Agent skill

Consumer Validation Engineering

by devcodex-labs in devcodex-labs/devcodex

跨仓消费者验证工程 Owner — 当任务涉及独立 consumer/verification repository、SDK/CLI/框架/公共包的跨仓完整验证、源码 link 与 packed artifact 一致性、多分母 100% 声明、跨仓 CI、新鲜度或漂移治理时使用;要求冻结可复现身份链、分别计算适用分母,并以真实安装和跨仓运行证据约束发布。

AGPL-3.0Auto-check passed

Install Consumer Validation Engineering

skills CLI
$ npx skills add devcodex-labs/devcodex --skill consumer-validation-engineering -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install devcodex-labs/devcodex consumer-validation-engineering --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .claude/skills && cp -r skills-src/content/skills/consumer-validation-engineering .claude/skills/consumer-validation-engineering && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
consumer-validation-engineering
GitHub stars
439
Token cost
~1.8k tokens
SKILL.md length
469 words
Files
2
Skills in repo
70
Repo updated
First seen
Licence
AGPL-3.0

At a glance

跨仓消费者验证工程 Owner — 当任务涉及独立 consumer/verification repository、SDK/CLI/框架/公共包的跨仓完整验证、源码 link 与 packed artifact 一致性、多分母 100% 声明、跨仓 CI、新鲜度或漂移治理时使用;要求冻结可复现身份链、分别计算适用分母,并以真实安装和跨仓运行证据约束发布。

  • Works in 6 steps: 两仓 origin、branch、commit、dirty state 与… → package version、源码 package… → dependency spec、resolved… → …
  • SKILL.md covers 定位, 触发条件, ConsumerValidationEngineeringGa… and 多分母完整性规则, plus 9 more sections
  • Calls npm

What it does

Consumer Validation Engineering is an agent skill from devcodex-labs/devcodex. 跨仓消费者验证工程 Owner — 当任务涉及独立 consumer/verification repository、SDK/CLI/框架/公共包的跨仓完整验证、源码 link 与 packed artifact 一致性、多分母 100% 声明、跨仓 CI、新鲜度或漂移治理时使用;要求冻结可复现身份链、分别计算适用分母,并以真实安装和跨仓运行证据约束发布。

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

The repository describes itself as: Intent-driven AI coding workflow runtime for consistent context, skills, approvals, validation, and handoffs across six AI coding hosts. The licence is AGPL-3.0.

Example prompts

  • “/consumer-validation-engineering”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. 两仓 origin、branch、commit、dirty state 与 diff hash。
  2. package version、源码 package hash、构建命令、dist hash;dist 被 ignore 时仍必须单独冻结。
  3. dependency spec、resolved realpath、lockfile hash,以及无关兄弟仓/绝对路径残留检查。
  4. tarball checksum、pack manifest、fresh install 路径和 registry metadata(若命中)。
  5. source event、consumer CI event/run、checkout topology、目标 commit 与最终 conclusion。
  6. run 结束时重新采集 1~5;任一身份变化而未重跑即标 stale。

What it can do on your machine

Read from SKILL.md and the folder at commit 1dd4525. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Consumer Validation Engineering loads about 1.8k tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 469 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from devcodex-labs/devcodex at commit 1dd4525, republished under its AGPL-3.0 licence (© devcodex-labs). 469 words, ~1,820 tokens.

Download SKILL.mdSave it as .claude/skills/consumer-validation-engineering/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
consumer-validation-engineering
description
跨仓消费者验证工程 Owner — 当任务涉及独立 consumer/verification repository、SDK/CLI/框架/公共包的跨仓完整验证、源码 link 与 packed artifact 一致性、多分母 100% 声明、跨仓 CI、新鲜度或漂移治理时使用;要求冻结可复现身份链、分别计算适用分母,并以真实安装和跨仓运行证据约束发布。

Consumer Validation Engineering

定位

本 Skill 负责“主仓变更是否被真实消费者以可复现方式验证”的完整证据链。它不把 dependency spec、realpath、单次 link smoke、功能清单数量或单一通过率当作跨仓闭环,而是同时管理仓库绑定、源码/制品身份、多分母验证、跨仓 CI、新鲜度和发布阻断。

触发条件

场景是否触发
为 SDK、CLI、框架、插件或公共包建立独立 consumer/test/verification repository必须
声称“跨仓完整验证”“全场景 100%”“消费者仓已覆盖全部功能”必须
同时存在源码 link、workspace/file dependency、tarball、registry install 或 ignored dist必须
主仓 push/PR/release 需要触发消费者仓 CI,或需要定时漂移检测必须
仅在同一仓库内执行单元测试且无外部消费者边界N/A + skipReason

ConsumerValidationEngineeringGate

字段要求
repositoryBinding主仓、消费者仓、origin、目标 branch、责任人、发布关系和支持矩阵
sourceConsumerIdentityrun 前后冻结两仓 commit、dirty/diff hash、版本、构建与依赖解析身份
artifactFreshness源码、dist、tarball、registry artifact 的生成时间、内容 hash 和来源 commit 可追溯
dependencyResolutiondependency spec、realpath、lockfile hash/hygiene 与 CI checkout 目录拓扑一致
packedArtifactIdentitytarball checksum、pack list、安装路径、公开 API/CLI/Skill/adapter smoke
validationDenominators功能、场景、adapter/环境、影响变更、性能适用项、发布门禁分别计算
designFitness每个适用功能的用户主路径、默认值、配置层级、框架约定、公共面、生命周期、组合、兼容与维护成本
crossRepositoryCICrossRepoCI:source push/PR/release dispatch、consumer workflow/run、目标 SHA 和结果可关联
freshnessDriftbefore/after identity 复核、定时漂移、证据保留、过期阈值和失效处理
evidenceStatenot-started / partial / accepted / rejected / stale,每个分母独立记录
releaseDecision只有全部适用分母 accepted 且身份链新鲜,才允许 complete/100% 或 release-ready 声明

多分母完整性规则

denominator最低内容禁止替代证据
featurepublic exports、CLI commands、配置、文档能力与内部能力归类README 条目数
scenariohappy/error/retry/timeout/compatibility/upgrade 适用场景单元测试总数
adapterEnvironmentruntime、OS、Node/runtime version、provider/adapter 适用组合默认脚手架成功
changeImpact本次 diff 影响的功能、消费者、迁移和回归集合全量套件名称
performance每功能适用性与每模块 workload/budget/baseline/candidate/capacity/resource/recovery单一 benchmark gate
releaseGatepack/install、public surface、CI、文档、回滚、registry/postcheck本地 link smoke

任何适用分母不是 100% accepted 时,总结只能是 partial;N/A 必须有适用性依据,skip/flake 必须进入治理分母,不能从统计中静默删除。

可复现身份链

正式 run 至少记录:

  1. 两仓 origin、branch、commit、dirty state 与 diff hash。
  2. package version、源码 package hash、构建命令、dist hash;dist 被 ignore 时仍必须单独冻结。
  3. dependency spec、resolved realpath、lockfile hash,以及无关兄弟仓/绝对路径残留检查。
  4. tarball checksum、pack manifest、fresh install 路径和 registry metadata(若命中)。
  5. source event、consumer CI event/run、checkout topology、目标 commit 与最终 conclusion。
  6. run 结束时重新采集 1~5;任一身份变化而未重跑即标 stale。

执行流程

  1. 冻结 ConsumerRepositoryBinding,明确哪个仓是 source of truth、哪个仓提供独立复证。
  2. 建立 SourceConsumerIdentitySnapshot,先验证工作区/CI 能按依赖声明重建目录拓扑。
  3. 生成 ValidationDenominatorMatrix,逐项记录 total/applicable/executed/accepted/skipped/failed/stale。
  4. 先跑 source link/workspace 验证,再 pack tarball fresh install;两条路线不能互相替代。
  5. 运行影响场景、全量回归、适用性能与发布门禁,保存原生命令退出码和制品 hash。
  6. 关联跨仓 CI event/run;主仓没有真实触发链时不得宣称持续验证。
  7. 执行 before/after drift 复核,更新 evidenceState 和 releaseDecision。
  8. 将主仓、消费者仓、报告、CI、制品和 registry 证据写入可追踪矩阵。

DesignFitnessGate

行为测试通过只能证明“现有契约按定义运行”,不能证明契约设计合理。对 SDK、框架、CLI 或公共包的每个适用功能建立 DesignFitnessMatrix,至少覆盖:

feature / userTask / recommendedPath / defaults / configurationLayering / frameworkConvention / publicSurface / lifecycle / composition / compatibilityAuthority / maintenanceCost / evidence / decision。

发现重复配置、手动装配、内部 API 泄漏、多 runtime 不一致、与框架约定冲突或维护成本无依据时,该功能不得仅凭行为测试标 accepted。设计取舍需由 DX/API/domain/quality Owner 给出证据,消费者仓不能反向独占定义主仓公共契约。

Show full SKILL.md (208 more words)Show less

ValidationFindingRepairLoop

  1. finding 先绑定 source identity、受影响 denominator、严重度和 authority;validation/audit 本身不越权直接修改 source。
  2. FindingObjectLayer(PI-VEXT-20260717-024 / T2):每条 finding 必须声明 objectLayer=source-product | verification-system。source-product 记录被测产品问题与 source patch;verification-system 记录验证脚本/证据链/控制面问题。禁止把 verification-system 修复表述为「产品已修复」。探针:classifyFindingObjectLayerSample → 缺分层或混报 layer-fail。
  3. 进入获授权的 dev/fix/self-fix 与双层修复合同,建立 findingToPatchMap。
  4. 任一 source mutation 立即使旧 source identity、artifact 和受影响 evidence 标 stale。
  5. 冻结新 identity,重跑原失败探针、同类边界、关联功能、适用性能和风险要求的全量消费者回归。
  6. before/after identity、freshness 与 denominator 均重新 accepted 后才关闭 finding;只重跑原单点不得恢复完整/100% 声明。

FormalRerunLightClassify(PI-20260724-02 · 条件)

进入 full formal / 长耗时 release rerun 前必须先轻量分类(读 issue authority、最近 run decision、issue-snapshot):

class含义
close-with-fresh可用已有 fresh run 关闭
unmet-fresh已有 fresh run 未满足
blocked-by-open同批 open blocker 阻断
shared-rerun同批多项可共享一次 formal
need-full-per-finding仅当分类证明需要且无共享收益时(默认 禁止 作为首选)

除非分类显示可关闭候选或同批共享收益,不得按 finding 粒度逐项启动 full formal。探针:classifyFormalRerunLightSample — startingFullFormal && !classified → rerun-fail;npm run test:executable-absorption-gates。

输出契约

markdown
## ConsumerValidationEngineeringGate

| 字段 | 内容 |
|---|---|
| repositoryBinding | source/consumer origins, branches, owners |
| sourceConsumerIdentity | commits, dirty/diff hashes, versions |
| artifactFreshness | source/dist/tarball/registry hashes |
| dependencyResolution | spec, realpath, lock hygiene, checkout topology |
| validationDenominators | denominator -> total/applicable/accepted/failed/skipped/stale |
| designFitness | feature -> task/default/config/framework/public/lifecycle/composition/compatibility/maintenance decision |
| validationFindingRepair | finding -> authorized patch -> stale evidence -> new identity -> rerun matrix -> result |
| crossRepositoryCI | source event -> consumer run -> target SHA -> conclusion |
| evidenceFreshness | capturedAt, expiresAt, before/after drift |
| releaseDecision | not-started/partial/accepted/rejected/stale |
| evidenceMatrix | claim -> source -> command/run -> artifact -> consumer |

生命周期与有效性

本 Skill 初始状态为 gray。只有在至少两个独立项目或三个可比较工作单元中证明:身份漂移被提前捕获、多分母假 100% 被阻断、发布后消费者逃逸率下降,且没有通过减少适用分母刷指标,才可进入 active review。晋级、回滚和 sunset 由 skill-lifecycle-governance 与 evolution-governance 决定。

反模式

反模式修正
realpath 正确就声称跨仓关联完成补两仓 identity、artifact、lock、CI event/run 和 before/after drift
功能清单 100% 就声称验证 100%独立计算功能、场景、组合、影响、性能和发布分母
link 成功替代 packed install两条路线都执行,并比较公开表面与制品 hash
CI 名称存在就声称持续验证证明 source event 实际触发 consumer run 且目标 SHA 一致
把 skip/N/A/flake 从分母删除记录适用性、原因、owner、期限与重试/阻断状态
运行中 source 或 dist 改变仍沿用结果标 stale,冻结新 identity 后重跑
行为测试全绿就认定设计合理执行 DesignFitnessGate,分别判断契约设计和行为实现
修源码后只重跑原失败单点执行 ValidationFindingRepairLoop,旧 identity 证据 stale 并按影响矩阵重跑
验证系统修好却写「产品已修复」强制 objectLayer;混报 layer-fail
未分类就逐 finding full formalFormalRerunLightClassify 先分类;rerun-fail

与其他 Skill 的关系

  • source-consumer-sync:维护真相源与当前消费者图;本 Skill 负责外部消费者仓的可执行复证。
  • quality-strategy:定义风险分层和验收矩阵;本 Skill 物化跨仓分母和 evidenceState。
  • test-router:选择单元、集成、场景、性能、pack/install 与 CI 路线。
  • performance-engineering:拥有逐模块性能协议和长期维护基线;本 Skill 只把适用结果纳入跨仓分母。
  • release-verification:消费 accepted 且新鲜的跨仓证据作为发布门禁,不得自行降级 partial。
  • skill-lifecycle-governance / evolution-governance:管理 gray 生命周期、效果指标、回滚与退役。

© devcodex-labs, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in content/skills/consumer-validation-engineering of devcodex-labs/devcodex.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 1dd4525

Compare with similar skills

Consumer Validation Engineering next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Consumer Validation Engineering compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Consumer Validation Engineering this skilldevcodex-labs/devcodex439—~1.8kAutomated safety check: PassAGPL-3.0
Agile Product Ownerdavila7/claude-code-templates32k2 repos~256Automated safety check: PassMIT
Agile Product Owneralirezarezvani/claude-skills28k3 repos~3.2kAutomated safety check: PassMIT
External Consumersforcedotcom/salesforcedx-vscode1k—~1.8kAutomated safety check: PassBSD-3-Clause
Consumer Experience Reviewjaemk/cached2.1k—~1.9kAutomated safety check: PassMIT
Weft ConsumersWeaveMindAI/weft2k—~3.8kAutomated safety check: PassCustom licence

Similar skills

  • Agile Product Owner

    davila7/claude-code-templates

    Agile product ownership toolkit for Senior Product Owner including INVEST-compliant user story generation, sprint planning, backlog management, and velocity tracking.

    32k GitHub starsUsed in 2 repos~256 tokens
    Product & Project ManagementAuto-check passed
  • Agile Product Owner

    alirezarezvani/claude-skills

    Writes INVEST-checked user stories with acceptance criteria, splits epics, plans sprints from velocity and ranks the backlog with a weighted score.

    28k GitHub starsUsed in 3 repos~3.2k tokens
    Product & Project ManagementAuto-check passed
  • External Consumers

    forcedotcom/salesforcedx-vscode

    Known external consumers of APIs from this monorepo's extensions.

    1k GitHub stars~1.8k tokensUpdated today
    DevelopmentAuto-check passed
  • Review a library/package from the perspective of an external downstream consumer — build a throwaway crate/project that depends on it the way a real user would, exercise the public API, and surface…

    2.1k GitHub stars~1.9k tokensUpdated 6 days ago
    Frontend & DesignAuto-check passed
  • Weft Consumers

    WeaveMindAI/weft

    Read when the user wants their own website, app, bot or extension to list, show, answer, skip or cancel what a program is waiting on, fetch a file it carries, or show what one of its nodes is…

    2k GitHub stars~3.8k tokensUpdated yesterday
    Auto-check passed
  • Salon Owner

    FerroxLabs/wayland

    Complete operations guide for salon and barbershop owners covering booking systems, inventory management, staff commission structures, client retention, retail product sales, social media marketing…

    608 GitHub stars~4.7k tokensUpdated yesterday
    Marketing & SEOAuto-check passed

More from devcodex-labs/devcodex

All 70 skills in this repo
  • Accessibility I18n

    devcodex-labs/devcodex

    无障碍与国际化专家 Owner — 当任务涉及可访问性、键盘操作、焦点、屏幕阅读器、ARIA、语言地区、本地化、RTL、翻译资源、用户可见文案或多语言文档时使用;要求把包容性体验和本地化验证绑定到真实用户路径。

    439 GitHub stars~718 tokensUpdated 21 days ago
    Auto-check passed
  • AI Agent System Architecture

    devcodex-labs/devcodex

    AI Agent 系统架构专家 Owner — 当任务涉及 Agent 路由、工具调用、上下文管理、记忆、状态机、权限、人机协作、可观测性、回放验证或模型辅助治理时使用;要求把 Agent 行为设计成可解释、可恢复、可审计。

    439 GitHub stars~2.4k tokensUpdated 21 days ago
    Auto-check passed
  • API Contract Architecture

    devcodex-labs/devcodex

    API 契约架构专家 Owner — 当任务涉及 public API、HTTP/SDK/CLI 契约、版本兼容、错误模型、分页过滤、幂等、Schema、类型、迁移或消费者影响时使用;要求先冻结消费者契约,再设计实现与验证。

    439 GitHub stars~865 tokensUpdated 21 days ago
    Auto-check passed
  • Architecture Design

    devcodex-labs/devcodex

    架构设计文档编排 Owner — 当用户要求架构设计、系统设计、技术架构或可指导开发、Review 与任务拆分的完整方案时使用;要求从业务流程反推节点、状态、数据、一致性、异常补偿、ADR 与实施任务。

    439 GitHub stars~1.1k tokensUpdated 21 days ago
    Auto-check passed
  • Audit Common

    devcodex-labs/devcodex

    审查公共维度 G0~G5 + Profile Freshness Check — 所有 audit 子类型必先执行的基础维度层

    439 GitHub stars~4.1k tokensUpdated 21 days ago
    Auto-check passed
  • Audit Session

    devcodex-labs/devcodex

    审计工作流的跨会话状态机 — 在 <audit-root/.audit-state/<session-id.json 持久化轮次/发现项/收敛状态,支持 Token 中断后精准恢复

    439 GitHub stars~1.8k tokensUpdated 21 days ago
    Auto-check passed

Questions about Consumer Validation Engineering

What does Consumer Validation Engineering do?

跨仓消费者验证工程 Owner — 当任务涉及独立 consumer/verification repository、SDK/CLI/框架/公共包的跨仓完整验证、源码 link 与 packed artifact 一致性、多分母 100% 声明、跨仓 CI、新鲜度或漂移治理时使用;要求冻结可复现身份链、分别计算适用分母,并以真实安装和跨仓运行证据约束发布。. Consumer Validation Engineering is an agent skill from devcodex-labs/devcodex.

How do I install Consumer Validation Engineering in Claude Code?

Run `npx skills add devcodex-labs/devcodex --skill consumer-validation-engineering -a claude-code`. Or copy the skill folder (content/skills/consumer-validation-engineering in devcodex-labs/devcodex) into .claude/skills/consumer-validation-engineering in your project. Claude Code loads it when a task matches its description.

How do I install Consumer Validation Engineering in Codex?

Run `npx skills add devcodex-labs/devcodex --skill consumer-validation-engineering -a codex`. Or copy the skill folder (content/skills/consumer-validation-engineering in devcodex-labs/devcodex) into .agents/skills/consumer-validation-engineering in your project. Codex loads it when a task matches its description.

Can I use Consumer Validation Engineering in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add devcodex-labs/devcodex --skill consumer-validation-engineering -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/consumer-validation-engineering, .gemini/skills/consumer-validation-engineering, .github/skills/consumer-validation-engineering and .opencode/skills/consumer-validation-engineering in your project.

What does Consumer Validation Engineering need to run?

Going by SKILL.md and its folder, Consumer Validation Engineering needs the command-line tools its instructions call (npm).

Does Consumer Validation Engineering access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Consumer Validation Engineering safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Consumer Validation Engineering use?

Consumer Validation Engineering is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Consumer Validation Engineering use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Consumer Validation Engineering?

Skills that share tags, products or a category with Consumer Validation Engineering: Agile Product Owner (davila7/claude-code-templates, 32k stars), Agile Product Owner (alirezarezvani/claude-skills, 28k stars), External Consumers (forcedotcom/salesforcedx-vscode, 1k stars) and Consumer Experience Review (jaemk/cached, 2.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Consumer Validation Engineering?

devcodex-labs (a GitHub organization) maintains it in devcodex-labs/devcodex, which has 439 GitHub stars. The repository holds 70 skills in this directory. The repository was last updated on September 17, 2026.

Source: devcodex-labs/devcodex on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.