Agent skill

Oss Standards

by gridaco in gridaco/grida

Pre-PR discipline for a public-by-default repo. An agent skill from gridaco/grida.

Apache-2.0Auto-check: notesDevelopment

Install Oss Standards

skills CLI
$ npx skills add gridaco/grida --skill oss-standards -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install gridaco/grida oss-standards --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/gridaco/grida.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/oss-standards .claude/skills/oss-standards && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
oss-standards
GitHub stars
2.7k
Token cost
~1.7k tokens
SKILL.md length
901 words
Files
1
Skills in repo
29
Repo updated
First seen
Licence
Apache-2.0

At a glance

Pre-PR discipline for a public-by-default repo. An agent skill from gridaco/grida.

  • Development work in your project
  • SKILL.md covers Code, Security, Docs and prose and The cleaning pass, plus 2 more sections
  • Calls git

What it does

Oss Standards is an agent skill from gridaco/grida. Pre-PR discipline for a public-by-default repo. What a reviewer enforces beyond CI: secrets and internal data in diffs or screenshots, docs that name their reader, and the cleaning pass where incomplete or confusing artifacts get dropped. Use before opening any PR against gridaco/grida or when finalizing work for review.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development. The licence is Apache-2.0.

When your agent uses it

  • Development work in your project

Example prompts

  • “/oss-standards”

What it can do on your machine

Read from SKILL.md and the folder at commit 165496f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Oss Standards loads about 1.7k tokens when it runs. Until then it costs about 85 tokens; SKILL.md has 901 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~85
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:64
    Use `.env.local` (gitignored) and fixture placeholders.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from gridaco/grida at commit 165496f, republished under its Apache-2.0 licence (© gridaco). 901 words, ~1,688 tokens.

Download SKILL.mdSave it as .claude/skills/oss-standards/SKILL.md (or your agent's skills folder).
name
oss-standards
description
Pre-PR discipline for a public-by-default repo. What a reviewer enforces beyond CI: secrets and internal data in diffs or screenshots, docs that name their reader, and the cleaning pass where incomplete or confusing artifacts get dropped. Use before opening any PR against `gridaco/grida` or when finalizing work for review.

oss-standards

Grida is open source. CI checks catch the mechanical failures — format, lint, typecheck, tests, typos, generated-file freshness. This skill is the extra bar a reviewer enforces because the repo is public, the threat model is public, and the audience for every artifact in a PR includes a stranger who arrived via Google.

The defaults that flip:

  • Public-by-default. Names, comments, fixtures, screenshots, commit messages — assume a stranger reads them first. There is no internal channel; everything is the channel.
  • Push = publish. A secret in a branch push is a published secret, even if you delete the commit five minutes later. "I'll redact before merge" is not a plan; rotation is.
  • Incomplete is worse than absent. "I'll finish it next PR" lands on main, gets indexed, and becomes the example the next contributor copies. Use draft: true, defer the PR, or just don't ship — but don't ship half.

Code

Beyond what CI catches and what CLAUDE.md / naming / code-ts / code-react already enforce:

  • No personal TODOs. // TODO(me): …, "fix later", "@username knows" — private notes published. Either resolve, or rewrite as a neutral TODO with a tracking issue link.
  • No machine-specific paths. See the links pre-commit gate — absolute paths, ~/scratch/..., /tmp/..., and untracked references resolve to nothing for anyone else.
  • One concern per PR. A reviewer in public cannot accept half a PR; bundled unrelated changes are unreviewable. Split or rebase.
  • New public surface is a semver commitment. YAGNI applies everywhere, but in OSS the cost of adding an exported name today is the deprecation path you owe tomorrow. Wait for the second caller.

For bug fixes specifically, the etiology skill is mandatory — bandaids in main become tribal knowledge that external contributors have no access to.

Security

The full boundary discipline lives in the security skill — GRIDA-SEC-<id> tags, the mandatory review before commit. Two extra OSS gates on top, both because push = publish:

  • Secrets in diffs, fixtures, or tests. Any credential, signing key, Stripe/Metronome id, webhook signature, or production-shaped URL committed has been published the moment the branch is pushed. Use .env.local (gitignored) and fixture placeholders.
  • Internal URLs and screenshots. Webhook URLs, dev-tunnel URLs, staging hosts, dashboard links, and screenshots that show real org slugs, account ids, or tenant data leak the same way. A doc PR with a real org slug visible in the screenshot chrome is a published org slug.

If a GRIDA-SEC-<id> tag appears anywhere in your diff, the security skill's review runs first; this skill's cleaning pass is downstream of that.

Docs and prose

Anything user-facing — README, docs/**, blog post, in-product copy, the PR description itself — has an audience that doesn't share your context.

Name the reader before writing. One sentence: "an external contributor first opening the repo," "a designer evaluating Grida vs Figma," "an agent grounding before a refactor." If you can't name the reader, the page doesn't know what it is — and that surfaces as prose that hedges, repeats, or assumes.

  • No "we know that…" prose. "We" is the maintainers; the reader is someone else. Explain the fact or link to where it lives.
  • No private references. Slack threads, internal tickets, "as we discussed" — invisible to the reader.
  • Link form follows the rendering surface. See the links skill — local-only or untracked targets are correctness bugs in OSS, not style.
  • Ship-or-draft is the doc taxonomy gate. draft: true is the honest answer when a page isn't useful enough yet; shipping a half-page because "something is better than nothing" is not. See docs/AGENTS.md.
Show full SKILL.md (329 more words)Show less

The cleaning pass

Final pass before opening the PR. For every file touched, ask literally:

If a stranger reads this file with no context, does it help them, or does it leave a question they cannot answer?

Apply the answer:

  • Helps → keep.
  • Recoverable question → fix it (rename, expand the doc, add the one comment that explains the non-obvious constraint).
  • Unrecoverable question → drop the file, the code block, the doc section, the fixture, the screenshot.

The bias is to drop. A confusing artifact in main outlives the PR and is the first thing the next contributor finds when they grep.

Common removals on this pass:

  • Scratch files committed by mistake (tmp.ts, notes.md, unnamed fixtures, snapshots from a one-off debug run).
  • Half-written doc pages with no audience or no conclusion — draft: true or delete.
  • TODO blocks that reference internal context.
  • Examples or fixtures that don't run or aren't referenced.
  • Inline comments that paraphrase code instead of stating the non-obvious why (per the repo-wide rule in CLAUDE.md).

The PR description and commit message

These are public artifacts permanently linked from the diff.

  • Commit message makes git log a useful index. "fix" is not a commit message; neither is "updates".
  • PR description lets a future contributor reconstruct why the change exists without reading the diff line by line. Bug fix → name the diagnostic-ladder rung (etiology). Feature → name the audience and the concrete use case that pulled it in.

The short version

  • Public-by-default. Push = publish. Nothing is internal.
  • CI catches the mechanical. This skill catches the rest.
  • Secrets, internal URLs, machine paths, screenshots with real data — published on push; rotation is the only remedy.
  • Docs name the reader, or they don't know what they are.
  • Final pass: every artifact justifies itself to a stranger, or it drops. Bias is to drop.
  • The PR description and commit message are the permanent index. Write them as such.

See also: security, links, etiology, naming, code-ts, code-react, pedantic (when you want a hard critique before opening the PR).

© gridaco, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/oss-standards of gridaco/grida.

Open the folder on GitHubat commit 165496f

Compare with similar skills

Oss Standards next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Oss Standards compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Oss Standards this skillgridaco/grida2.7k—~1.7kAutomated safety check: NotesApache-2.0
Vercel Composition Patternssupabase/supabase111k59 repos~726Automated safety check: PassMIT
Finishing a Development Branchobra/superpowers296k5 repos~1.9kAutomated safety check: PassMIT
Typescript Advanced Typesrolling-scopes/rsschool-app10k25 repos~4.2kAutomated safety check: PassMPL-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • Official

    React composition patterns that scale. An agent skill from supabase/supabase.

    111k GitHub starsUsed in 59 repos~726 tokens
    DevelopmentAuto-check passed
  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    296k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Typescript Advanced Types

    rolling-scopes/rsschool-app

    Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.

    10k GitHub starsUsed in 25 repos~4.2k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed

More from gridaco/grida

All 29 skills in this repo
  • Desktop

    gridaco/grida

    Grida Desktop Electron shell and release-impact work: BrowserWindow, preload, window.grida, menus, protocol/deep links, file associations, Forge, path-scoped bridge security, Electron-only UI bugs…

    2.7k GitHub stars~3.2k tokensUpdated yesterday
    Auto-check: notes
  • Io Figma

    gridaco/grida

    Guides work on the Figma I/O package (@grida/io-figma, packages/grida-canvas-io-figma/).

    2.7k GitHub stars~2.2k tokensUpdated yesterday
    Auto-check: notes
  • Opt Library

    gridaco/grida

    Set up, download, verify, and seed the optional Grida Library developer corpus into local Supabase.

    2.7k GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • Vision

    gridaco/grida

    Query images with a local Ollama vision model without loading the image into the main agent context.

    2.7k GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • AI Models

    gridaco/grida

    Research, compare, and update shared AI model JSON for TypeScript, web, and Rust consumers.

    2.7k GitHub stars~5.7k tokensUpdated yesterday
    Auto-check passed
  • Agent System

    gridaco/grida

    Grida AI agent system work: @grida/daemon (DaemonServer, loopback HTTP perimeter, files/workspaces, secrets store, daemon discovery) and @grida/agent (the agent tenant: sessions, providers/BYOK…

    2.7k GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Oss Standards

What does Oss Standards do?

Pre-PR discipline for a public-by-default repo. An agent skill from gridaco/grida. Oss Standards is an agent skill from gridaco/grida. Pre-PR discipline for a public-by-default repo.

When should I use Oss Standards?

Oss Standards fits situations like: development work in your project.

How do I install Oss Standards in Claude Code?

Run `npx skills add gridaco/grida --skill oss-standards -a claude-code`. Or copy the skill folder (.agents/skills/oss-standards in gridaco/grida) into .claude/skills/oss-standards in your project. Claude Code loads it when a task matches its description.

How do I install Oss Standards in Codex?

Run `npx skills add gridaco/grida --skill oss-standards -a codex`. Or copy the skill folder (.agents/skills/oss-standards in gridaco/grida) into .agents/skills/oss-standards in your project. Codex loads it when a task matches its description.

Can I use Oss Standards in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add gridaco/grida --skill oss-standards -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/oss-standards, .gemini/skills/oss-standards, .github/skills/oss-standards and .opencode/skills/oss-standards in your project.

What does Oss Standards need to run?

Going by SKILL.md and its folder, Oss Standards needs the command-line tools its instructions call (git).

Does Oss Standards access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Oss Standards safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Oss Standards use?

Oss Standards is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Oss Standards use?

About 1.7k tokens (SKILL.md is roughly 6.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Oss Standards?

Skills that share tags, products or a category with Oss Standards: Vercel Composition Patterns (supabase/supabase, 111k stars), Finishing a Development Branch (obra/superpowers, 296k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Oss Standards?

gridaco (a GitHub organization) maintains it in gridaco/grida, which has 2,659 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 7, 2026.

Source: gridaco/grida on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.