Agent skill

Compliance

by devcodex-labs in devcodex-labs/devcodex

执行入口检查与 FC/SC/RC/T 合规校验。PC0~PC10 入口检查所有模式启用;仅 dev 模式执行全量合规校验,prod 模式不执行(规范已验证)。chat 豁免合规块。

AGPL-3.0Auto-check passed

Install Compliance

skills CLI
$ npx skills add devcodex-labs/devcodex --skill compliance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install devcodex-labs/devcodex compliance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .claude/skills && cp -r skills-src/content/skills/compliance .claude/skills/compliance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
compliance
GitHub stars
439
Token cost
~3.6k tokens
SKILL.md length
935 words
Files
3
Skills in repo
70
Repo updated
First seen
Licence
AGPL-3.0

At a glance

执行入口检查与 FC/SC/RC/T 合规校验。PC0~PC10 入口检查所有模式启用;仅 dev 模式执行全量合规校验,prod 模式不执行(规范已验证)。chat 豁免合规块。

  • Works in 3 steps: 不修复会导致什么具体的功能异常?→ 答不出 → 降级 → 是否可能是有意的设计选择?→ 有可能 → 验证意图后再定级 → 不修复的风险是否可接受?→ 可接受 → 降级为 🟡 或 💡
  • SKILL.md covers §0 模式判断(前置,优先执行), §0.1 SpecRadarSubgate(PC4…, §1 输出验证(每条建议/方案/问题必须附) and §2 形式合规(FC)— 不通过立即修正后重检, plus 5 more sections
  • Calls npm and node

What it does

Compliance is an agent skill from devcodex-labs/devcodex. 执行入口检查与 FC/SC/RC/T 合规校验。PC0~PC10 入口检查所有模式启用;仅 dev 模式执行全量合规校验,prod 模式不执行(规范已验证)。chat 豁免合规块。

Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `intent.json` and `workflow-completion.schema.json`).

The repository describes itself as: Intent-driven AI coding workflow runtime for consistent context, skills, approvals, validation, and handoffs across six AI coding hosts. The licence is AGPL-3.0.

Example prompts

  • “/compliance”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. 不修复会导致什么具体的功能异常?→ 答不出 → 降级
  2. 是否可能是有意的设计选择?→ 有可能 → 验证意图后再定级
  3. 不修复的风险是否可接受?→ 可接受 → 降级为 🟡 或 💡

What it can do on your machine

Read from SKILL.md and the folder at commit 1dd4525. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Compliance loads about 3.6k tokens when it runs. Until then it costs about 25 tokens; SKILL.md has 935 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~25
When it runs · the whole SKILL.md, loaded when a task matches
~3.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from devcodex-labs/devcodex at commit 1dd4525, republished under its AGPL-3.0 licence (© devcodex-labs). 935 words, ~3,586 tokens.

Download SKILL.mdSave it as .claude/skills/compliance/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
compliance
description
执行入口检查与 FC/SC/RC/T 合规校验。PC0~PC10 入口检查所有模式启用;仅 dev 模式执行全量合规校验,prod 模式不执行(规范已验证)。chat 豁免合规块。

§0 模式判断(前置,优先执行)

读取由 load-profile Skill 注入的 ENV_MODE(参见 01-common §ENV_MODE 行为总表):

<!-- devcodex:include shared/compliance/env-mode-table.md -->

⛔ S01~S06 安全底线不受 ENV_MODE 影响,无论 dev/prod 均强制执行;S07 在 instruction-fallback 模式下要求全模式入口检查(致命自修正)。

⚠️ 入口检查(PC0~PC10)所有模式启用,收到用户消息后立即执行;dev 模式额外执行 PC4 完整规范雷达,非 dev 模式 PC4 标注 N/A,详见 17-compliance.instructions.md §入口检查。

🔴 S07 时序:用户首次可见 PC0~PC10 先于实质正文与产物 mutation(报告/记忆/台账);禁止最终文首补 PC 冒充已先输出。Hook 可报告 s07OrderStatus(ok/late/missing/unverified)。

🔴 PC0 单源语义(ABS-07):用户可见 PC0 必须写 ContextReadPlan + 必要来源回执;instructions.md、17-compliance、precheck-status.prompt 同源。禁止「Profile ✅ 已加载」单字段冒充上下文完整;PC7 使用 memory_status + 有界 query 回执一致表述。

ℹ️ ENV_MODE 未注入(profile 未加载)时,默认按 prod(不执行合规检查)。

§0.1 SpecRadarSubgate(PC4 规范雷达承接)

SpecRadarSubgate 是 PC4 的执行承接层:instructions/18-spec-radar.instructions.md 只负责入口提示和用户可见摘要,具体 Gate 分组、触发判断、ownerSkill、验证路线和 N/A 理由必须引用 spec-governance 的 GovernanceGateRegistry。

dev 模式 PC4 至少输出:

字段要求
modedev / prod / unknown;非 dev 时 PC4 可写 N/A + skipReason
triggeredGateGroups命中的 gateGroup 列表,例如 absorption-layering、review-checklist、frontend-runtime、release-parity
ownerSkills每个 gateGroup 的 owner Skill;不得把执行细节继续堆回 PC4 文案
requiredArtifacts本轮需要的清单、报告、证据、探针或部署同步
validationRoutetargeted test、validate 编号、SCV、人工证据或 N/A + skipReason

当 PC4 命中新规范吸纳、历史长清单迁移、复审遗漏、用户文档、发布或前端运行态相关 gateGroup 时,后续报告必须引用对应 owner Skill 的证据,而不是只写“已检查规范雷达”。

🔴 合规执行 vs 用户面可见(UserVisibleNoisePolicyV1 · chat 豁免完成块)
层要求
执行dev 模式仍须在内部完成 FC/SC/RC/T;证据写入报告/记忆
用户面默认未宣称完成 → 不贴完成检查/FVS/产物全表(只保留入口检查 + 正文)
宣称完成且全绿贴 短 FVS(见 shared validation-summary);不默认 FC 全表
失败/缺口/用户要详情展开失败项 + 全量 FVS / 相关产物
<!-- devcodex:include shared/compliance/validation-summary.md -->

⛔ 宣称完成却只有“全绿/详见报告” → DevModeCompletionCheckDetailGate 未通过。 ⛔ 未宣称完成时 不得 为过 Stop 而硬贴长完成检查(Stop 以 workDoneClaimed 为准)。 ℹ️ 六宿主同源:user-visible-output-contract · UserVisibleReplyLayoutV1 + UserVisibleNoisePolicyV1。 ⚠️ FC5 填写规则:触发 user-visible-output-contract。ArtifactDeliveryManifestV1 必须 planned=observed=internalDelivered,UserFacingArtifactSetV1 必须 required hidden=0 且 listed+remaining=total;session/daily/SUMMARY/task/checkpoint/raw ledger 默认 internal-only 但仍参与 ECR。持久化投影使用 LinkCapabilityDecisionV1,用户面使用 HostLinkCapabilityDecisionV2 + ArtifactDeliveryAttemptV1;只有 action 与 readback 均成功才可写 opened,其他情况使用 ready 或 absolute fallback。Hook 未观察 payload 时只能 unverified,legacy 格式最多 unverified-legacy。 ⚠️ HostPermissionAuthorityInvariant:PreToolUse/PermissionRequest 的文件、命令、删除和工具操作权限仅由宿主决定。DevCodex 可以记录 advisory/workflow-invalid,但输出及宿主 adapter 不得含 allow/deny/ask/block/continue:false 操作权限载荷;负向测试必须覆盖六宿主遗留载荷剥离。 ℹ️ prod 模式不执行合规检查,不输出状态块。 ℹ️ chat 工作流豁免此输出。

EnforcementHonesty(全宿主完成态 · R5 / R11)

完成态 / 被 Stop 续跑后的收尾,用户可见回复或正式报告须披露拦截与流程诚实摘要(诚实=披露缺口,不是关能力)。Hook 状态字段:state.enforcementHonesty(EnforcementHonestyV1)。

markdown
### 拦截与流程诚实摘要(EnforcementHonesty)
| 项 | 值 |
|----|-----|
| host | grok / codex / claude / … |
| hard 事件启用 | PreToolUse, Stop(宿主能力矩阵) |
| 本轮 PreTool deny | 0 / N(摘要) |
| 本轮 Stop | block→续跑 / allow / unverified(无正文) |
| 未能硬拦 | 如:纯文本无 tool;safety-only 下 CP 写控制面 |
| 流程缺口 | 如:entry-check / pr1-skipped / cp2-unconfirmed-write / final-validation-summary |
| evidenceMode | path-observable+stop-conditional / host-native |
processGaps 枚举(R11 规范名)含义
entry-check-missing缺 PC0~PC10 / 入口检查块
completion-check-missing缺 ### DevCodex · 完成检查(或 envelope completion-check)
final-validation-summary宣称完成但 FVS 短矩阵不完整 / thin-green
report-missing / memory-missingmutation 后未写报告/记忆(可用 SimpleTask / N/A+skipReason 豁免)
pr1-skipped请求确认 CP2 但无 强 PR-1 通过证据(zero-blocker / PR-1 ✅)
cp2-unconfirmed-writesafety-only 下控制面/源码写在 CP2 未确认时被放行(strict 为 deny)
stop-continuation-exhausted达 softCap 后 fail-open

Grok:条件 Stop 硬续(有 lastAssistantMessage 可 decision:block;无正文 unverified;平台/softCap 后 fail-open)。控制面写路径建议 DEVCODEX_HOOK_ENFORCEMENT=strict,否则 Honesty 必须披露「未硬拦」。

GovernanceIntakeClosureGate(全模式语义项)

本项不受 dev/prod 后置合规块开关影响:每条非空用户消息都必须有中性 candidate,并在合理性评估后形成 GovernanceIntakeDecision。收尾前检查 candidate ID、评估结论、泛化范围、现有规范状态、复合意图、目标台账、写入要求与证据;required 写入必须满足 LedgerWriteEvidenceGate,record.none 必须满足 RecordNoneChallengeGate,record.ambiguous 保持未终结。Hook 证据不可观察时只能标 unverified,不能把回复中的自报编号当作落账成功;instruction-fallback 必须在报告/记忆保留相同字段与人工复证路线。

TimeToFirstValueGate + WorkspaceRootScanHygiene(C16 / PI-20260724-01 · 全模式防复发)

🔴 与 ENV_MODE 无关:非 chat 任务不得用「准备过重」制造假卡住。Owner 细节见 skill-gap-analysis;机器探针见 classifyTtfvOmissionSample / classifyWorkspaceRootScanSample(host-parity-scorecard.js)与 ProgressReportFastPath classifyProgressReportFastPathSample。

门禁通过条件失败处置
TTFVPC0~PC10 + 最小 ContextReadPlan 之后,同一用户可见回复含:范围卡 或 首批 finding/结论 或 明确阻断+恢复本轮不得宣称「已启动审查/分析完成准备」;下一 tool 轮必须先交付
ProgressReportFastPath进度/发版状态查询:绑定项目 → 固定真相源顺序 → 首轮进度卡;禁止根 inventory 抢跑同 TTFV 违约;progress-fail
WorkspaceRootScanAdvisory未绑定唯一项目前不递归 workspace 根;项目可知时用直达路径;inventory 排除 node_modules/dist改用有界命令;Hook 只提示成本与范围,是否执行由宿主权限策略决定
Skill 最小充分只加载当前意图强制 bundle + 本批所需 Skill,禁止首轮通读全部 audit 子 Skill 百科记 WARN;不作为「已审查」证据

chat / 纯确认短答:TTFV 可 N/A + skipReason=chat-or-ack。

全自动模式差异

显式 @devcodex-auto、全局默认 @rocky、Profile extensions.devcodex.autoAliases 替换别名或明确自然语言 auto 授权模式下:

在用户已授权的任务范围内,FC/SC 失败时继续修正;遵守 S01~S06 的宿主权限和工作流边界。Auto/白名单不创建正式任务、CP confirmation、fenced owner 或 mutation lease;任何修正都必须先完成对应标准流程与 V5 prewrite。

instruction-fallback 宿主(如 JetBrains / Cursor)仅保留 auto 规则语义,不承诺 runtime 级自动行为;hook-enforced 宿主校验当前语义决定和正式 workflow authority。路径分类仅作 advisory,safety-only 或 strict 均不得据此覆盖已有授权或要求额外确认。

§1 输出验证(每条建议/方案/问题必须附)

验证项说明
合理性为什么要这样做?依据是什么?
可实施性能否落地执行?是否有前置条件?
收益执行后带来什么改善?

附加标注(每条还须标注):

属性说明
验证状态✅已验证(实际读取了源文件确认;运行时/探针/测试结论还须满足下方 MeasuredVerificationStandard)或 ⚠️待验证(基于推测/上下文推断/非权威实验)
影响范围涉及哪些文件/模块(一句话描述)
MeasuredVerificationStandard(SC14 承接 · 全工作流运行时结论)

凡报告或用户面将测试、探针、validate、性能数字、命令输出标为 ✅已验证:

规则要求
权威入口必须执行生产入口命令,例如 node scripts/test-spec-governance.js、npm run test:core / node scripts/validate.js、需要 full 时用 npm test;并记录命令与 exitCode
非权威实验自写隔离 harness、裸 fs.read + includes、未复用 validate.js 同款 createCanonicalAwareReader/ROOT/上下文 的脚本 → 只能标 非权威实验 或 ⚠️待验证(生产路径),不得写成 V# 失败/通过或「今日验收不通过/通过」
等价条件隔离脚本若宣称与某 V# / suite 等价,必须复用生产 read 路径与上下文,并在报告写 parity 证据
历史数字SUMMARY / 记忆 / 旧报告中的数字不得直接冒充本轮 ✅已验证

若报告或用户面输出包含多个可执行建议、多个后续路径、方案对比或决策点,必须额外给出 推荐结论 / 推荐方案,且推荐理由可追溯到五项验证;无后续动作时写明 推荐:无后续动作。

UniqueNextStepRecommendationGate(FC7 / SC5 完成态扩展 · PF-172)

凡用户可见 完成态 / 收口 / 台账批次结束 的「下一步 / 后续建议 / 推荐结论」:

规则要求
唯一主动作有且仅有 1 条可执行主动作(一句可验收);禁止把 ≥2 条可执行路径写成同级推荐
禁止「或」并列禁止用「或 / 或者」在推荐主面上连接两条可执行路径(如「对齐 VL 表或挑 PF 链路」);机器分类见 classifyNextStepOrForkSample → or-fork 即失败
备选降级非推荐路径只能放在「不推荐 / 明确劣于推荐」小节,并写清为何不选;不得与推荐同级
无动作无后续时写 推荐:无后续动作,不得硬凑二选一
与 CP 前门禁关系CP 确认前的 A/B/C 仍由 UniqueRecommendationBeforeConfirmGate / NoPreferenceMenuAfterConvergenceGate 覆盖;本门禁补 free-text 完成态 缺口(VL-077 / PI-151)
ControlPlaneDisciplineProbeBundle(PF-138/139/140 · 2026-07-21 吸纳)
分类器失败码覆盖
classifyPreferenceMenuAfterConvergenceSamplepreference-menu收敛后希望哪种 / A/B/C
classifyCpArtifactBeforeConfirmSamplemissing-cp-artifact确认 CP 无产物路径
classifyCodeTruthMatrixAtCpSamplemissing-code-truth-matrix控制面定稿无 CodeTruth 矩阵
classifyControlPlaneDigestSamplemissing-digest控制面确认无 sha/digest
classifyAuthorSelfReviewBoundarySampleauthor-self-review-as-independent作者自审冒充独立审查
classifyNextStepOrForkSampleor-fork完成态「或」双主动作

生产入口:npm run test:discipline-execution。Owner:cp-gate + compliance + dev-plan-review + expert-output-quality。

Show full SKILL.md (390 more words)Show less

§2 形式合规(FC)— 不通过立即修正后重检

#检查项
FC1记忆文件完整(必填字段齐全,状态 🔄/✅;📨 对话记录必须为四列表格格式:轮次 | 👤 用户消息 | 🤖 AI执行 | 状态,三列或项目符号格式不通过)
FC2报告文件已写入(chat 豁免)
FC3CP 按序执行(dev/fix;其他 N/A)
FC4文件名/路径合规(NN-- 双横杠开头)
FC5ArtifactDeliveryManifestV1 完整对账;UserFacingArtifactSetV1 required hidden=0、计数守恒;semantic name/action/order、LinkCapabilityDecisionV1 持久化投影、HostLinkCapabilityDecisionV2 renderer 与逐目标 ArtifactDeliveryAttemptV1 action/readback/fallback 有效
FC6新增 DevCodex 规范资产 .md 行数检查(instructions / skills / prompts / templates / 规范源等超 500 行须按 C13 拆分;业务项目需求、技术方案、报告和正式项目文档不因 C13 强制拆分)
FC7用户决策选项与报告决策点必带推荐 + 理由:所有 AskUserQuestion / 多选项呈现 / CP 选项 / 方案对比 / analyze-audit 报告决策点必须有且仅有 1 个推荐项,推荐项置首且说明推荐理由;完成态「下一步/后续建议」适用 UniqueNextStepRecommendationGate(禁止「或」并列双主动作);无后续动作时写明 推荐:无后续动作

§3 实质合规(SC)— 🔴 阻塞性

#检查项适用范围
SC1报告验证列完整(合理性 + 可实施性 + 收益 + 验证状态 + 影响范围五项)全工作流
SC2代码已诊断(无未处理 error)dev/fix 🔴;其他 N/A
SC3修复已全局扫描(三步扫描:同类全局+数据联动+grep零残留)fix 🔴;dev(重构) 🔴
SC4关联文件已同步dev/fix/self-fix 🔴
SC5后续建议与推荐结论已输出(报告含 ## 后续建议 / ## 推荐结论 / ## 推荐方案 或等效内容;有且仅有 1 条主动作;禁止完成态用「或/或者」并列 ≥2 条可执行路径;备选须标「不推荐」+ 理由;无待跟进时显式标注“推荐:无后续动作”即通过;探针 classifyNextStepOrForkSample)全工作流
SC6Agent SUMMARY 已更新(.memory/clients/<agent>/SUMMARY.md)全工作流 🔴
SC7全局 SUMMARY 关键决策已追加(仅规范变更/架构决策/P0修复)有关键决策时 🔴
SC8上次待跟进已查阅(首次会话 N/A)全工作流 🔴
SC9C08 Token 防护状态(>10轮关注 / >13轮预警 / >15轮防护)全工作流
SC10C07 并发策略合规:只读/隔离验证并发需符合 ConcurrencyPolicy,写共享状态、同一 audit session 或 package boundary 竞争写视为阻断涉及 Agent 调用或并发任务 🔴
SC11C14 多任务拆分检查(≥5任务需建议拆分会话)任务≥5时 🔴
SC12C14 多任务进度快照验证(每完成子任务有 T{N}进度 标记)任务≥2时 🔴
SC13C15 架构质量自检(dev plan-review 三维评估;fix CP2 三维评估)dev/fix 🔴
SC14analyze/audit(及任何宣称探针/测试结果的工作流)中,所有标注 ✅已验证 的运行时结论须满足 MeasuredVerificationStandard:本轮执行生产入口命令并记录 exitCode;隔离 harness / 非生产 reader 不得写成 V# 成败;SUMMARY/记忆历史数字必须降级为 ⚠️待验证analyze/audit 🔴;dev/fix 宣称测试/validate 时同标
SC14a强主张证据新鲜度:报告、分析、审查、推荐、CP 可确认或完成态声明命中 evidence-freshness 时,须有 StaleEvidenceLintDecisionV1;summary-only 不得单独支撑 ✅已验证 / 推荐 / 可确认analyze/audit/dev/fix/self-fix 🔴
SC15dev/fix 关键产物已完成 ECR 执行闭环复审:覆盖 CP1/CP2/CP3、实施进度(触发时)、ExecutionContract/TestRoute/ReleaseAudit/ReleaseVerification(触发时)、报告、daily tasks、SUMMARY、diff/commit、测试/扫描证据、dirty 边界;最后一次阻断性修正后至少再复审 1 轮且无新增阻断性问题dev/fix 🔴
SC16C16 TTFV + WorkspaceRootScanHygiene + ProgressReportFastPath:非 chat 首轮实质回复具备范围卡/首批结论/阻断之一;进度查询走固定真相源;默认 inventory 不使用 workspace 根无界 Recurse,Hook 只发 advisory;探针 classifyTtfvOmissionSample / classifyWorkspaceRootScanSample / classifyProgressReportFastPathSample非 chat 🔴;chat N/A

§4 恢复性检查(RC)— 非阻塞

豁免:chat 豁免全部合规检查;analyze 豁免 RC 层(只读工作流,多轮收敛但每轮不写恢复性记忆)。

#检查项
RC1记忆文件是否足以让下一个 Agent 恢复上下文;跨会话/多批次/summary/compact/handoff 场景是否已有 ContextHandoffCard
RC2已产出文件是否自洽完整
RC3🔄 标记任务是否提供了足够恢复线索
RC4关联需求的 .memory/sessions.md 是否已创建

§5 报告二次验证(报告写入后执行)

🔴 阻塞性验证
#检查项
V1每条问题有文件来源(文件名+行号/章节)
V2验证列+标注完整(回读报告文件确认)
V3✅已验证 的问题确实读取了对应文件
V4纯推测性问题已标注 ⚠️待验证
V5每条 🔴 级问题通过反向质疑三问(不修复的具体后果/是否有意设计/风险可否接受)
V5 反向质疑三问

逐条对 🔴 级问题执行:

  1. 不修复会导致什么具体的功能异常?→ 答不出 → 降级
  2. 是否可能是有意的设计选择?→ 有可能 → 验证意图后再定级
  3. 不修复的风险是否可接受?→ 可接受 → 降级为 🟡 或 💡
🟡 改进性验证
#检查项
V6🔴 级占总问题数超 1/3 时,触发"分级标准是否过严"自检

§6 任务完成验证

aliascanonical ID检查项
T1requirements.coverage✅ 需求覆盖(用户所有需求点已处理)
T2delivery.report✅ 报告存在(chat 豁免)
T3delivery.memory✅ 记忆完整(任务摘要+对话记录+关联报告)
T4confirmation.cp✅ CP 完整(dev/fix;其他 N/A)
T5governance.compliance✅ 合规通过(FC+SC 全通过)
T6constraints.and-sync✅ 约束遵守(C01~C22 + 关联文件已同步 + GovernanceIntakeClosureGate 已终结或明确 unverified/ambiguous)
T7workflow.verification✅ 工作流验证(dev/fix: 扫描/验证 + ECR 已执行;audit/analyze: PCV 与推荐结论已执行)
T8continuity.summary✅ SUMMARY 已更新;若触发上下文交接,daily tasks 或报告已写 ContextHandoffCard;若主动建议新会话,同回复已交付 NewSessionContinuationCard
T9delivery.manifest✅ internal manifest 与用户可见交付均完成;默认隐藏内部记录仍已写入、验证并纳入 ECR
T10long-task.timing-and-coverage✅ 条件:长任务是否记录 SessionTimingCard(或 N/A+skipReason);确认类清单是否含 CoverageMatrix 或 residual 声明(ABS-17/18)
T11long-task.budget-and-authorization✅ 条件:长任务/Auto/多批次是否具备 ExecutionBudget + LongTaskAuthorization(或 N/A+skipReason);有等待面时是否分列 external wait(PI-118/PF-137)
T12deployment.and-completion-evidence✅ 条件:触及部署消费者时是否输出 WorkspaceSyncStatus;dev/fix/self-fix 宣称完成时是否通过 CompletionEvidenceGate(ECR + 同步/验证/dirty 证据)
T13post-delivery.self-check✅ 条件:长任务收口 / 宣称完成 / 用户质疑慢漏时是否执行 PostDeliverySelfCheck(或 N/A+skipReason);不得用自评刷 PI

机器消费者必须使用 canonical ID;T1~T13 只用于现有文档、人工清单与兼容投影,不得作为新状态键。

§7 自修复触发

触发条件处理方式
FC/SC 检查不通过立即修正后重检(FC+SC 累计修正 ≥5 次仍未全通过 → 停止循环,输出剩余失败项摘要标 ⚠️,写入记忆后交由用户决策)
连续 2 次同类偏差升级分析(追加记忆 ⚠️连续违规 + 报告增加「规范偏差分析」章节);不自动进入 self-fix(防递归)
文件路径不符合 02-output-paths.instructions.md立即停止创建,迁移到正确路径
规范文件修改后引用未同步交叉验证后修正

© devcodex-labs, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files in content/skills/compliance of devcodex-labs/devcodex.

  • SKILL.md
  • intent.json
  • workflow-completion.schema.json

Open the folder on GitHubat commit 1dd4525

More from devcodex-labs/devcodex

All 70 skills in this repo
  • Accessibility I18n

    devcodex-labs/devcodex

    无障碍与国际化专家 Owner — 当任务涉及可访问性、键盘操作、焦点、屏幕阅读器、ARIA、语言地区、本地化、RTL、翻译资源、用户可见文案或多语言文档时使用;要求把包容性体验和本地化验证绑定到真实用户路径。

    439 GitHub stars~718 tokensUpdated 20 days ago
    Auto-check passed
  • AI Agent System Architecture

    devcodex-labs/devcodex

    AI Agent 系统架构专家 Owner — 当任务涉及 Agent 路由、工具调用、上下文管理、记忆、状态机、权限、人机协作、可观测性、回放验证或模型辅助治理时使用;要求把 Agent 行为设计成可解释、可恢复、可审计。

    439 GitHub stars~2.4k tokensUpdated 20 days ago
    Auto-check passed
  • API Contract Architecture

    devcodex-labs/devcodex

    API 契约架构专家 Owner — 当任务涉及 public API、HTTP/SDK/CLI 契约、版本兼容、错误模型、分页过滤、幂等、Schema、类型、迁移或消费者影响时使用;要求先冻结消费者契约,再设计实现与验证。

    439 GitHub stars~865 tokensUpdated 20 days ago
    Auto-check passed
  • Architecture Design

    devcodex-labs/devcodex

    架构设计文档编排 Owner — 当用户要求架构设计、系统设计、技术架构或可指导开发、Review 与任务拆分的完整方案时使用;要求从业务流程反推节点、状态、数据、一致性、异常补偿、ADR 与实施任务。

    439 GitHub stars~1.1k tokensUpdated 20 days ago
    Auto-check passed
  • Audit Common

    devcodex-labs/devcodex

    审查公共维度 G0~G5 + Profile Freshness Check — 所有 audit 子类型必先执行的基础维度层

    439 GitHub stars~4.1k tokensUpdated 20 days ago
    Auto-check passed
  • Audit Session

    devcodex-labs/devcodex

    审计工作流的跨会话状态机 — 在 <audit-root/.audit-state/<session-id.json 持久化轮次/发现项/收敛状态,支持 Token 中断后精准恢复

    439 GitHub stars~1.8k tokensUpdated 20 days ago
    Auto-check passed

Questions about Compliance

What does Compliance do?

执行入口检查与 FC/SC/RC/T 合规校验。PC0~PC10 入口检查所有模式启用;仅 dev 模式执行全量合规校验,prod 模式不执行(规范已验证)。chat 豁免合规块。. Compliance is an agent skill from devcodex-labs/devcodex.

How do I install Compliance in Claude Code?

Run `npx skills add devcodex-labs/devcodex --skill compliance -a claude-code`. Or copy the skill folder (content/skills/compliance in devcodex-labs/devcodex) into .claude/skills/compliance in your project. Claude Code loads it when a task matches its description.

How do I install Compliance in Codex?

Run `npx skills add devcodex-labs/devcodex --skill compliance -a codex`. Or copy the skill folder (content/skills/compliance in devcodex-labs/devcodex) into .agents/skills/compliance in your project. Codex loads it when a task matches its description.

Can I use Compliance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add devcodex-labs/devcodex --skill compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/compliance, .gemini/skills/compliance, .github/skills/compliance and .opencode/skills/compliance in your project.

What does Compliance need to run?

Going by SKILL.md and its folder, Compliance needs the command-line tools its instructions call (npm and node).

Does Compliance access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Compliance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Compliance use?

Compliance is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Compliance use?

About 3.6k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

Who maintains Compliance?

devcodex-labs (a GitHub organization) maintains it in devcodex-labs/devcodex, which has 439 GitHub stars. The repository holds 70 skills in this directory. The repository was last updated on September 17, 2026.

Source: devcodex-labs/devcodex on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.