Official agent skill

Ssl Skill Normalizer

by github in github/gh-aw

Normalize SKILL.md artifacts into Scheduling-Structural-Logical (SSL) JSON representations using a conservative multi-pass extraction pipeline.

OfficialMITAuto-check passedDevOps & Cloud

Install Ssl Skill Normalizer

skills CLI
$ npx skills add github/gh-aw --skill ssl-skill-normalizer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install github/gh-aw ssl-skill-normalizer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/ssl .claude/skills/ssl-skill-normalizer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ssl-skill-normalizer
GitHub stars
5.3k
Token cost
~2.5k tokens
SKILL.md length
1,173 words
Files
2
Skills in repo
52
Repo updated
First seen
Licence
MIT

At a glance

Normalize SKILL.md artifacts into Scheduling-Structural-Logical (SSL) JSON representations using a conservative multi-pass extraction pipeline.

  • Works in 5 steps: Invoke this skill with skill_path… → The normalizer runs all four passes in… → If Pass 4 fails, the RECOVER pass… → …
  • DevOps & Cloud work in your project
  • SKILL.md covers Purpose, Layer 1 — Scheduling (When /…, Layer 2 — Structural (How /… and Layer 3 — Logical (What /…, plus 11 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Ssl Skill Normalizer is an agent skill from github/gh-aw, published by the product's own GitHub organization. Normalize SKILL.md artifacts into Scheduling-Structural-Logical (SSL) JSON representations using a conservative multi-pass extraction pipeline.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `ssl.json`).

It sits in DevOps & Cloud. The repository describes itself as: GitHub Agentic Workflows. The licence is MIT.

When your agent uses it

  • DevOps & Cloud work in your project

Example prompts

  • “/ssl-skill-normalizer”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Invoke this skill with skill_path pointing to the target SKILL.md.
  2. The normalizer runs all four passes in sequence.
  3. If Pass 4 fails, the RECOVER pass retries generation up to the retry budget.
  4. The resulting ssl.json is written alongside the source file.
  5. Review the validation_report output to confirm acceptance.

What it can do on your machine

Read from SKILL.md and the folder at commit eb63040. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ssl Skill Normalizer loads about 2.5k tokens when it runs. Until then it costs about 41 tokens; SKILL.md has 1,173 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~41
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from github/gh-aw at commit eb63040, republished under its MIT licence (© github). 1,173 words, ~2,507 tokens.

Download SKILL.mdSave it as .claude/skills/ssl-skill-normalizer/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
ssl-skill-normalizer
description
Normalize SKILL.md artifacts into Scheduling-Structural-Logical (SSL) JSON representations using a conservative multi-pass extraction pipeline.
tools
read_file, write_file, search_files, json_validate, create_artifact, run_tests
inputs
skill_path
outputs
ssl_json, validation_report

SSL Skill Normalizer

Purpose

This skill converts markdown-based skill artifacts into a structured Scheduling-Structural-Logical (SSL) representation as introduced in:

Liang et al., "From Skill Text to Skill Structure: The Scheduling-Structural-Logical Representation for Agent Skills", arXiv:2604.24026 (2026).

SSL addresses the core limitation of free-form skill text: it is human-readable but hard for agents to reason over, discover, and audit. By mapping each skill into three complementary layers, SSL makes skills searchable (improved MRR 0.573 → 0.707 in the paper) and risk-assessable (improved macro F1 0.744 → 0.787).


The Three SSL Layers

The representation is grounded in Schank & Abelson's theories of Memory Organization Packets (MOPs), Script Theory, and Conceptual Dependency. Each layer captures a different dimension of skill knowledge:

Layer 1 — Scheduling (When / Who)

Answers: When should this skill be invoked? By whom, given which inputs and outputs?

Fields extracted:

  • id — stable lowercase identifier
  • name — human-readable skill name
  • goal — one-sentence purpose
  • intent_signature — typed function signature (fn($input) -> $output)
  • inputs — $-prefixed named input bindings
  • outputs — $-prefixed named output bindings
  • dependencies — explicit runtime tool or library requirements
  • control_flow_features — e.g. sequential, conditional, loop
  • entry_scene — ID of the first scene to execute
  • subscene_refs — IDs of any nested/delegated scenes

Layer 2 — Structural (How / Order)

Answers: What are the macro-level execution stages and how do they connect?

Each scene is a named execution stage with:

  • id — unique within the skill
  • type — one of the restricted scene-type enum (see below)
  • goal — what the scene accomplishes
  • entry_condition — precondition for entering the scene
  • exit_condition — postcondition that must hold on exit
  • next_scene_rules — conditional transitions to the next scene ID, END_SUCCESS, or END_FAIL
  • inputs / outputs — $-prefixed bindings consumed and produced
  • entry_logic_step — ID of the first logic step in this scene

Layer 3 — Logical (What / Actions)

Answers: What atomic operations are performed, on which resources?

Each logic step is an indivisible operation with:

  • id — unique within the skill
  • scene_id — owning scene
  • action_type — one of the restricted action-type enum (see below)
  • resource_scope — one of the restricted resource-scope enum (see below)
  • description — one sentence describing the operation
  • inputs / outputs — named $-variable bindings
  • next — ID of the following step, YIELD_SUCCESS, or YIELD_FAIL

Restricted Enumerations

Scene Types

ValueMeaning
PREPARESetup: load inputs, configure environment
ACQUIREReceive or fetch required data
REASONAnalyze, infer, or plan
ACTProduce or transform primary output
VERIFYValidate outputs or preconditions
RECOVERHandle failure; retry or compensate
FINALIZEWrite results, emit notifications, clean up

Action Types

ValueMeaning
READConsume data from a resource without side effects
SELECTChoose among alternatives
COMPAREDiff or rank two or more values
VALIDATEAssert a constraint or schema
INFERDerive new information via reasoning
WRITEProduce or overwrite data in a resource
UPDATE_STATEMutate shared state
CALL_TOOLInvoke an external tool or subprocess
REQUESTSend a request to an external service
TRANSFERMove data between resources
NOTIFYEmit a message or event
TERMINATEEnd execution and return control

Resource Scopes

ValueMeaning
MEMORYIn-process working memory
LOCAL_FSLocal file system
CODEBASESource code under version control
PROCESSOS process or shell
USER_DATAUser-provided or personal data
CREDENTIALSSecrets, tokens, or credentials
NETWORKRemote network resource
OTHERAny resource not covered above

Terminal Targets

  • Scene transitions: END_SUCCESS | END_FAIL
  • Logic-step transitions: YIELD_SUCCESS | YIELD_FAIL

Behavioral Requirements

General Rules

  • Only extract information directly supported by the source artifact.
  • Do not invent hidden behavior, tools, dependencies, or side effects.
  • Use restricted enum vocabularies only; never free-form strings in typed fields.
  • Reject malformed outputs instead of silently repairing them.
  • Prefer null, empty arrays, or coarse-grained classifications when evidence is weak.

Execution Pipeline

Pass 1: Scheduling Extraction

Read the source SKILL.md, then extract the scheduling layer.

Produce scheduling with all fields in Layer 1. When evidence is absent for an optional field, emit an empty array or null.

Requirements

  • Use only explicit evidence from the source document.
  • Preserve semantic intent without paraphrasing behavior into unsupported claims.
  • Normalize all identifiers to snake_case.

Pass 2: Scene Decomposition

Analyse the skill's execution flow and decompose it into macro-level scenes.

Requirements

  • Prefer 2–5 scenes when supported by the source. Only add more if the source describes clearly distinct phases.
  • Assign only allowed scene types from the enum table.
  • For each scene define: goal, entry_condition, exit_condition, next_scene_rules, inputs, outputs, entry_logic_step.

Constraints

  • Every next_scene_rules target must resolve to another scene ID, END_SUCCESS, or END_FAIL.
  • Include a RECOVER scene when the source describes retry or error-recovery behaviour.

Show full SKILL.md (458 more words)Show less

Pass 3: Logic-Step Expansion

Expand each scene into its sequence of atomic logic steps.

Split a step whenever any of the following changes:

  • action type
  • resource boundary
  • execution effect
  • control-flow behaviour

Requirements

  • Assign only allowed action types and resource scopes.
  • Use $-prefixed variable bindings for all named data ($user_request, $selected_file, $generated_output).
  • Do not use unnamed or free-form intermediate variables.

Pass 4: Validation

Validate the draft SSL JSON against all of the following rules:

RuleCheck
JSON syntaxWell-formed JSON
Required fieldsAll top-level fields present
Enum membershipAll enum fields use allowed values only
Unique identifiersAll scene IDs and step IDs are globally unique
Entry pointerentry_scene references an existing scene ID
Scene entry pointerentry_logic_step references an existing step ID
Scene containmentAll referenced scene IDs exist
Logic-step containmentAll referenced step IDs exist
Transition validityAll transition targets are valid scene/step IDs or terminal values
Graph integrityNo unreachable scenes or dangling references

Failure Handling

  • Retry malformed generations within a bounded retry budget (recommend ≤ 3 retries).
  • Record each validation failure with the specific rule that was violated.
  • Reject records that remain invalid after retries; do not silently emit invalid JSON.

Reporting

Generate a normalization report containing:

  • processed artifact count
  • valid SSL count
  • rejected SSL count
  • parse failures
  • schema failures
  • graph failures
  • enum failures
  • retry counts

Include per-artifact diagnostics with the specific Pass-4 rule that caused rejection.

Do not expose secrets or credentials in reports.


Success Criteria

The skill succeeds when:

  • a valid SSL JSON artifact is produced
  • all references resolve correctly
  • all enum values are valid
  • the output passes all Pass-4 validation rules
  • the output remains grounded in the source artifact with no invented behaviour

The skill fails when:

  • required graph structures are missing
  • transitions are invalid
  • unsupported inference is required to fill required fields
  • validation errors remain unresolved after retries

Output Expectations

Primary Output

A schema-valid SSL JSON file named ssl.json placed alongside the source SKILL.md. Top-level keys: scheduling, scenes, logic_steps.

Secondary Output

A validation and normalization report summarizing accepted artifacts, rejected artifacts, per-artifact validation diagnostics, and retry behaviour.


Safety Constraints

  • Never invent credentials or external systems.
  • Never infer unstated side effects.
  • Never fabricate execution logic not present in the source.
  • Never silently repair invalid graph structures.
  • Never emit malformed JSON intentionally.
  • Keep normalization deterministic where possible.

Reuse Instructions

To apply this skill to a SKILL.md artifact:

  1. Invoke this skill with skill_path pointing to the target SKILL.md.
  2. The normalizer runs all four passes in sequence.
  3. If Pass 4 fails, the RECOVER pass retries generation up to the retry budget.
  4. The resulting ssl.json is written alongside the source file.
  5. Review the validation_report output to confirm acceptance.

For batch normalization, invoke this skill once per artifact and aggregate the per-artifact reports.

© github, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .github/skills/ssl of github/gh-aw.

  • SKILL.md
  • ssl.json

Open the folder on GitHubat commit eb63040

Compare with similar skills

Ssl Skill Normalizer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ssl Skill Normalizer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ssl Skill Normalizer this skillgithub/gh-aw5.3k—~2.5kAutomated safety check: PassMIT
Monitor CInrwl/nx29k5 repos~4.7kAutomated safety check: PassMIT
Terraform and OpenTofu Guideagentscope-ai/QwenPaw35k6 repos~4.2kAutomated safety check: PassApache-2.0
Vercel Optimize Auditvercel-labs/agent-skills32k8 repos~4.3kAutomated safety check: PassNone
Analyze GitHub Action Logswithastro/astro63k1 repos~1.3kAutomated safety check: PassCustom licence
Docs Learn PR Previewnetdata/netdata81k—~2kAutomated safety check: PassGPL-3.0

Similar skills

  • Monitor CI

    nrwl/nx

    Monitor Nx Cloud CI pipeline and handle self-healing fixes. An agent skill from nrwl/nx.

    29k GitHub starsUsed in 5 repos~4.7k tokens
    DevOps & CloudAuto-check passed
  • Terraform and OpenTofu Guide

    agentscope-ai/QwenPaw

    Guidance for writing and testing Terraform and OpenTofu code: module structure, naming, test approaches, CI/CD workflows, state handling and security scanning.

    35k GitHub starsUsed in 6 repos~4.2k tokens
    DevOps & CloudAuto-check passed
  • Vercel Optimize Audit

    vercel-labs/agent-skills

    Official

    Runs a metrics-first audit of a deployed Vercel project, gating investigations on real signals to produce ranked, citation-backed cost and performance recommendations.

    32k GitHub starsUsed in 8 repos~4.3k tokens
    DevOps & CloudAuto-check passed
  • Official

    Analyze recent GitHub Actions workflow runs to identify patterns, mistakes, and improvements.

    63k GitHub starsUsed in 1 repo~1.3k tokens
    DevOps & CloudAuto-check passed
  • Docs Learn PR Preview

    netdata/netdata

    Use only when the user explicitly asks to build, run, preview, inspect, or validate learn.netdata.cloud locally using the contents of a PR or documentation branch before merge.

    81k GitHub stars~2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Repo Mirror Sources

    netdata/netdata

    Inspect Netdata-org source checkouts under NETDATAREPOSDIR, or set up and synchronize that mirror when requested.

    81k GitHub stars~1.2k tokensUpdated today
    DevOps & CloudAuto-check: notes

More from github/gh-aw

All 52 skills in this repo
  • Official

    Drives a real browser from the command line with playwright-cli to open pages, interact, mock requests, save state and work with Playwright tests.

    5.3k GitHub starsUsed in 23 repos~2.8k tokens
    Auto-check passed
  • Official

    Designs and verifies a deterministic grader that measures whether a GitHub Agentic Workflow run reached its real-world or repository outcome.

    5.3k GitHub stars~6.8k tokensUpdated today
    Auto-check passed
  • Official

    Scaffolds, edits, reloads and debugs a canvas extension that the GitHub Copilot CLI can open in its side panel.

    5.3k GitHub stars~3.7k tokensUpdated today
    Auto-check passed
  • Official

    Drives an open pull request to merge-ready from inside a GitHub Copilot cloud agent, resolving review threads and local checks concurrently, without merging or retriggering CI.

    5.3k GitHub stars~3.8k tokensUpdated today
    Auto-check: warnings
  • Official

    Bumps gh-aw's pinned gh-aw-firewall version, rebuilds generated artifacts, and flags upstream spec or schema changes that need follow-up work.

    5.3k GitHub stars~899 tokensUpdated today
    Auto-check passed
  • Official

    Guide to the console struct tag system in gh-aw: headers, titles, number and cost formats, omitempty, and how structs, slices and maps render in the terminal.

    5.3k GitHub stars~736 tokensUpdated today
    Auto-check passed

Categories

Questions about Ssl Skill Normalizer

What does Ssl Skill Normalizer do?

Normalize SKILL.md artifacts into Scheduling-Structural-Logical (SSL) JSON representations using a conservative multi-pass extraction pipeline. Ssl Skill Normalizer is an agent skill from github/gh-aw, published by the product's own GitHub organization.md artifacts into Scheduling-Structural-Logical (SSL) JSON representations using a conservative multi-pass extraction pipeline.

When should I use Ssl Skill Normalizer?

Ssl Skill Normalizer fits situations like: devOps & Cloud work in your project.

How do I install Ssl Skill Normalizer in Claude Code?

Run `npx skills add github/gh-aw --skill ssl-skill-normalizer -a claude-code`. Or copy the skill folder (.github/skills/ssl in github/gh-aw) into .claude/skills/ssl-skill-normalizer in your project. Claude Code loads it when a task matches its description.

How do I install Ssl Skill Normalizer in Codex?

Run `npx skills add github/gh-aw --skill ssl-skill-normalizer -a codex`. Or copy the skill folder (.github/skills/ssl in github/gh-aw) into .agents/skills/ssl-skill-normalizer in your project. Codex loads it when a task matches its description.

Can I use Ssl Skill Normalizer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add github/gh-aw --skill ssl-skill-normalizer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ssl-skill-normalizer, .gemini/skills/ssl-skill-normalizer, .github/skills/ssl-skill-normalizer and .opencode/skills/ssl-skill-normalizer in your project.

What does Ssl Skill Normalizer need to run?

SKILL.md names no scripts, command-line tools or credentials: Ssl Skill Normalizer is instructions for the agent only.

Does Ssl Skill Normalizer access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ssl Skill Normalizer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ssl Skill Normalizer use?

Ssl Skill Normalizer is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ssl Skill Normalizer use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ssl Skill Normalizer?

Skills that share tags, products or a category with Ssl Skill Normalizer: Monitor CI (nrwl/nx, 29k stars), Terraform and OpenTofu Guide (agentscope-ai/QwenPaw, 35k stars), Vercel Optimize Audit (vercel-labs/agent-skills, 32k stars) and Analyze GitHub Action Logs (withastro/astro, 63k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ssl Skill Normalizer?

github (a GitHub organization, an official publisher) maintains it in github/gh-aw, which has 5,350 GitHub stars. The repository holds 52 skills in this directory. The repository was last updated on October 7, 2026.

Source: github/gh-aw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.