Caveman Gateway Setup
JuliusBrussee/caveman
Routes every LLM call in a repository through the Caveman Cloud gateway in record mode, so requests and costs are measured without changing behavior.
Define, use, and enforce @cc code-contracts across a codebase.
$ npx skills add ghuntley/underclass --skill code-contracts -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ghuntley/underclass code-contracts --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ghuntley/underclass.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/code-contracts .claude/skills/code-contracts && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "code-contracts" agent skill from https://github.com/ghuntley/underclass/tree/main/.agents/skills/code-contracts into .claude/skills/code-contracts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-contracts", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ghuntley/underclass/tree/main/.agents/skills/code-contractsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ghuntley/underclass --skill code-contracts -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ghuntley/underclass code-contracts --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ghuntley/underclass.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/code-contracts .agents/skills/code-contracts && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "code-contracts" agent skill from https://github.com/ghuntley/underclass/tree/main/.agents/skills/code-contracts into .agents/skills/code-contracts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-contracts", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ghuntley/underclass --skill code-contracts -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ghuntley/underclass code-contracts --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ghuntley/underclass.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/code-contracts .cursor/skills/code-contracts && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "code-contracts" agent skill from https://github.com/ghuntley/underclass/tree/main/.agents/skills/code-contracts into .cursor/skills/code-contracts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-contracts", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ghuntley/underclass.git --path .agents/skills/code-contracts--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ghuntley/underclass --skill code-contracts -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ghuntley/underclass code-contracts --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ghuntley/underclass.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/code-contracts .gemini/skills/code-contracts && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "code-contracts" agent skill from https://github.com/ghuntley/underclass/tree/main/.agents/skills/code-contracts into .gemini/skills/code-contracts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-contracts", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ghuntley/underclass code-contractsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ghuntley/underclass --skill code-contracts -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ghuntley/underclass.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/code-contracts .github/skills/code-contracts && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "code-contracts" agent skill from https://github.com/ghuntley/underclass/tree/main/.agents/skills/code-contracts into .github/skills/code-contracts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-contracts", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ghuntley/underclass --skill code-contracts -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ghuntley/underclass code-contracts --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ghuntley/underclass.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/code-contracts .opencode/skills/code-contracts && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "code-contracts" agent skill from https://github.com/ghuntley/underclass/tree/main/.agents/skills/code-contracts into .opencode/skills/code-contracts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-contracts", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
code-contractsDefine, use, and enforce @cc code-contracts across a codebase.
Code Contracts is an agent skill from ghuntley/underclass. Define, use, and enforce @cc code-contracts across a codebase.
Its SKILL.md is about 4.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).
It sits in DevOps & Cloud. It works with OpenAI. The repository describes itself as: underclass: an OpenAI-compatible pooling proxy that pins sessions to one account (prompt cache stays warm), cools quota-exhausted subscriptions until their window resets, and… The licence is MIT.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 3e35c3b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitnpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git and npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Code Contracts loads about 4.1k tokens when it runs. Until then it costs about 19 tokens; SKILL.md has 2,030 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ghuntley/underclass at commit 3e35c3b, republished under its MIT licence (© ghuntley). 2,030 words, ~4,143 tokens.
.claude/skills/code-contracts/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.A simple open format for specifying structured assumptions and requirements colocated with code to support faster and better agent-driven software development.
/**
* @cc [owner:spolu,label:product] balance-pre-and-fail
* `from.balance` is expected to be greater than or equal to `invoice.amount`, fails with
* `InsufficientBalanceError` otherwise.
*/
/**
* @cc [owner:spolu,label:product] balance-post
* `from.balance` is decreased by `invoice.amount` and `invoice.status` is set to `paid`.
*/
/**
* @cc [owner:spolu,label:product] atomicity
* The operation is atomic: either `from.balance` is decreased and `invoice.status` is set to
* `paid`, or neither is changed.
*/
export async function payInvoice(
invoice: Invoice,
from: Account,
): Promise<PaidInvoice> {
...
}Code contracts are written and used by both humans and agents to reason about code.
They serve three main purposes:
Specification: Compared with separate product or system specification files, which tend to drift from code and are harder to discover, code contracts are embedded locally. Humans use them to reason about behavior without having to inspect implementation details. Agents use them to guide implementations and surface important assumptions to humans and future agents.
Attention: They reduce the cycles required to reason about code by surfacing important assumptions and invariants in a structured way, freeing one of the most bottlenecked resources in modern software development teams: human attention.
Verification: Their structure and granularity enable tooling to enforce compliance and ease maintenance over time. Code contract enforcement provides a verification signal to agents that improves their performance.
Code contracts enable:
npm install --global @spolu/cc-checkThe cc-check command-line interface provides:
cc-check format [file-like]: reports malformed @cc syntax and duplicate contract IDs in a
supported source or CONTRACTS file. Without a path, it recursively inspects every supported file
in the current directory. It never rewrites files or assesses contract prose or implementation
compliance.cc-check list <file-like|location-like>: lists contracts attached to declarations throughout a
supported source file, or contracts applicable to the declaration containing a source location
and its declaration ancestors. Directory-scoped contracts from ancestor CONTRACTS files are
included by default; pass --no-global to exclude them.cc-check format
cc-check format path/file.rs
cc-check list path/to/file.ts:42
cc-check list path/to/file.go@cc directives are extracted from documentation comments in any supported source language. Each
directive defines one code contract. Contracts are generally colocated with or within function,
class, or method definitions.
Code contracts that are not attached to a declaration live in a file named CONTRACTS. They apply
to all code contained in the directory where that file lives and its descendant directories. Their
typical use case is expressing directory-scoped coding rules, such as architectural boundaries,
dependency constraints, or security practices.
CONTRACTS file example:
@cc [owner:spolu,label:architecture] database-access-thru-resources
Database accesses must happen exclusively through `Resource`-like interfaces.
@cc [owner:spolu,label:security] no-sensitive-data-logging
Credentials, tokens, secrets and user data must not be logged.The grammar uses ISO-style EBNF. SP is one or more spaces and NL is a line break. Comment
delimiters and decorations such as /**, */, //, ///, Python docstring triple quotes, and
leading * are removed before parsing.
contracts_file
= { contract, NL } ;
contract = directive, NL, prose ;
directive = "@cc", SP, [ metadata, SP ], contract_id ;
metadata = "[", attribute, { ",", attribute }, "]" ;
attribute = key, ":", value ;
contract_id = token ;
key = token ;
value = token ;
prose = prose_line, { NL, prose_line } ;token is a non-empty sequence without whitespace, commas, colons, or square brackets. Metadata
keys are extensible; owner, notify, and label are well-known. A contract may have multiple
owners, notification recipients, and labels. Prefer ; to separate values within an attribute
instead of repeating its key:
[owner:spolu;tdraier,label:product] instead of
[owner:spolu,owner:tdraier,label:product], or label:product;security for multiple labels.
Repeated keys remain valid. Semicolon-separated lists are a metadata convention; the parser
preserves each value as a single token. prose_line is any line that does not begin with an @cc
directive.
owner lists GitHub usernames to notify when an existing contract is changed or removed. Contract
introductions do not notify owners. notify lists GitHub usernames to notify on every discovered
violation of that contract.
For example, [owner:spolu,notify:spolu;flvndvd,label:product] notifies spolu about contract
changes and both spolu and flvndvd about violations. Owners are not automatically notified about
violations; include them in notify if they want both. Review agents split semicolon lists, combine
repeated keys, and deduplicate usernames.
The prose body is non-empty and extends to the end of the documentation comment, the next @cc
directive in a CONTRACTS file, or the end of that file. It may contain any text and span any
number of lines. The core format does not prescribe vocabulary, sentence shape, modality, or a
requirements notation, but Markdown is generally expected.
A documentation comment contains one @cc directive. Multiple consecutive contract comments may
attach to the same declaration. Contract IDs are unique and stable within the declaration to which
they are attached; the same ID may be used on a different declaration. Contracts in a CONTRACTS
file are not attached to a declaration, and their IDs are unique and stable within that file and
across all parent CONTRACTS files.
The identity of an attached contract is the language-specific identity of its declaration plus its
contract ID. The identity of a directory contract is the repository-relative path of its CONTRACTS
file plus its contract ID.
For $code-contracts verify, follow On-demand verification.
Before changing or reviewing code, identify every local, enclosing-declaration, and ancestor
CONTRACTS-file obligation governing the target, manually or with cc-check list. Resolve called
symbols and inspect their contracts too: a call can violate a contract declared in another file.
Treat all applicable local and directory contracts as simultaneous obligations. Surface conflicting, obsolete, or impossible contracts instead of choosing one silently. Documentation examples and intentionally malformed test fixtures are not production contract declarations.
Code contracts are effective when they are simple, concise, and precise. Place a
declaration-specific contract in that language's supported documentation comment or docstring. Place
a contract governing a directory tree in CONTRACTS, normally for architectural, security, or
coding constraints. Use the narrowest relevant declaration or directory boundary.
Each source documentation block contains exactly one contract. Keep contract IDs unique and stable
within their declaration. Keep CONTRACTS IDs unique and stable within that file and its parent
CONTRACTS files. Set owner to the current user's GitHub username; use their authenticated
GitHub identity when available, and ask rather than guessing when it cannot be determined. Multiple
owners are possible; prefer separating their usernames with ; in a single owner attribute.
Use the same convention for multiple labels and notify recipients. Set notify only when
explicitly requested by the user; do not infer it from owner. Preserve established repository
metadata conventions.
Validate contract syntax with cc-check format. The command reports malformed syntax and duplicate
IDs only. It does not prove that the prose is true or that code complies with it. You are responsible
for verifying contracts' validity and coherence and the code's compliance. Validate contract
discoverability with cc-check list.
Write each contract around a concrete obligation:
Before keeping a contract, check that a reviewer can identify both a concrete violation and an alternative implementation that satisfies it.
You must ensure at all times that all discovered and introduced contracts related to a code change are valid, coherent, enforced, and respected. There is no automated semantic enforcement of contracts. Code changes are assumed to comply with all applicable contracts, so authors and reviewers must verify that compliance.
Contract violations and contradictions within the task's scope must be fixed or surfaced clearly. For reviews, follow On-demand verification.
When behavior intentionally changes, update the relevant contracts in the same change. Verify the impact of the contract change on consumers of the associated declaration.
CRITICAL REQUIREMENTS for all code changes
When invoked as $code-contracts verify, or when a review workflow requests this procedure,
perform a read-only contract review. Read applicable repository instructions. Do not edit files or
post reviews or notifications unless separately requested.
Use the requested PR, revision range, file, directory, or repository as the scope. Without an explicit scope, review the current task's changes, including committed branch changes and staged, unstaged, and untracked files. Infer the branch's comparison base from the task or repository context; ask for the scope if no target or baseline can be established. A file or directory can be verified against its current contracts without a diff. When a workflow supplies captured commits, use that exact comparison even if the branch advances.
Diff relevance. Check changes against all applicable contracts. Inspect unchanged code and report pre-existing violations only when directly related to changed behavior, an assumption the change relies on, or an introduced or modified contract. Explain that connection in the finding. Being in the same file, declaration, or call graph is not sufficient. This rule also applies to findings carried forward from earlier reviews.
Audits without a diff cover the full selected scope.
git diff --find-renames <merge_base> <head_sha> and
git show <merge_base>:<path> for old code and contracts. Include local changes when in scope.
Discover changed files locally even when a supplied file list may be truncated. Inspect additions,
modifications, and the effects of deletions. Compare entire contract bodies and metadata;
searching added @cc lines alone misses prose-only changes and removed contracts.cc-check format; it checks syntax, not semantic validity or compliance.
Use a caller-supplied cc-check executable when provided. If tooling is unavailable, inspect
contracts manually and disclose any resulting verification limit.rg and source navigation. Trace imports, re-exports, aliases,
wrappers, and type/member uses; confirm each match refers to the affected declaration. For
directory contracts, inspect the affected code in their subtree and consumers of affected
declarations.cc-check list <caller-location> or manual inspection. Check both that the call respects the
callee's contract and that the callee's changed guarantees keep the caller compliant with its
own contracts. Follow evidence through wrappers; do not assume consumers are compatible.Reuse applicable validation results for the inspected revision. Respect sandbox restrictions; an unavailable or failed tool alone is not evidence of a contract violation. Continue source analysis and report material verification limits.
Use the invoking workflow's output format when specified. Otherwise, report concise findings with the contract ID and declaration/file, exact source location, evidence, and consequence. Identify pre-existing violations as such; avoid speculative or unrelated general review findings. If no violations are found, state that for the inspected scope, with any material limitations.
© ghuntley, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in .agents/skills/code-contracts of ghuntley/underclass.
Open the folder on GitHubat commit 3e35c3b
Code Contracts next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Code Contracts this skillghuntley/underclass | 191 | — | ~4.1k | Automated safety check: Pass | MIT | |
| Caveman Gateway SetupJuliusBrussee/caveman | 111k | 1 repos | ~2.6k | Automated safety check: Warn | Apache-2.0 | |
| Azure Architecture Autopilotgithub/awesome-copilot | 40k | 1 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Youtubeeat-pray-ai/yutu | 699 | — | ~1.1k | Automated safety check: Pass | MIT | |
| Local Stack RuntimeOpenHands/OpenHands | 90k | — | ~375 | Automated safety check: Pass | MIT | |
| Telemetry AnalyticsOpenHands/OpenHands | 90k | — | ~305 | Automated safety check: Pass | MIT |
JuliusBrussee/caveman
Routes every LLM call in a repository through the Caveman Cloud gateway in record mode, so requests and costs are measured without changing behavior.
github/awesome-copilot
Designs Azure infrastructure from a natural-language description, or diagrams an existing resource group, then refines the design through conversation and deploys it with Bicep.
eat-pray-ai/yutu
A skill your agent uses whenever the user mentions YouTube, video uploads, channel management, playlists, video SEO, or any YouTube Data API operation.
OpenHands/OpenHands
This skill should be used when the user asks to "change the dev stack", "add a runtime service", "change the launcher", "update Docker", "bump Agent Server", "change ingress routing", or changes…
OpenHands/OpenHands
This skill should be used when the user asks to "add tracking", "add a PostHog event", "change telemetry consent", "instrument onboarding", "debug analytics", or changes telemetry.ts…
microsoft/GitHub-Copilot-for-Azure
Discovers available Azure OpenAI model capacity across regions and projects.
Works with
Categories
Define, use, and enforce @cc code-contracts across a codebase. Code Contracts is an agent skill from ghuntley/underclass. Define, use, and enforce @cc code-contracts across a codebase.
Code Contracts fits situations like: devOps & Cloud work in your project.
Run `npx skills add ghuntley/underclass --skill code-contracts -a claude-code`. Or copy the skill folder (.agents/skills/code-contracts in ghuntley/underclass) into .claude/skills/code-contracts in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ghuntley/underclass --skill code-contracts -a codex`. Or copy the skill folder (.agents/skills/code-contracts in ghuntley/underclass) into .agents/skills/code-contracts in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ghuntley/underclass --skill code-contracts -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-contracts, .gemini/skills/code-contracts, .github/skills/code-contracts and .opencode/skills/code-contracts in your project.
Going by SKILL.md and its folder, Code Contracts needs the command-line tools its instructions call (git and npm). Our summary lists: Python 3; Node.js.
SKILL.md contains no URLs. Its commands use git and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Code Contracts is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.1k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Code Contracts: Caveman Gateway Setup (JuliusBrussee/caveman, 111k stars), Azure Architecture Autopilot (github/awesome-copilot, 40k stars), Youtube (eat-pray-ai/yutu, 699 stars) and Local Stack Runtime (OpenHands/OpenHands, 90k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ghuntley (a GitHub user) maintains it in ghuntley/underclass, which has 191 GitHub stars. The repository was last updated on October 9, 2026.
Source: ghuntley/underclass on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.