MCP Server Builder
anthropics/skills
Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.
宿主契约验证规范 — 为 Hook / CLI / bootstrap / visible envelope / workspace guard / LinkCapabilityDecision / MCP fallback 定义 direct replay、fixture replay、部署同步与证据路线
$ npx skills add devcodex-labs/devcodex --skill host-contract-verification -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install devcodex-labs/devcodex host-contract-verification --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .claude/skills && cp -r skills-src/content/skills/host-contract-verification .claude/skills/host-contract-verification && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "host-contract-verification" agent skill from https://github.com/devcodex-labs/devcodex/tree/main/content/skills/host-contract-verification into .claude/skills/host-contract-verification/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "host-contract-verification", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/devcodex-labs/devcodex/tree/main/content/skills/host-contract-verificationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add devcodex-labs/devcodex --skill host-contract-verification -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install devcodex-labs/devcodex host-contract-verification --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .agents/skills && cp -r skills-src/content/skills/host-contract-verification .agents/skills/host-contract-verification && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "host-contract-verification" agent skill from https://github.com/devcodex-labs/devcodex/tree/main/content/skills/host-contract-verification into .agents/skills/host-contract-verification/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "host-contract-verification", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add devcodex-labs/devcodex --skill host-contract-verification -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install devcodex-labs/devcodex host-contract-verification --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/content/skills/host-contract-verification .cursor/skills/host-contract-verification && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "host-contract-verification" agent skill from https://github.com/devcodex-labs/devcodex/tree/main/content/skills/host-contract-verification into .cursor/skills/host-contract-verification/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "host-contract-verification", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/devcodex-labs/devcodex.git --path content/skills/host-contract-verification--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add devcodex-labs/devcodex --skill host-contract-verification -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install devcodex-labs/devcodex host-contract-verification --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/content/skills/host-contract-verification .gemini/skills/host-contract-verification && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "host-contract-verification" agent skill from https://github.com/devcodex-labs/devcodex/tree/main/content/skills/host-contract-verification into .gemini/skills/host-contract-verification/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "host-contract-verification", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install devcodex-labs/devcodex host-contract-verificationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add devcodex-labs/devcodex --skill host-contract-verification -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .github/skills && cp -r skills-src/content/skills/host-contract-verification .github/skills/host-contract-verification && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "host-contract-verification" agent skill from https://github.com/devcodex-labs/devcodex/tree/main/content/skills/host-contract-verification into .github/skills/host-contract-verification/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "host-contract-verification", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add devcodex-labs/devcodex --skill host-contract-verification -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install devcodex-labs/devcodex host-contract-verification --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/content/skills/host-contract-verification .opencode/skills/host-contract-verification && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "host-contract-verification" agent skill from https://github.com/devcodex-labs/devcodex/tree/main/content/skills/host-contract-verification into .opencode/skills/host-contract-verification/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "host-contract-verification", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
host-contract-verification宿主契约验证规范 — 为 Hook / CLI / bootstrap / visible envelope / workspace guard / LinkCapabilityDecision / MCP fallback 定义 direct replay、fixture replay、部署同步与证据路线
Host Contract Verification is an agent skill from devcodex-labs/devcodex. 宿主契约验证规范 — 为 Hook / CLI / bootstrap / visible envelope / workspace guard / LinkCapabilityDecision / MCP fallback 定义 direct replay、fixture replay、部署同步与证据路线
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `intent.json`).
It works with Model Context Protocol. The repository describes itself as: Intent-driven AI coding workflow runtime for consistent context, skills, approvals, validation, and handoffs across six AI coding hosts. The licence is AGPL-3.0.
12 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 1dd4525. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
nodenpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Host Contract Verification loads about 2.6k tokens when it runs. Until then it costs about 45 tokens; SKILL.md has 791 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from devcodex-labs/devcodex at commit 1dd4525, republished under its AGPL-3.0 licence (© devcodex-labs). 791 words, ~2,567 tokens.
.claude/skills/host-contract-verification/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.当任务涉及宿主事件契约、Hook 可见回复、workspace 项目识别、bootstrap 护栏、产物链接可点击性、MCP bridge fallback 或部署副本同步时,本 Skill 负责把“怎么证明宿主行为真的成立”收口为可复审的验证路线。
它不替代 test-router、report 或 runtime tests,而是为这些产物提供统一的宿主证据模型。
| 场景 | 是否触发 |
|---|---|
| Hook runtime / 宿主适配 / Hook 输出契约变更 | 🔴 必须 |
| Stop / PreCompact 可见回复验证语义变更 | 🔴 必须 |
sticky activeProject / mode / workspace guard 变更 | 🔴 必须 |
| Bootstrap、部署副本、父链同步口径变更 | 🔴 必须 |
EntryCheckModelV3 / DevCodexVisibleEnvelopeV3 / V1/V2 只读兼容 / PostCompletionActionSetV1 / UserFacingArtifactSetV1 / LinkCapabilityDecisionV1 / HostLinkCapabilityDecisionV2 / ArtifactDeliveryAttemptV1 变更 | 🔴 必须 |
Copilot / Codex MCP bridge 报错、profile_load fallback、invoke undefined 恢复链变更 | 🔴 必须 |
ContextReadPlanV2 / ContextReadReceiptV2(含 V1 兼容)、Pre/Post 相关性、内容身份/复用、上下文读取 allowlist 或 fallback 语义变更 | 🔴 必须 |
| 公开本地 probe、checkpoint 证据语义或 trace show/replay 变更 | 🔴 必须 |
| 仅普通业务代码改动 | N/A |
| 字段 | 必填 | 说明 |
|---|---|---|
hostSurface | ✅ | Copilot / Claude Code / Codex / instruction-fallback 中本轮实际验证的宿主面 |
eventScope | ✅ | UserPromptSubmit / PreToolUse / PostToolUse / PreCompact / Stop / bootstrap / deploy-sync |
evidenceMode | ✅ | direct replay / fixture replay / targeted test / validate probe / manual trace |
fixtureSource | 条件 | 使用 fixture replay 时记录脚本、payload 或样例来源 |
visibleReplyEvidence | 条件 | verified-present / verified-missing / unverified,以及证据来源 |
workspaceGuard | 条件 | 多项目 workspace、sticky project、workspace profile 提示等边界验证 |
bootstrapScope | 条件 | 父链部署体、入口检查块、adapter 初始化或 update 部署验证 |
artifactLinkMatrix | 条件 | presentationSurface + capability evidence 主选 renderer,hostSurface 只验 adapter 匹配;记录 ArtifactDeliveryAttemptV1 的 actionId/attempted/actionStatus/readback/status/fallbackReason 与 renderer parity |
mcpFallback | 条件 | MCP bridge 失败时是否降级到同计划有界文件读取 / instruction-fallback;记录错误文本、fallback 路线和是否停止重试 |
contextAcquisition | 条件 | plan/epoch/target/source 相关性、Pre attempted、Post success receipt、fallback 与完成状态 |
turnLiveness | 条件 | 长任务/无续接场景的 host-native、Hook-event、sidecar 能力边界,以及 lease、ACK、terminal、checkpoint 证据 |
localProbe | 条件 | LocalProbeDescriptorV1/ResultV1 的 ID、依赖、local-only、同步只读和 zero-write 证据 |
checkpointValidation | 条件 | response-time / post-execution 的 evidence、deadline、status 与 incomplete/timeout 处理 |
localTaskTrace | 条件 | LocalTaskTraceV1 的 sequence、duplicate、terminal、restart 与只读 replay 边界 |
commands | ✅ | 本轮实际执行命令或 targeted tests |
| 变更类型 | 最小验证 |
|---|---|
| Hook 输出契约 | targeted test + direct replay |
| 可见回复三态 | fixture replay 或 direct replay,报告中写明 visibleReplyEvidence |
| sticky project / workspace guard | multi-project fixture + follow-up replay |
| bootstrap / 部署副本 | node scripts/validate.js + 部署同步后的落点复核 |
| managed deployment manifest | legacy 多 owner + workspace-namespace fixture、规范化 destination 单一 current owner、project current host=0、workspace missing/mismatch/stale/duplicate=0、V8 direct replay |
| workspace 宿主作用域 | HostAdapterScopeV1 owner/activation 一致 + 子项目五类 generated host artifact=0 + Grok workspace plugin/用户登记正向 + uninstall/repeat/reinstall 配置保真 + status/doctor 同 owner + root native kernel + child plain partial + devcodex grok --rules full 路线 + --cwd/nested workspace/Windows path identity + outside-workspace no-op 负向 |
| visible set / 产物打开 | manifest/projection property test + Codex Desktop、VS Code、Zed、WebStorm、Codex CLI、Claude/unknown renderer fixture;renderer-only 必须 fallback,opened 必须同时具备 action success + readback success;若声称当前 presentationSurface 已打开,需 direct replay 或用户实测证据 |
| MCP bridge fallback | MCP server no-args direct replay + 非 Full 宿主 fallback 文案探针;若错误来自宿主桥接层,只能声明 fallback 已覆盖,不能声明宿主 bug 已修复 |
| 意图驱动上下文获取 | ContextAcquisitionToolAllowlistProbe + plan/receipt direct replay + Pre/Post fixture + hidden-full-read 负例 + fallback no-deadlock |
| Turn Liveness / orphaned turn | state-machine fault matrix + Hook direct replay + restart rehydrate;事件停止后的 proactive 检测只能由 host-native watchdog 或 gray read-only sidecar 证明 |
| 本地 probe | descriptor/dependency/error fixture + CLI JSON/human replay + state hash zero-write;不得联网、启动 watcher 或写 telemetry |
| checkpoint / local trace | fixed-clock 双阶段 fixture + Hook terminal replay + sequence/duplicate/restart/terminal 负例;trace replay 必须证明 payload 不执行且源 state hash 不变 |
| 仅文档声明变更 | source-consumer-sync + validate probe;若声称宿主行为改变则不得只改文档 |
Stop/PreCompact 对最终回复证据必须使用 verified-present / verified-missing / unverified:只有观察到可解析 assistant 内容和当前 DevCodexVisibleEnvelopeV3 marker、合法动作标题、语义 item 才能判定 present/missing;V1/V2 marker 只记录 legacy-v1-read-only / legacy-v2-read-only,不得把它当作新写入证据。未观察到只能 unverified。记录 evidenceSource / missingItems / semanticDigest,不得保存不必要的完整回复正文。
legacy “主要产物 + 绝对路径”最多为 unverified-legacy。能力未 direct 验证时保持 portable/plain;Rich clickable 只显示单个语义链接。session、daily、SUMMARY、task/checkpoint 和 raw ledger 默认 internal-only,但宿主验证仍要核对它们已进入 internal manifest 和 ECR。
PreToolUse 与 PermissionRequest 的文件、命令、删除及工具调用权限完全归当前宿主和用户宿主配置。DevCodex 只能记录风险 advisory、telemetry 或 typed workflow-invalid;runtime、输出 builder 和每个宿主 adapter 均不得发出或转译 allow / deny / ask / block / continue:false 操作权限载荷。Stop、PreCompact 等非操作生命周期完成门禁不受此条影响。验证必须向 Codex、Claude、Gemini、Copilot、Grok、Cursor 注入遗留允许/拒绝载荷,并证明最终操作事件投影不含任何 permission carrier。
ContextAcquisitionToolAllowlistProbe 只允许已注册的只读 Profile / memory 查询工具推进 source state;普通文件搜索、写工具、legacy no-args 全文读取或未知工具不得伪造完成。PreToolUse 只记录 correlated attempted;只有 PostToolUse 中可解析的成功结果,且 invocation planId、planContentId、contextEpoch、activeRoot、tool/source/query 全部匹配时,才生成或推进 ContextReadReceiptV2(V1 兼容)。ContextDeliveryReuseHostProbe 必须分别证明 computation reuse 与 delivery reuse:跨进程只允许复用内容身份绑定的计算元数据;正文省略还必须同 host session、同 epoch、同 source identity 且当前模型已有成功 body observation。宿主无法提供稳定 session 或 Post body 证据时 delivery reuse 必须降级为 false。unverified,不能由提示文案升级为 relevant-complete/completed。PreToolUse/PermissionRequest 保持 advisory-only;Stop 等非操作生命周期事件可按宿主能力恢复 hard default。bootstrap 与 observe 均保持。unverified,不能伪造 verified-present。profile_load / MCP 工具出现 Cannot read properties of undefined (reading 'invoke') 时,若 DevCodex MCP server direct replay 通过,应记录为宿主 MCP bridge 失败并启用 mcpFallback=used,禁止反复重试同一 MCP 调用。host-native-verified / hook-event-verified / sidecar-observed / unsupported / unverified;PostToolUse 落盘只能证明工具结果已观察,不能证明模型续接或 turn 已终态。CheckpointValidationResultV1 缺失 post-execution evidence 时只能是 unverified 或 incomplete-timeout;只有实际 Hook terminal evidence 才能通过,禁止把等待或 PreCompact 当完成。LocalTaskTraceV1 只保留当前 turn 的 typed data projection;replay 不得 dispatch payload、重放 mutation、改 lifecycle state、唤醒宿主或控制进程。.grok/AGENTS.md 是作用域异常而不是部署成功证据;只有 workspace plugin、用户注册、两 cwd 同 identity 与工作区外 no-op 同时通过,才能升级 Grok workspace 结论。commands/evidenceMode/evidenceCeiling;任何一方通过都不能替另一方升级结论。doctor/status 的 hostParity 必须能给出 failedChecks + 可执行 repairSteps(command + detail);宣称已修复 registration/plugin 缺口时,证据须含再次 doctor --json 的 checks 回读,不得只写「建议 update」。classifyGrokTurnOmissionSample(scripts/lib/host-parity-scorecard.js)。scripts/lib/checked-command.js 的 runChecked / runSequenceChecked,统一记录 command、cwd、exitCode、signal、duration 与 stdout/stderr 摘要。shell:false;只有调用方记录 allowShellReason 时才允许 shell。positional path 中的字面 glob 必须在 spawn 前拒绝,显式 --glob/-g 等 option value 除外。test-router:决定宿主验证是否进入 direct replay / fixture replay / targeted test。execution-contract:记录 verificationEvidence,说明本轮要收集哪些宿主证据。source-consumer-sync:当宿主契约变化会影响 README / website / Profile / 部署副本时,负责同步消费链。report:把 HostContractRoute 的结果写入实施报告或审查报告。## HostContractRoute
| 字段 | 内容 |
|------|------|
| hostSurface | |
| eventScope | |
| evidenceMode | |
| fixtureSource | |
| visibleReplyEvidence | |
| workspaceGuard | |
| bootstrapScope | |
| artifactLinkMatrix | |
| mcpFallback | |
| contextAcquisition | plan/epoch/target/source、allowlist、Pre/Post、receipt、fallback 与完成状态 |
| turnLiveness | capability layer、lease/ACK/terminal/checkpoint、fault matrix 与证据状态 |
| localProbe | descriptor/dependency/local-only/zero-write 与 CLI 证据 |
| checkpointValidation | response-time/post-execution 结果、deadline 与证据状态 |
| localTaskTrace | ordered events、terminal、restart、read-only replay 与 source hash |
| commands | |npm test 通过等价为 direct replay 已覆盖。© devcodex-labs, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in content/skills/host-contract-verification of devcodex-labs/devcodex.
Open the folder on GitHubat commit 1dd4525
Host Contract Verification next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Host Contract Verification this skilldevcodex-labs/devcodex | 439 | — | ~2.6k | Automated safety check: Pass | AGPL-3.0 | |
| MCP Server Builderanthropics/skills | 180k | 62 repos | ~2.3k | Automated safety check: Pass | Apache-2.0 | |
| MCP Server BuildershareAI-lab/learn-claude-code | 78k | 5 repos | ~1.2k | Automated safety check: Pass | MIT | |
| MCP Integration for Pluginsanthropics/claude-plugins-official | 37k | 11 repos | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Figma use_figma Plugin API Ruleswarpdotdev/warp | 65k | 4 repos | ~4.4k | Automated safety check: Pass | AGPL-3.0 | |
| Stitch to Remotion Walkthrough Videosgoogle-labs-code/stitch-skills | 8.4k | 6 repos | ~3.2k | Automated safety check: Notes | Apache-2.0 |
anthropics/skills
Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.
shareAI-lab/learn-claude-code
Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.
anthropics/claude-plugins-official
Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.
warpdotdev/warp
Required groundwork before any use_figma call: the rules and reference files for running JavaScript in a Figma file through the Plugin API without common failures.
google-labs-code/stitch-skills
Builds walkthrough videos from Stitch design projects using Remotion, with transitions, zoom effects and text overlays on each screen.
coollabsio/coolify
A skill your agent uses for Laravel MCP development. An agent skill from coollabsio/coolify.
devcodex-labs/devcodex
无障碍与国际化专家 Owner — 当任务涉及可访问性、键盘操作、焦点、屏幕阅读器、ARIA、语言地区、本地化、RTL、翻译资源、用户可见文案或多语言文档时使用;要求把包容性体验和本地化验证绑定到真实用户路径。
devcodex-labs/devcodex
AI Agent 系统架构专家 Owner — 当任务涉及 Agent 路由、工具调用、上下文管理、记忆、状态机、权限、人机协作、可观测性、回放验证或模型辅助治理时使用;要求把 Agent 行为设计成可解释、可恢复、可审计。
devcodex-labs/devcodex
API 契约架构专家 Owner — 当任务涉及 public API、HTTP/SDK/CLI 契约、版本兼容、错误模型、分页过滤、幂等、Schema、类型、迁移或消费者影响时使用;要求先冻结消费者契约,再设计实现与验证。
devcodex-labs/devcodex
架构设计文档编排 Owner — 当用户要求架构设计、系统设计、技术架构或可指导开发、Review 与任务拆分的完整方案时使用;要求从业务流程反推节点、状态、数据、一致性、异常补偿、ADR 与实施任务。
devcodex-labs/devcodex
审查公共维度 G0~G5 + Profile Freshness Check — 所有 audit 子类型必先执行的基础维度层
devcodex-labs/devcodex
审计工作流的跨会话状态机 — 在 <audit-root/.audit-state/<session-id.json 持久化轮次/发现项/收敛状态,支持 Token 中断后精准恢复
Works with
宿主契约验证规范 — 为 Hook / CLI / bootstrap / visible envelope / workspace guard / LinkCapabilityDecision / MCP fallback 定义 direct replay、fixture replay、部署同步与证据路线. Host Contract Verification is an agent skill from devcodex-labs/devcodex.
Run `npx skills add devcodex-labs/devcodex --skill host-contract-verification -a claude-code`. Or copy the skill folder (content/skills/host-contract-verification in devcodex-labs/devcodex) into .claude/skills/host-contract-verification in your project. Claude Code loads it when a task matches its description.
Run `npx skills add devcodex-labs/devcodex --skill host-contract-verification -a codex`. Or copy the skill folder (content/skills/host-contract-verification in devcodex-labs/devcodex) into .agents/skills/host-contract-verification in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add devcodex-labs/devcodex --skill host-contract-verification -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/host-contract-verification, .gemini/skills/host-contract-verification, .github/skills/host-contract-verification and .opencode/skills/host-contract-verification in your project.
Going by SKILL.md and its folder, Host Contract Verification needs the command-line tools its instructions call (node and npm).
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Host Contract Verification is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Host Contract Verification: MCP Server Builder (anthropics/skills, 180k stars), MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars), MCP Integration for Plugins (anthropics/claude-plugins-official, 37k stars) and Figma use_figma Plugin API Rules (warpdotdev/warp, 65k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
devcodex-labs (a GitHub organization) maintains it in devcodex-labs/devcodex, which has 439 GitHub stars. The repository holds 70 skills in this directory. The repository was last updated on September 17, 2026.
Source: devcodex-labs/devcodex on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.