Rootly Automation
ComposioHQ/awesome-claude-skills
Automate Rootly tasks via Rube MCP (Composio). An agent skill from ComposioHQ/awesome-claude-skills.
审计工作流的跨会话状态机 — 在 <audit-root/.audit-state/<session-id.json 持久化轮次/发现项/收敛状态,支持 Token 中断后精准恢复
$ npx skills add devcodex-labs/devcodex --skill audit-session -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install devcodex-labs/devcodex audit-session --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .claude/skills && cp -r skills-src/content/skills/audit-session .claude/skills/audit-session && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "audit-session" agent skill from https://github.com/devcodex-labs/devcodex/tree/main/content/skills/audit-session into .claude/skills/audit-session/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-session", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/devcodex-labs/devcodex/tree/main/content/skills/audit-sessionType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add devcodex-labs/devcodex --skill audit-session -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install devcodex-labs/devcodex audit-session --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .agents/skills && cp -r skills-src/content/skills/audit-session .agents/skills/audit-session && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "audit-session" agent skill from https://github.com/devcodex-labs/devcodex/tree/main/content/skills/audit-session into .agents/skills/audit-session/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-session", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add devcodex-labs/devcodex --skill audit-session -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install devcodex-labs/devcodex audit-session --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/content/skills/audit-session .cursor/skills/audit-session && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "audit-session" agent skill from https://github.com/devcodex-labs/devcodex/tree/main/content/skills/audit-session into .cursor/skills/audit-session/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-session", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/devcodex-labs/devcodex.git --path content/skills/audit-session--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add devcodex-labs/devcodex --skill audit-session -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install devcodex-labs/devcodex audit-session --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/content/skills/audit-session .gemini/skills/audit-session && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "audit-session" agent skill from https://github.com/devcodex-labs/devcodex/tree/main/content/skills/audit-session into .gemini/skills/audit-session/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-session", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install devcodex-labs/devcodex audit-sessionInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add devcodex-labs/devcodex --skill audit-session -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .github/skills && cp -r skills-src/content/skills/audit-session .github/skills/audit-session && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "audit-session" agent skill from https://github.com/devcodex-labs/devcodex/tree/main/content/skills/audit-session into .github/skills/audit-session/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-session", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add devcodex-labs/devcodex --skill audit-session -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install devcodex-labs/devcodex audit-session --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/content/skills/audit-session .opencode/skills/audit-session && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "audit-session" agent skill from https://github.com/devcodex-labs/devcodex/tree/main/content/skills/audit-session into .opencode/skills/audit-session/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-session", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
audit-session审计工作流的跨会话状态机 — 在 <audit-root/.audit-state/<session-id.json 持久化轮次/发现项/收敛状态,支持 Token 中断后精准恢复
Audit Session is an agent skill from devcodex-labs/devcodex. 审计工作流的跨会话状态机 — 在 <audit-root/.audit-state/<session-id.json 持久化轮次/发现项/收敛状态,支持 Token 中断后精准恢复
Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `intent.json`).
The repository describes itself as: Intent-driven AI coding workflow runtime for consistent context, skills, approvals, validation, and handoffs across six AI coding hosts. The licence is AGPL-3.0.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 1dd4525. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Audit Session loads about 1.8k tokens when it runs. Until then it costs about 27 tokens; SKILL.md has 396 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from devcodex-labs/devcodex at commit 1dd4525, republished under its AGPL-3.0 licence (© devcodex-labs). 396 words, ~1,761 tokens.
.claude/skills/audit-session/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.audit 且预期轮次 ≥3(即所有非 chat 审计场景)<audit-root>/.audit-state/<session-id>.json<audit-root> 取值:
旧布局:<项目根>/.devcodex
集中布局单项目:<工作区根>/.devcodex/<project>
集中布局全工作区:<工作区根>/.devcodex/workspace
<session-id> 取首次启动审计的时间戳:YYYYMMDD-HHmmss
<audit-root>/.audit-state/ 目录由本 Skill 首次写入时创建(不随 init 分发)
.gitignore 须覆盖 <audit-root>/.audit-state/ 对应路径(如 .devcodex/.audit-state/、.devcodex/*/.audit-state/,同记忆策略)
active ──┬─> paused (Token 防护触发 / 用户中断)
├─> resumed (跨会话 resume 重新进入)
├─> converged (CRS + PCV 通过 + 连续3轮零发现)
└─> closed (用户确认审计闭环)
paused ──> resumed ──> active
converged ──> closed| 状态 | 进入条件 | 退出条件 |
|---|---|---|
active | 首次 audit 意图识别成功 | 任一退出条件触发 |
paused | C08 Token 防护(>15 轮)或 用户中断 | resume 意图 + 当前 session 命中 |
resumed | resume 意图 + 读取本文件 | 立即转 active 继续审计 |
converged | zeroFindingStreak ≥ 3 且 crsPassed 且 pcvPassed | 用户确认 → closed |
closed | 用户确认审计完成或放弃 | 终态(不再写入) |
{
"schemaVersion": "AuditSessionStateV2",
"sessionId": "20260520-143055",
"startedAt": "2026-05-20T14:30:55+08:00",
"lastUpdatedAt": "2026-05-20T16:12:33+08:00",
"target": {
"type": "spec | tech-design | requirements | project | report | document",
"scope": "<被审查文件 glob 或目录>"
},
"dimensions": ["D1", "D2", "..."],
"round": 3,
"state": "active | paused | resumed | converged | closed",
"findings": [
{
"id": "F-001",
"round": 1,
"dim": "D5",
"file": "instructions/12-audit.instructions.md",
"severity": "🔴 | 🟡 | 💡",
"summary": "<一句话>",
"status": "open | pending | in-progress | fixed | wontfix | accepted | recorded | transferred | superseded",
"category": "spec-defect | release-pending | v{X.Y.Z}-candidate",
"fixPlan": "<修复方案概述>",
"fixCommit": "<git commit hash, 修复后写入>",
"linkedPF": "PF-NNN | null"
}
],
"regressionProbes": [
{
"findingId": "F-007",
"scanCmd": "grep -c 'PC5' CLAUDE.md",
"expectedMatches": 3,
"lastVerifiedRound": 4,
"lastVerifiedAt": "2026-05-21T03:30:00+08:00"
}
],
"r2Probes": [{"name": "<probe>", "status": "✅|⚠️|❌"}],
"r3Probes": [{"name": "<probe>", "status": "✅|⚠️|❌"}],
"r4Probes": [{"name": "<probe>", "status": "✅|⚠️|❌"}],
"zeroFindingStreak": 0,
"crsPassed": false,
"pcvPassed": false,
"remoteReleased": {
"gitPush": false,
"npmPublish": false,
"recordedAt": "ISO8601",
"source": "user-confirmed-manual | ci-automation"
},
"lastCheckpoint": {
"round": 3,
"writtenAt": "2026-05-20T16:12:33+08:00",
"reason": "round-end | token-protect | user-interrupt | switching-to-release-vX.Y.Z | release-pending-vX.Y.Z"
},
"linkedMemory": "tasks/20260520.md",
"linkedReport": "<active-root>/<task-kind>/<task>/reports/<agent>/20260520/01--<name>.md",
"linkedRelease": "<active-root>/requirements/<task>/reports/<agent>/YYYYMMDD/01--vX.Y.Z-release.md"
}.audit-state 兼容读取边界.audit-state 是多类运行态证据的共享目录名,不代表目录内每个 JSON 都属于当前审计会话。读取者必须先分类,再决定校验方式:
| 分类 | 识别 | 处理 |
|---|---|---|
| current session | exact AuditSessionStateV1 / AuditSessionStateV2 | 按本 Skill 的状态、finding 与 regression probe 合同严格校验 |
| legacy audit | AuditStateV1 或可识别的历史无 schema 审计形状 | 只读导航与取证,不要求满足当前枚举或新探针,不改写历史字节 |
| non-audit | SkillRoute、batch plan、validation 等其他 schema | 跳过审计会话校验,由各自 owner 负责 |
| unsupported current | 未支持的 AuditSessionStateV* | 明确报告不支持,禁止猜测或降成 legacy |
| invalid | JSON 损坏或顶层不是 object | 报告结构错误,不静默忽略 |
兼容分类只解决 reader 误判,不授予旧状态新的写权限,也不得伪造 superseded、重算旧 finding 或迁移历史文件。
| 字段 | 引入 | 用途 |
|---|---|---|
findings[].category | v1.9.4 | 分类标识:spec-defect(规范缺陷)/ release-pending(仅发版动作未启动导致)/ v{X.Y.Z}-candidate(推迟到下版本同源合并) |
findings[].fixPlan | v1.9.4 | 修复方案概述,留作 release/dev 工作流参考 |
findings[].fixCommit | v1.9.4 | 独立 fix/self-fix 工作流产生的修复 commit hash;audit 只读取并验证,不自行提交 |
regressionProbes[] | v1.9.5+ | 已修复 finding 的回归扫描定义;audit-common §收敛门禁第 7 步触发;任一回归 → status 切回 open,streak 归零 |
r{N}Probes[] | v1.9.4 | 第 N 轮的探针清单与状态,便于跨会话 resume 时审计深度可追溯 |
remoteReleased | v1.9.4 | 远端发版动作状态(git push + npm publish),消除 release-pending findings 的依据 |
lastCheckpoint.reason | v1.9.4 | 扩充值:switching-to-release-vX.Y.Z(切 release 流程缓冲)/ release-pending-vX.Y.Z(等下版本合并) |
linkedRelease | v1.9.4 | 关联 release 报告路径,建立 audit → release 双向链 |
| 状态 | 含义 | 是否未解决 |
|---|---|---|
open | 当前审计仍需处理 | 是 |
pending | 已确认但等待后续批次处理 | 是 |
in-progress | 正在修复或验证中 | 是 |
fixed | 已修复并通过回归验证 | 否 |
wontfix | 已确认不修复,需保留理由 | 否 |
accepted | 已接受为项目例外或可接受风险,需保留理由 | 否 |
recorded | 已记录到外部台账、问题池或报告,当前审计不再直接处理 | 否 |
transferred | 已转入其他报告、需求或问题池继续跟进 | 否 |
superseded | 已被后续报告或新版结论取代 | 否 |
终态
converged/closed不得保留open、pending、in-progressfindings;允许fixed、wontfix、accepted、recorded、transferred、superseded作为已处置状态。
AuditMutationBoundaryGate:audit session 只记录 finding/交接/外部修复证据;sourceMutationAuthorized 在 audit 中恒为 false,用户修复授权由独立 fix/self-fix 的 CP/ExecutionContract 持有。
| 时机 | 动作 | 字段更新 |
|---|---|---|
| 首轮启动 | 创建文件,state=active | sessionId / startedAt / target / dimensions |
| 每轮结束 | 追加 findings + 更新 round | round / findings / zeroFindingStreak |
| CRS 完成 | 标记通过状态 | crsPassed |
| PCV 完成 | 标记通过状态 | pcvPassed |
| Token 防护(C08 >15轮) | state=paused | state / lastCheckpoint.reason=token-protect |
| 收敛 | state=converged | state |
| 用户确认 | state=closed | state |
| 关联点 | 说明 |
|---|---|
instructions/12-audit.instructions.md | 审计工作流入口须读取/创建本文件;收敛门禁须校验 crsPassed && pcvPassed && zeroFindingStreak>=3 |
instructions/15-memory.instructions.md | tasks/YYYYMMDD.md 段落须追加 🔗 审计会话:<session-id> 字段,建立双向链 |
intent/SKILL.md | resume 意图识别后须在三层记忆读取之前优先扫描 <audit-root>/.audit-state/*.json 查找未 closed 的会话 |
skills/audit-execution-guide/SKILL.md | finding 先记录/交接;用户显式授权的独立 fix/self-fix 完成后,audit 读取新证据并重启新轮,旧轮不得在 audit 内伪造 fixed |
<audit-root>/.audit-state/ 下有界 .json 清单,先按上述兼容规则分类lastUpdatedAt 倒序,找出 state ∈ {paused, active, resumed} 的最新一份;其他 schema 不参与排序<sessionId>:目标 <target.scope>,已完成 R{round},发现 {open} 项 open。是否继续?".devcodex/.memory/)ConcurrencyPolicy 中不可变 audit-session 单写者锁,不受项目 concurrency 配置放开git add、commit 或 source mutation 权限© devcodex-labs, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in content/skills/audit-session of devcodex-labs/devcodex.
Open the folder on GitHubat commit 1dd4525
Audit Session next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Audit Session this skilldevcodex-labs/devcodex | 439 | — | ~1.8k | Automated safety check: Pass | AGPL-3.0 | |
| Rootly AutomationComposioHQ/awesome-claude-skills | 77k | 3 repos | ~727 | Automated safety check: Pass | None | |
| Monte Carlo Analyze Root Causesickn33/agentic-awesome-skills | 47k | 1 repos | ~4k | Automated safety check: Pass | Apache-2.0 | |
| Issue Root ResolutionGentleman-Programming/gentle-ai | 7.6k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | |
| Root Cause Paretodavila7/claude-code-templates | 32k | — | ~791 | Automated safety check: Pass | MIT | |
| Root Cause Debugginggarrytan/gstack | 136k | — | ~1.4k | Automated safety check: Pass | MIT |
ComposioHQ/awesome-claude-skills
Automate Rootly tasks via Rube MCP (Composio). An agent skill from ComposioHQ/awesome-claude-skills.
sickn33/agentic-awesome-skills
Curated upstream guidance for Monte Carlo Analyze Root Cause; use when the workflow matches the user goal.
Gentleman-Programming/gentle-ai
Trigger: root audit, atacar la raíz, issue roots, backlog roots, mechanism map, deletion-driven fix, resolver issues de raíz, close outdated issues.
davila7/claude-code-templates
Build a decision-grade Pareto for downtime, defects, complaints or delays - with unit-of-measure discipline, category hygiene, exposure normalization and a follow-up metric.
garrytan/gstack
Investigates bugs, errors and stack traces in phases and requires a root-cause hypothesis to be confirmed before any fix is written.
garrytan/gstack
Debugs in four phases (investigate, analyze, hypothesize, implement) under one rule: no fix is made until the root cause is found.
devcodex-labs/devcodex
无障碍与国际化专家 Owner — 当任务涉及可访问性、键盘操作、焦点、屏幕阅读器、ARIA、语言地区、本地化、RTL、翻译资源、用户可见文案或多语言文档时使用;要求把包容性体验和本地化验证绑定到真实用户路径。
devcodex-labs/devcodex
AI Agent 系统架构专家 Owner — 当任务涉及 Agent 路由、工具调用、上下文管理、记忆、状态机、权限、人机协作、可观测性、回放验证或模型辅助治理时使用;要求把 Agent 行为设计成可解释、可恢复、可审计。
devcodex-labs/devcodex
API 契约架构专家 Owner — 当任务涉及 public API、HTTP/SDK/CLI 契约、版本兼容、错误模型、分页过滤、幂等、Schema、类型、迁移或消费者影响时使用;要求先冻结消费者契约,再设计实现与验证。
devcodex-labs/devcodex
架构设计文档编排 Owner — 当用户要求架构设计、系统设计、技术架构或可指导开发、Review 与任务拆分的完整方案时使用;要求从业务流程反推节点、状态、数据、一致性、异常补偿、ADR 与实施任务。
devcodex-labs/devcodex
审查公共维度 G0~G5 + Profile Freshness Check — 所有 audit 子类型必先执行的基础维度层
devcodex-labs/devcodex
后端领域架构专家 Owner — 当任务涉及领域模型、业务流程、权限、API、事务、一致性、幂等、兼容、数据边界、服务职责或用户要求从后端/领域专家角度审查时使用;要求用领域语言和业务不变量约束实现。
审计工作流的跨会话状态机 — 在 <audit-root/.audit-state/<session-id.json 持久化轮次/发现项/收敛状态,支持 Token 中断后精准恢复. Audit Session is an agent skill from devcodex-labs/devcodex.
Run `npx skills add devcodex-labs/devcodex --skill audit-session -a claude-code`. Or copy the skill folder (content/skills/audit-session in devcodex-labs/devcodex) into .claude/skills/audit-session in your project. Claude Code loads it when a task matches its description.
Run `npx skills add devcodex-labs/devcodex --skill audit-session -a codex`. Or copy the skill folder (content/skills/audit-session in devcodex-labs/devcodex) into .agents/skills/audit-session in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add devcodex-labs/devcodex --skill audit-session -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-session, .gemini/skills/audit-session, .github/skills/audit-session and .opencode/skills/audit-session in your project.
Going by SKILL.md and its folder, Audit Session needs the command-line tools its instructions call (git).
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Audit Session is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.8k tokens (SKILL.md is roughly 7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Audit Session: Rootly Automation (ComposioHQ/awesome-claude-skills, 77k stars), Monte Carlo Analyze Root Cause (sickn33/agentic-awesome-skills, 47k stars), Issue Root Resolution (Gentleman-Programming/gentle-ai, 7.6k stars) and Root Cause Pareto (davila7/claude-code-templates, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
devcodex-labs (a GitHub organization) maintains it in devcodex-labs/devcodex, which has 439 GitHub stars. The repository holds 70 skills in this directory. The repository was last updated on September 17, 2026.
Source: devcodex-labs/devcodex on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.