Agent skill

Skill Lifecycle Governance

by devcodex-labs in devcodex-labs/devcodex

Skill 生命周期治理 Owner — 当任务涉及 Skill 组合、重叠冲突、依赖关系、误触发/漏触发、active/gray/deprecated/retired 状态、合并拆分、废弃退役、质量指标或自我进化后的 Skill portfolio 健康度时使用。

AGPL-3.0Auto-check passed

Install Skill Lifecycle Governance

skills CLI
$ npx skills add devcodex-labs/devcodex --skill skill-lifecycle-governance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install devcodex-labs/devcodex skill-lifecycle-governance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .claude/skills && cp -r skills-src/content/skills/skill-lifecycle-governance .claude/skills/skill-lifecycle-governance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
skill-lifecycle-governance
GitHub stars
439
Token cost
~1.8k tokens
SKILL.md length
501 words
Files
3
Skills in repo
70
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Skill 生命周期治理 Owner — 当任务涉及 Skill 组合、重叠冲突、依赖关系、误触发/漏触发、active/gray/deprecated/retired 状态、合并拆分、废弃退役、质量指标或自我进化后的 Skill portfolio 健康度时使用。

  • Works in 7 steps: 建立或刷新 SkillPortfolioIndex 与… → 按触发样本统计命中、误触发、漏触发和人工纠偏。 → 将问题分类为 keep / tune-trigger / split /… → …
  • SKILL.md covers 职责, SkillPortfolioLifecycleGate, 核心门禁 and 执行流程, plus 4 more sections
  • Calls node

What it does

Skill Lifecycle Governance is an agent skill from devcodex-labs/devcodex. Skill 生命周期治理 Owner — 当任务涉及 Skill 组合、重叠冲突、依赖关系、误触发/漏触发、active/gray/deprecated/retired 状态、合并拆分、废弃退役、质量指标或自我进化后的 Skill portfolio 健康度时使用。

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files (for example `agents/openai.yaml` and `intent.json`).

The repository describes itself as: Intent-driven AI coding workflow runtime for consistent context, skills, approvals, validation, and handoffs across six AI coding hosts. The licence is AGPL-3.0.

Example prompts

  • “/skill-lifecycle-governance”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. 建立或刷新 SkillPortfolioIndex 与 SkillDependencyGraph。
  2. 按触发样本统计命中、误触发、漏触发和人工纠偏。
  3. 将问题分类为 keep / tune-trigger / split / merge / gray / deprecate / retire / blocked。
  4. 形成 LifecycleChangeSet,列 affectedUnits、consumer delta、dependency delta、risk、validation、rollout、rollback。
  5. 由 evolution-governance 校验授权;active/release 前执行 full validation 和人工审批。
  6. 返工治理 Skill 追加前瞻试运行;普通晋级至少覆盖 3 个可比 WorkUnit 或 2 个独立上下文,P0/P1 紧急启用也必须补后验观察窗。
  7. 更新 TriggerQualityScorecard、ConflictDecision、DeprecationPlan 或 RetirementEvidence。

What it can do on your machine

Read from SKILL.md and the folder at commit 1dd4525. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Skill Lifecycle Governance loads about 1.8k tokens when it runs. Until then it costs about 40 tokens; SKILL.md has 501 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~40
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from devcodex-labs/devcodex at commit 1dd4525, republished under its AGPL-3.0 licence (© devcodex-labs). 501 words, ~1,801 tokens.

Download SKILL.mdSave it as .claude/skills/skill-lifecycle-governance/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
skill-lifecycle-governance
description
Skill 生命周期治理 Owner — 当任务涉及 Skill 组合、重叠冲突、依赖关系、误触发/漏触发、active/gray/deprecated/retired 状态、合并拆分、废弃退役、质量指标或自我进化后的 Skill portfolio 健康度时使用。

Skill Lifecycle Governance

职责

维护 Skill portfolio 的可发现性、组合质量、状态演进与退役证据。授权、候选生成和 active 发布仍由 evolution-governance 负责;本 Skill 不允许绕过人工采纳或发布审批。

SkillPortfolioLifecycleGate

每个 Skill 在 SkillPortfolioIndex 中记录:name / owner / triggers / ownedArtifacts / consumers / dependencies / conflicts / validationProfile / lifecycleState / version / lastEvidenceAt。

合法状态:draft → gray → active → deprecated → retired,另允许 gray→draft、active→gray 和任意非 retired 状态进入 blocked。禁止 draft→active、active→retired 或 retired 静默恢复。

Gray 可选部署规则:gray Skill 表示可选/试验能力,默认不进入宿主部署面(plugin.json skills 清单、部署副本、init 默认分发);可保留在源仓 skills/ 与 portfolio.json 供验证、文档索引与晋级证据。只有经 evolution-governance 授权并满足激活条件后,才可晋级 active 并纳入默认部署。不得因源码目录存在 gray Skill 就要求消费者安装或强制触发。

DevCodex 源仓的机器可读实例是 skills/portfolio.json(schema v2):由 scripts/generate-skill-portfolio.js 从 skills/*/SKILL.md、plugin.json 与 skills/portfolio-evidence.json 确定性生成,--check 只比较、不改生命周期。严格 dependencies 只承载显式依赖声明;普通 Markdown 关系进入 referenceGraph,避免把互相说明误报成依赖环。

PostStageDerivedArtifactFreshnessGate

当 Skill portfolio 或其他派生资产会受 tracked consumer membership、索引、模板、生成顺序或候选文件集合影响时,普通工作树 --check 不能单独证明提交候选新鲜。commit/tag/publish 前必须先物化完整 staged candidate,再执行 node scripts/generate-skill-portfolio.js --check-staged:该模式从 Git index 读取 package、registry、evidence、Skill source 与 consumer blob,并与 index 内的 skills/portfolio.json 比较;Git/index 不可读或任一输入 stale 时 fail-closed,不得回退工作树后宣称通过。

portfolio 的 generatedFrom 必须分别保留 Skill sourceDigest 与 consumerInventoryFileCount / consumerInventoryDigest / consumerProjectionDigest / portfolioInputDigest。consumer 漂移不得伪装成 Skill 源变化;commit SHA/index tree identity 只进入本次 validation receipt,不写入派生资产,避免自引用。生成后又新增/重命名/删除 consumer 时,正确顺序是:stage 最终输入 → regenerate → stage portfolio → --check-staged。完成声明还需在 commit 后 clean target tree 运行普通 --check;post-stage 与 post-commit 证据互补,不能互相替代。

本 Gate 补充 CandidateDiffCompletenessGate:后者证明 staged candidate 覆盖授权范围,前者证明派生资产与该 candidate 一致。负向夹具必须覆盖“先生成、后 stage consumer”会失败,以及重新生成并 stage 后会通过;changed-scope validation 的 portfolio 节点 inputs 必须覆盖真实 tracked text consumer 扩散面。

SkillIndexV2 与 BundleDecisionV1/V2

每个 portfolio entry 必须包含保守的 skillIndex 投影:id/type/workflow/phase/domains/triggers/requires/conflictsWith/priority/visibility/maxTokens/fixtures/evolvableUnitRef/probeSuiteRefs/exitCondition/evidenceState。没有直接事实时使用空数组、maxTokens=null 或 evidenceState=unverified,禁止凭结构证据编造 workflow/phase/token budget。

buildBundleDecision 只读消费 candidate IDs、当前 lifecycle、显式冲突和可选 maxSkills,输出 selected/ignored/conflicts/budget/exitCondition。ignored reason 固定为 unknown/inactive/conflict/budget;该决策不得写 portfolio、修改 plugin.json 或自动把 gray/draft 晋级 active。

BundleDecisionV2 是渐进加载的正确性 oracle:先校验 active(gray 仅显式 includeGray),再递归闭合 requires,依赖必须排在消费者之前;随后处理 mandatory conflict,并按 priority/id 确定 optional 冲突结果。预算必须使用 SKILL.md canonical UTF-8 全文的精确 sourceBytes,按 maxSkills → maxBytes 选择;只有宿主提供真实 token counter 时才执行 maxTokens,否则固定为 N/A,不得用 bytes 估算 token。

mandatory Skill 或其依赖未知、inactive、owner/sourceBytes 缺失、冲突或真实 token count 缺失时必须 blocked。mandatory 闭包超预算时不得截断 SKILL.md,必须输出依赖优先的完整 Skill stages;宿主不支持 Bundle V2 时必须 fallback-full / full-skill-read。optional 项可因 conflict、budget 或 token-count-missing 被忽略,但不能影响 mandatory 完整性。该 oracle 全程只读,禁止修改 lifecycle、portfolio、plugin.json 或部署状态。

BundleDecisionV2 的配置开关必须来自当前 Context plan 的 ExecutionOptimizationPlanBindingV1,随后再以同一 active-root 的 ExecutionOptimizationFeatureDecisionV1 校验 skill-bundle lifecycle。模式为 full-only、绑定缺失/损坏、feature 为 off / shadow / rolled-back / sunset、状态无效或消费者不支持该契约时,一律返回 fallback-full / full-skill-read;不得为了读取开关额外加载 Profile config,也不得把 fallback 冒充 bundle 命中。Skill lifecycle 与执行优化 lifecycle 相互独立:回退 bundle 不得修改 portfolio 的 active/gray 状态。

Show full SKILL.md (209 more words)Show less
激活条件
  • 有明确自然语言触发和独立 Owner。
  • 至少一个 current consumer、正向 fixture、负向 fixture 和回滚计划。
  • 依赖图无循环,冲突/优先级决策可解释。
  • 已通过 evolution-governance 授权与 LayeredAbsorptionDecision。
  • 新增或改变能力入口时,已引用 spec-governance#CapabilitySurfaceDecisionGate 的新鲜 decisionRef;中央状态为 stale/blocked 时不得激活或晋级。
  • 声称降低返工或补齐复审逃逸时,已执行 ReworkReductionValueGate;新 Skill 先进入 gray,只有 ReworkEffectivenessLoop 的前瞻证据达到样本门槛后才可申请 active。

Skill 本地资产只记录触发、Owner、消费者、生命周期和 decisionRef 等元数据;不得复制中央 preferredSurface / controlParty / runtimeOwner / truthBoundary 字段,也不得因某个领域 Skill 提出能力就绕过中央单写者直接新建 Skill 或 MCP surface。

退役条件
  • deprecated 已给迁移窗口、替代 Skill 和消费者清单。
  • 当前消费者为 0,部署副本、routing、plugin、Prompt 和文档引用已清扫。
  • 保留 RetirementEvidence,不得删除历史审计证据。

核心门禁

Gate要求
NoOrphanActiveSkillactive Skill 必须有 owner、consumer、fixture、source path 和 hash/version
NoUnboundedSkillGrowth长期未命中、误触发高、重复 Owner 或无消费者项进入 merge/deprecate review
SkillDependencyGraphGate依赖方向、循环、互斥、组合顺序和预算可验证
TriggerQualityGate记录 precision、falsePositiveRate、falseNegativeRate、manualCorrectionRate
SkillConflictDecisionGate冲突时记录 selected/ignored、priority、budget、理由和 fallback
SkillDeprecationMigrationGate替代项、迁移消费者、观察窗、rollback、retire 条件完整
ReworkEffectivenessPromotionGate返工治理 Skill 的 baseline、prospective trials、效果、误报/开销和 rollback/sunset 完整;只有历史案例或文本 grep 时保持 gray / insufficient-evidence

执行流程

  1. 建立或刷新 SkillPortfolioIndex 与 SkillDependencyGraph。
  2. 按触发样本统计命中、误触发、漏触发和人工纠偏。
  3. 将问题分类为 keep / tune-trigger / split / merge / gray / deprecate / retire / blocked。
  4. 形成 LifecycleChangeSet,列 affectedUnits、consumer delta、dependency delta、risk、validation、rollout、rollback。
  5. 由 evolution-governance 校验授权;active/release 前执行 full validation 和人工审批。
  6. 返工治理 Skill 追加前瞻试运行;普通晋级至少覆盖 3 个可比 WorkUnit 或 2 个独立上下文,P0/P1 紧急启用也必须补后验观察窗。
  7. 更新 TriggerQualityScorecard、ConflictDecision、DeprecationPlan 或 RetirementEvidence。

健康指标

至少跟踪:skillTriggerPrecision、falsePositiveRate、falseNegativeRate、ruleReuseCount、orphanUnitCount、deprecatedAge、rollbackRate、instructionBudgetP95、manualCorrectionRate、repeatedIssueRate;返工治理 Skill 追加 FirstPassYield、WorkUnitReworkRate、RepeatEscapeRate、PreventionHitRate 和 lateDiscoveryCost。

指标只用于发现候选,不得单独触发 active mutation;低样本量必须标记 insufficient-evidence。

输出字段

portfolioIndex、dependencyGraph、lifecycleChangeSet、triggerQualityScorecard、conflictDecision、deprecationPlan、retirementEvidence、authorizationEvidence、validationRoute、rollbackPlan。

反模式

  • 以 Skill 数量增长作为自我进化成功指标。
  • 有相似 Skill 就直接合并,不核对触发、产物和消费者。
  • active Skill 无 owner/fixture/consumer,或 deprecated 永不退役。
  • 用模型建议、单次命中、历史问题数量或文本 grep 直接改变 lifecycle state。
  • 删除 retired Skill 的审计、迁移和回滚证据。

验证

至少覆盖:完整 active、orphan active、循环依赖、draft 直跳 active、active 直退役、误触发超阈值、deprecated 无迁移、gray rollback、retired 引用残留和低样本指标不得自动决策。

源仓最小命令:日常运行 node scripts/generate-skill-portfolio.js --check + node scripts/test-skill-portfolio.js;提交候选追加 node scripts/generate-skill-portfolio.js --check-staged,提交后在 clean target tree 重跑普通 --check。静态消费者和注册事实可以证明集合/引用完整,但 precision、false positive/negative 与人工纠偏率没有真实样本时必须保持 insufficient-evidence;SkillIndex source-backed 也不能替代触发 precision 的真实测量。

© devcodex-labs, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files in content/skills/skill-lifecycle-governance of devcodex-labs/devcodex.

  • SKILL.md
  • agents/openai.yaml
  • intent.json

Open the folder on GitHubat commit 1dd4525

Compare with similar skills

Skill Lifecycle Governance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Skill Lifecycle Governance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Skill Lifecycle Governance this skilldevcodex-labs/devcodex439—~1.8kAutomated safety check: PassAGPL-3.0
Board Governancesickn33/agentic-awesome-skills47k1 repos~4.1kAutomated safety check: PassMIT
Agent Governancegithub/awesome-copilot40k2 repos~4.6kAutomated safety check: PassMIT
Model Registry Governancesickn33/agentic-awesome-skills47k2 repos~3.9kAutomated safety check: PassMIT
Protect MCP Governancesickn33/agentic-awesome-skills47k2 repos~2.3kAutomated safety check: PassMIT
Living Docs Governanceaffaan-m/ECC274k1 repos~2.1kAutomated safety check: PassMIT

Similar skills

  • Board Governance

    sickn33/agentic-awesome-skills

    Board and governance register: meeting date, agenda, decision, resolution number, vote result, action owner and due date.

    47k GitHub starsUsed in 1 repo~4.1k tokens
    Auto-check passed
  • Agent Governance

    github/awesome-copilot

    Official

    Patterns and techniques for adding governance, safety, and trust controls to AI agent systems.

    40k GitHub starsUsed in 2 repos~4.6k tokens
    AI & LLM EngineeringAuto-check passed
  • Model Registry Governance

    sickn33/agentic-awesome-skills

    Establish model registry standards, governance controls, metadata schemas, approvals, and lifecycle policies for enterprise AI deployments.

    47k GitHub starsUsed in 2 repos~3.9k tokens
    DevOps & CloudAuto-check passed
  • Protect MCP Governance

    sickn33/agentic-awesome-skills

    Agent governance skill for MCP tool calls — Cedar policy authoring, shadow-to-enforce rollout, and Ed25519 receipt verification.

    47k GitHub starsUsed in 2 repos~2.3k tokens
    Agent WorkflowsAuto-check passed
  • Keep a long-lived project's documentation from rotting by assigning existing project docs clear constitution, map, status, and history roles, then wiring the active agent harness to those canonical…

    274k GitHub starsUsed in 1 repo~2.1k tokens
    DevelopmentAuto-check passed
  • Governance

    plugin87/ux-ui-agent-skills

    Govern how the design system evolves — SemVer for tokens/components, the contribution workflow, deprecation policy, and change communication.

    1.5k GitHub stars~613 tokensUpdated today
    Frontend & DesignAuto-check passed

More from devcodex-labs/devcodex

All 70 skills in this repo
  • Accessibility I18n

    devcodex-labs/devcodex

    无障碍与国际化专家 Owner — 当任务涉及可访问性、键盘操作、焦点、屏幕阅读器、ARIA、语言地区、本地化、RTL、翻译资源、用户可见文案或多语言文档时使用;要求把包容性体验和本地化验证绑定到真实用户路径。

    439 GitHub stars~718 tokensUpdated 20 days ago
    Auto-check passed
  • AI Agent System Architecture

    devcodex-labs/devcodex

    AI Agent 系统架构专家 Owner — 当任务涉及 Agent 路由、工具调用、上下文管理、记忆、状态机、权限、人机协作、可观测性、回放验证或模型辅助治理时使用;要求把 Agent 行为设计成可解释、可恢复、可审计。

    439 GitHub stars~2.4k tokensUpdated 20 days ago
    Auto-check passed
  • API Contract Architecture

    devcodex-labs/devcodex

    API 契约架构专家 Owner — 当任务涉及 public API、HTTP/SDK/CLI 契约、版本兼容、错误模型、分页过滤、幂等、Schema、类型、迁移或消费者影响时使用;要求先冻结消费者契约,再设计实现与验证。

    439 GitHub stars~865 tokensUpdated 20 days ago
    Auto-check passed
  • Architecture Design

    devcodex-labs/devcodex

    架构设计文档编排 Owner — 当用户要求架构设计、系统设计、技术架构或可指导开发、Review 与任务拆分的完整方案时使用;要求从业务流程反推节点、状态、数据、一致性、异常补偿、ADR 与实施任务。

    439 GitHub stars~1.1k tokensUpdated 20 days ago
    Auto-check passed
  • Audit Common

    devcodex-labs/devcodex

    审查公共维度 G0~G5 + Profile Freshness Check — 所有 audit 子类型必先执行的基础维度层

    439 GitHub stars~4.1k tokensUpdated 20 days ago
    Auto-check passed
  • Audit Session

    devcodex-labs/devcodex

    审计工作流的跨会话状态机 — 在 <audit-root/.audit-state/<session-id.json 持久化轮次/发现项/收敛状态,支持 Token 中断后精准恢复

    439 GitHub stars~1.8k tokensUpdated 20 days ago
    Auto-check passed

Questions about Skill Lifecycle Governance

What does Skill Lifecycle Governance do?

Skill 生命周期治理 Owner — 当任务涉及 Skill 组合、重叠冲突、依赖关系、误触发/漏触发、active/gray/deprecated/retired 状态、合并拆分、废弃退役、质量指标或自我进化后的 Skill portfolio 健康度时使用。. Skill Lifecycle Governance is an agent skill from devcodex-labs/devcodex.

How do I install Skill Lifecycle Governance in Claude Code?

Run `npx skills add devcodex-labs/devcodex --skill skill-lifecycle-governance -a claude-code`. Or copy the skill folder (content/skills/skill-lifecycle-governance in devcodex-labs/devcodex) into .claude/skills/skill-lifecycle-governance in your project. Claude Code loads it when a task matches its description.

How do I install Skill Lifecycle Governance in Codex?

Run `npx skills add devcodex-labs/devcodex --skill skill-lifecycle-governance -a codex`. Or copy the skill folder (content/skills/skill-lifecycle-governance in devcodex-labs/devcodex) into .agents/skills/skill-lifecycle-governance in your project. Codex loads it when a task matches its description.

Can I use Skill Lifecycle Governance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add devcodex-labs/devcodex --skill skill-lifecycle-governance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/skill-lifecycle-governance, .gemini/skills/skill-lifecycle-governance, .github/skills/skill-lifecycle-governance and .opencode/skills/skill-lifecycle-governance in your project.

What does Skill Lifecycle Governance need to run?

Going by SKILL.md and its folder, Skill Lifecycle Governance needs the command-line tools its instructions call (node).

Does Skill Lifecycle Governance access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Skill Lifecycle Governance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Skill Lifecycle Governance use?

Skill Lifecycle Governance is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Skill Lifecycle Governance use?

About 1.8k tokens (SKILL.md is roughly 7.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Skill Lifecycle Governance?

Skills that share tags, products or a category with Skill Lifecycle Governance: Board Governance (sickn33/agentic-awesome-skills, 47k stars), Agent Governance (github/awesome-copilot, 40k stars), Model Registry Governance (sickn33/agentic-awesome-skills, 47k stars) and Protect MCP Governance (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Skill Lifecycle Governance?

devcodex-labs (a GitHub organization) maintains it in devcodex-labs/devcodex, which has 439 GitHub stars. The repository holds 70 skills in this directory. The repository was last updated on September 17, 2026.

Source: devcodex-labs/devcodex on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.