

Non-negotiable safety boundaries

  • Drift checks are read-only. Config edits, link sync, installs, uninstalls, moves, cache repair, and marketplace source changes require authorization.
  • Preserve Claude plugin scope. Verify replacements before retiring old identities.
  • Never use direct cache copying as installation or source sync.
  • Do not enforce “one cache version”. Current Claude Code owns orphan-version grace for running sessions; manual cache removal is exceptional repair only.
  • Do not use blind marketplace remove-then-add. Removing the last scoped marketplace can uninstall its plugins.
  • Read every candidate's unique instructions, scripts, references, and assets before calling it redundant. Old or short does not mean valueless.
  • Decide model-visible vs user-invocable-only per Skill from usage evidence (§15), never from its description or install location alone.
  • Keep cold third-party resources installed; hide only their exact discovery paths, then prove the router still resolves one representative capability.
  • Retire by recoverable move plus file/executable/hash manifest, never by rm -rf.
  • Existing sessions retain startup metadata. Restart before treating the interactive catalog as verification.

Source and activation ownership

For Daymade source-backed Codex activation, route to the current claude-switch-models-setup dry-run/apply workflow. Its explicit codex-active-skills.json owns only links created from declared source marketplaces. Do not reimplement its collision, symlink, or pruning logic here.

For Claude plugins, inspect current marketplace and install JSON, update or reinstall through the official CLI at the original scope, and independently read back the result. Treat cache folders as derived runtime artifacts.

For suite topology changes, use marketplace-dev to edit the source manifest; use this Skill only to reconcile already-landed migrations on the current host.

Read-only delivery contract audit

For an explicit delivery review, read §16 and run scripts/audit_skill_delivery.py <skill-path> --delivery-contract <private-contract.json> --json. It delegates source ownership to skill-creator; runtime visibility and original-requirement fidelity remain separate evidence. A source error blocks delivery even if the Skill can run.

Definition of done

All applicable claims must be proven independently:

  • canonical source and current owner are named;
  • selected direct entries/routers appear in a fresh prompt under the requested discovery policy; report description truncation separately, including when the installation-only target gate passes;
  • entries intended cold are absent from that catalog;
  • one representative cold capability still resolves and works;
  • source-backed links or Claude installs read back with the intended identity, source/version, and scope;
  • any retired bundle and its recovery manifest still exist;
  • unresolved ownership, host-version behavior, or deliberately retained exceptions are explicit.

Use the reference's task-behavior check only when actual task execution is part of delivery; catalog visibility alone does not prove that result.

Stop there. Do not create a new hook, manifest, report layer, or cleanup project unless the requested outcome still lacks evidence.

© daymade, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 9 other files (scripts, references) in daymade-skill/skill-governance of daymade/claude-code-skills.

  • SKILL.md
  • references/skill-surface-governance.md
  • scripts/audit_claude_skill_surface.py
  • scripts/audit_codex_skill_surface.py
  • scripts/audit_project_skill_roots.py
  • scripts/audit_skill_delivery.py
  • tests/test_audit_claude_skill_surface.py
  • tests/test_audit_codex_skill_surface.py
  • tests/test_audit_project_skill_roots.py
  • tests/test_audit_skill_delivery.py

Open the folder on GitHubat commit 872127b

Compare with similar skills

Skill Governance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Skill Governance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Skill Governance this skilldaymade/claude-code-skills1.4k—~2kAutomated safety check: PassMIT
Workspace Surface Auditaffaan-m/ECC276k3 repos~1.3kAutomated safety check: NotesMIT
Board Governancesickn33/agentic-awesome-skills47k1 repos~4.1kAutomated safety check: PassMIT
Agent Governancegithub/awesome-copilot40k2 repos~4.6kAutomated safety check: PassMIT
Surfacesrid/emanote963—~1.5kAutomated safety check: PassCustom licence
Model Registry Governancesickn33/agentic-awesome-skills47k2 repos~3.9kAutomated safety check: PassMIT

Similar skills

  • Audit the active repo, MCP servers, plugins, connectors, env surfaces, and harness setup, then recommend the highest-value ECC-native skills, hooks, agents, and operator workflows.

    276k GitHub starsUsed in 3 repos~1.3k tokens
    Agent WorkflowsAuto-check: notes
  • Board Governance

    sickn33/agentic-awesome-skills

    Board and governance register: meeting date, agenda, decision, resolution number, vote result, action owner and due date.

    47k GitHub starsUsed in 1 repo~4.1k tokens
    Auto-check passed
  • Agent Governance

    github/awesome-copilot

    Official

    Patterns and techniques for adding governance, safety, and trust controls to AI agent systems.

    40k GitHub starsUsed in 2 repos~4.6k tokens
    AI & LLM EngineeringAuto-check passed
  • Surface

    srid/emanote

    How a downstream app consumes the shared @kolu/surface stack (@kolu/surface · surface-app · surface-nix-host · surface-mcp) — declaring a typed reactive surface, serving it, consuming it (SolidJS…

    963 GitHub stars~1.5k tokensUpdated 2 mo ago
    Auto-check passed
  • Model Registry Governance

    sickn33/agentic-awesome-skills

    Establish model registry standards, governance controls, metadata schemas, approvals, and lifecycle policies for enterprise AI deployments.

    47k GitHub starsUsed in 2 repos~3.9k tokens
    DevOps & CloudAuto-check passed
  • Protect MCP Governance

    sickn33/agentic-awesome-skills

    Agent governance skill for MCP tool calls — Cedar policy authoring, shadow-to-enforce rollout, and Ed25519 receipt verification.

    47k GitHub starsUsed in 2 repos~2.3k tokens
    Agent WorkflowsAuto-check passed

More from daymade/claude-code-skills

All 103 skills in this repo
  • Video Comparer

    daymade/claude-code-skills

    This skill should be used when comparing two videos to analyze compression results or quality differences.

    1.4k GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check: notes
  • CLI Demo Generator

    daymade/claude-code-skills

    Generates professional animated CLI demos as GIFs using VHS terminal recordings.

    1.4k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Doc To Markdown

    daymade/claude-code-skills

    Converts DOCX/PDF/PPTX and saved HTML/HTM to high-quality Markdown with automatic post-processing.

    1.4k GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Interaction Design Board

    daymade/claude-code-skills

    Generates several distinct, clickable HTML interaction prototypes for one product surface into a Design Board and collects selection/remix feedback before implementation.

    1.4k GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Auto Repo Setup

    daymade/claude-code-skills

    Diagnoses and repairs repository setup and guarded Git workflows for Claude Code or Codex — environment repair, startup sync, hook auditing, collaborator handoff.

    1.4k GitHub stars~2.8k tokensUpdated today
    Auto-check: notes
  • Bigdata Skill

    daymade/claude-code-skills

    Pulls Bigdata.com (RavenPack) financial and news data via the official bigdata-client SDK and /v1/ REST endpoints — structured financials, prices, analyst estimates, entity-sentiment series…

    1.4k GitHub stars~3.7k tokensUpdated today
    Auto-check passed

Questions about Skill Governance

What does Skill Governance do?

Governs the Claude Code/Codex Skill surface: reconciles source/install/catalog-visibility drift without losing cold capability. Skill Governance is an agent skill from daymade/claude-code-skills. Governs the Claude Code/Codex Skill surface: reconciles source/install/catalog-visibility drift without losing cold capability.

When should I use Skill Governance?

Skill Governance fits situations like: users ask how many Skills load; why the catalog is truncated; want routers visible while other bundles stay cold; need duplicate/superseded-Skill.

How do I install Skill Governance in Claude Code?

Run `npx skills add daymade/claude-code-skills --skill skill-governance -a claude-code`. Or copy the skill folder (daymade-skill/skill-governance in daymade/claude-code-skills) into .claude/skills/skill-governance in your project. Claude Code loads it when a task matches its description.

How do I install Skill Governance in Codex?

Run `npx skills add daymade/claude-code-skills --skill skill-governance -a codex`. Or copy the skill folder (daymade-skill/skill-governance in daymade/claude-code-skills) into .agents/skills/skill-governance in your project. Codex loads it when a task matches its description.

Can I use Skill Governance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add daymade/claude-code-skills --skill skill-governance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/skill-governance, .gemini/skills/skill-governance, .github/skills/skill-governance and .opencode/skills/skill-governance in your project.

What does Skill Governance need to run?

Going by SKILL.md and its folder, Skill Governance needs Python for the scripts in its folder and the command-line tools its instructions call (python3, codex and claude). Our summary lists: Python 3.

Does Skill Governance access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Skill Governance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Skill Governance use?

Skill Governance is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Skill Governance use?

About 2k tokens (SKILL.md is roughly 8.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 7.1k tokens, read only when the agent opens those files.

What are the alternatives to Skill Governance?

Skills that share tags, products or a category with Skill Governance: Workspace Surface Audit (affaan-m/ECC, 276k stars), Board Governance (sickn33/agentic-awesome-skills, 47k stars), Agent Governance (github/awesome-copilot, 40k stars) and Surface (srid/emanote, 963 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Skill Governance?

daymade (a GitHub user) maintains it in daymade/claude-code-skills, which has 1,447 GitHub stars. The repository holds 103 skills in this directory. The repository was last updated on October 9, 2026.

Source: daymade/claude-code-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.