Workspace Surface Audit
affaan-m/ECC
Audit the active repo, MCP servers, plugins, connectors, env surfaces, and harness setup, then recommend the highest-value ECC-native skills, hooks, agents, and operator workflows.
Governs the Claude Code/Codex Skill surface: reconciles source/install/catalog-visibility drift without losing cold capability.
$ npx skills add daymade/claude-code-skills --skill skill-governance -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install daymade/claude-code-skills skill-governance --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/daymade/claude-code-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/daymade-skill/skill-governance .claude/skills/skill-governance && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "skill-governance" agent skill from https://github.com/daymade/claude-code-skills/tree/main/daymade-skill/skill-governance into .claude/skills/skill-governance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skill-governance", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/daymade/claude-code-skills/tree/main/daymade-skill/skill-governanceType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add daymade/claude-code-skills --skill skill-governance -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install daymade/claude-code-skills skill-governance --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/daymade/claude-code-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/daymade-skill/skill-governance .agents/skills/skill-governance && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "skill-governance" agent skill from https://github.com/daymade/claude-code-skills/tree/main/daymade-skill/skill-governance into .agents/skills/skill-governance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skill-governance", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add daymade/claude-code-skills --skill skill-governance -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install daymade/claude-code-skills skill-governance --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/daymade/claude-code-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/daymade-skill/skill-governance .cursor/skills/skill-governance && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "skill-governance" agent skill from https://github.com/daymade/claude-code-skills/tree/main/daymade-skill/skill-governance into .cursor/skills/skill-governance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skill-governance", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/daymade/claude-code-skills.git --path daymade-skill/skill-governance--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add daymade/claude-code-skills --skill skill-governance -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install daymade/claude-code-skills skill-governance --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/daymade/claude-code-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/daymade-skill/skill-governance .gemini/skills/skill-governance && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "skill-governance" agent skill from https://github.com/daymade/claude-code-skills/tree/main/daymade-skill/skill-governance into .gemini/skills/skill-governance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skill-governance", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install daymade/claude-code-skills skill-governanceInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add daymade/claude-code-skills --skill skill-governance -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/daymade/claude-code-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/daymade-skill/skill-governance .github/skills/skill-governance && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "skill-governance" agent skill from https://github.com/daymade/claude-code-skills/tree/main/daymade-skill/skill-governance into .github/skills/skill-governance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skill-governance", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add daymade/claude-code-skills --skill skill-governance -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install daymade/claude-code-skills skill-governance --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/daymade/claude-code-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/daymade-skill/skill-governance .opencode/skills/skill-governance && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "skill-governance" agent skill from https://github.com/daymade/claude-code-skills/tree/main/daymade-skill/skill-governance into .opencode/skills/skill-governance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skill-governance", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skill-governanceGoverns the Claude Code/Codex Skill surface: reconciles source/install/catalog-visibility drift without losing cold capability.
Skill Governance is an agent skill from daymade/claude-code-skills. Governs the Claude Code/Codex Skill surface: reconciles source/install/catalog-visibility drift without losing cold capability. Use when users ask how many Skills load, why the catalog is truncated, want routers visible while other bundles stay cold, or need duplicate/superseded-Skill or old-cache cleanup. Not for building a marketplace manifest (use marketplace-dev) or repo audits (use marketplace-health-check).
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 12 other files, including scripts and reference files (for example `references/skill-surface-governance.md`, `scripts/audit_claude_skill_surface.py` and `scripts/audit_codex_skill_surface.py`).
The repository describes itself as: Professional Claude Code skills marketplace featuring production-ready skills for enhanced development workflows. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 872127b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 4 files in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
python3codexclaudeFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Skill Governance loads about 2k tokens when it runs, and up to ~9.2k if it reads all its reference files. Until then it costs about 108 tokens; SKILL.md has 972 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from daymade/claude-code-skills at commit 872127b, republished under its MIT licence (© daymade). 972 words, ~2,021 tokens.
.claude/skills/skill-governance/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.Govern the Skill surface the user actually experiences: the intended hot or router entries are fully visible in a fresh host, cold capabilities remain reachable, editable behavior has one canonical owner, and every retirement is recoverable. A smaller directory count is not the outcome.
Before acting, state in one sentence:
If the request is only “how many / what is loaded / why”, stay read-only.
Never collapse these layers into one:
Installed does not mean active; active does not prove visible; visible does not prove usable. Counts and byte totals are diagnostic values only.
Use current runtime truth, not remembered conventions:
claude plugin ... --json for current Claude marketplace/install state;~/.agents/skills as Codex's current user Skill root;~/.codex/config.toml policy for Codex discovery disables;codex debug prompt-input for the actual fresh Codex catalog;~/.codex/skills is legacy/system compatibility unless a current local contract
explicitly assigns it another role. Never move third-party inventory into an
owned-source activation manifest just to make ownership look complete.
Read the named section of
references/skill-surface-governance.md
completely before using that workflow.
| Request | Read and use |
|---|---|
| Explicit delivery contract; verify source owner, registration and installed route | §16, then requested fresh-host gate in §14 |
| What Codex really loads; count, truncation, duplicate identity, missing router | §3–4, then §11 |
Reconcile owned source links or ~/.agents/skills activation | §2–5, then §11 |
| Keep gstack/Lark/IMA/UiPath or another bundle cold behind a router | §2–4, §6, then §11 |
| Claude marketplace/plugin source or installed-state drift | §2–3, §7, then §11 |
| Old cache versions | §2 and §7 “Exceptional manual cache repair” |
| Standalone plugins superseded by a suite | §7–8, then §11 |
Project .claude/skills vs .agents/skills drift | §9, then §11 |
| Retire loose or duplicate Skill directories | §2–3, §10–11 |
| Decide which Skills stay model-visible vs user-invocable-only | §15, then §11 |
For a newly registered Skill whose local use is part of the delivery, run the
target-name checks in references/skill-surface-governance.md §14 before calling
it ready. This covers Claude's fresh command catalog and Codex's fresh prompt.
The name must come from the requested delivery, not only the active whitelist.
Run from this Skill bundle:
python3 scripts/audit_codex_skill_surface.py --jsonOnly add policy the user or activation SSOT actually declared:
python3 scripts/audit_codex_skill_surface.py \
--require-visible gstack-router \
--jsonThe script compares codex debug prompt-input with the complete metadata parsed
by Codex's own app-server skills/list, plus exact activation/discovery policy.
Exit 0 is clean, 1 is pressure or drift to classify, and 2 means
the evidence is invalid. It is read-only. Do not convert exit 1 into automatic
pruning.
For a project's dual roots:
python3 scripts/audit_project_skill_roots.py <project-root> --jsonThat audit pairs direct child bundles by frontmatter name, recognizes only its
explicit fail-visible compatibility-router contract, and distinguishes shared
targets, identical copies, real drift, and invalid state.
rm -rf.For Daymade source-backed Codex activation, route to the current
claude-switch-models-setup dry-run/apply workflow. Its explicit
codex-active-skills.json owns only links created from declared source
marketplaces. Do not reimplement its collision, symlink, or pruning logic here.
For Claude plugins, inspect current marketplace and install JSON, update or reinstall through the official CLI at the original scope, and independently read back the result. Treat cache folders as derived runtime artifacts.
For suite topology changes, use marketplace-dev to edit the source manifest;
use this Skill only to reconcile already-landed migrations on the current host.
For an explicit delivery review, read §16 and run scripts/audit_skill_delivery.py <skill-path> --delivery-contract <private-contract.json> --json. It delegates source ownership to skill-creator; runtime visibility and original-requirement fidelity remain separate evidence. A source error blocks delivery even if the Skill can run.
All applicable claims must be proven independently:
Use the reference's task-behavior check only when actual task execution is part of delivery; catalog visibility alone does not prove that result.
Stop there. Do not create a new hook, manifest, report layer, or cleanup project unless the requested outcome still lacks evidence.
© daymade, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 9 other files (scripts, references) in daymade-skill/skill-governance of daymade/claude-code-skills.
Open the folder on GitHubat commit 872127b
Skill Governance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Skill Governance this skilldaymade/claude-code-skills | 1.4k | — | ~2k | Automated safety check: Pass | MIT | |
| Workspace Surface Auditaffaan-m/ECC | 276k | 3 repos | ~1.3k | Automated safety check: Notes | MIT | |
| Board Governancesickn33/agentic-awesome-skills | 47k | 1 repos | ~4.1k | Automated safety check: Pass | MIT | |
| Agent Governancegithub/awesome-copilot | 40k | 2 repos | ~4.6k | Automated safety check: Pass | MIT | |
| Surfacesrid/emanote | 963 | — | ~1.5k | Automated safety check: Pass | Custom licence | |
| Model Registry Governancesickn33/agentic-awesome-skills | 47k | 2 repos | ~3.9k | Automated safety check: Pass | MIT |
affaan-m/ECC
Audit the active repo, MCP servers, plugins, connectors, env surfaces, and harness setup, then recommend the highest-value ECC-native skills, hooks, agents, and operator workflows.
sickn33/agentic-awesome-skills
Board and governance register: meeting date, agenda, decision, resolution number, vote result, action owner and due date.
github/awesome-copilot
Patterns and techniques for adding governance, safety, and trust controls to AI agent systems.
srid/emanote
How a downstream app consumes the shared @kolu/surface stack (@kolu/surface · surface-app · surface-nix-host · surface-mcp) — declaring a typed reactive surface, serving it, consuming it (SolidJS…
sickn33/agentic-awesome-skills
Establish model registry standards, governance controls, metadata schemas, approvals, and lifecycle policies for enterprise AI deployments.
sickn33/agentic-awesome-skills
Agent governance skill for MCP tool calls — Cedar policy authoring, shadow-to-enforce rollout, and Ed25519 receipt verification.
daymade/claude-code-skills
This skill should be used when comparing two videos to analyze compression results or quality differences.
daymade/claude-code-skills
Generates professional animated CLI demos as GIFs using VHS terminal recordings.
daymade/claude-code-skills
Converts DOCX/PDF/PPTX and saved HTML/HTM to high-quality Markdown with automatic post-processing.
daymade/claude-code-skills
Generates several distinct, clickable HTML interaction prototypes for one product surface into a Design Board and collects selection/remix feedback before implementation.
daymade/claude-code-skills
Diagnoses and repairs repository setup and guarded Git workflows for Claude Code or Codex — environment repair, startup sync, hook auditing, collaborator handoff.
daymade/claude-code-skills
Pulls Bigdata.com (RavenPack) financial and news data via the official bigdata-client SDK and /v1/ REST endpoints — structured financials, prices, analyst estimates, entity-sentiment series…
Governs the Claude Code/Codex Skill surface: reconciles source/install/catalog-visibility drift without losing cold capability. Skill Governance is an agent skill from daymade/claude-code-skills. Governs the Claude Code/Codex Skill surface: reconciles source/install/catalog-visibility drift without losing cold capability.
Skill Governance fits situations like: users ask how many Skills load; why the catalog is truncated; want routers visible while other bundles stay cold; need duplicate/superseded-Skill.
Run `npx skills add daymade/claude-code-skills --skill skill-governance -a claude-code`. Or copy the skill folder (daymade-skill/skill-governance in daymade/claude-code-skills) into .claude/skills/skill-governance in your project. Claude Code loads it when a task matches its description.
Run `npx skills add daymade/claude-code-skills --skill skill-governance -a codex`. Or copy the skill folder (daymade-skill/skill-governance in daymade/claude-code-skills) into .agents/skills/skill-governance in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add daymade/claude-code-skills --skill skill-governance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/skill-governance, .gemini/skills/skill-governance, .github/skills/skill-governance and .opencode/skills/skill-governance in your project.
Going by SKILL.md and its folder, Skill Governance needs Python for the scripts in its folder and the command-line tools its instructions call (python3, codex and claude). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Skill Governance is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 8.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 7.1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Skill Governance: Workspace Surface Audit (affaan-m/ECC, 276k stars), Board Governance (sickn33/agentic-awesome-skills, 47k stars), Agent Governance (github/awesome-copilot, 40k stars) and Surface (srid/emanote, 963 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
daymade (a GitHub user) maintains it in daymade/claude-code-skills, which has 1,447 GitHub stars. The repository holds 103 skills in this directory. The repository was last updated on October 9, 2026.
Source: daymade/claude-code-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.