Agent skill

Code Engineering

by kangarooking in kangarooking/system-prompt-skills

当系统提示面向编程代理(Coding Agent)场景时调用。适用于构建代码编辑、文件操作、Git 工作流、自动化编程助手的系统提示。不适用于代码解释或教学场景(无文件修改),不适用于 DevOps 基础设施配置(非代码层),不适用于纯对话式代码问答(无工具调用)。

MITAuto-check passedAI & LLM Engineering

Install Code Engineering

skills CLI
$ npx skills add kangarooking/system-prompt-skills --skill code-engineering -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kangarooking/system-prompt-skills code-engineering --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kangarooking/system-prompt-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/code-engineering .claude/skills/code-engineering && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-engineering
GitHub stars
205
Token cost
~769 tokens
SKILL.md length
211 words
Files
1
Skills in repo
15
Repo updated
First seen
Licence
MIT

At a glance

当系统提示面向编程代理(Coding Agent)场景时调用。适用于构建代码编辑、文件操作、Git 工作流、自动化编程助手的系统提示。不适用于代码解释或教学场景(无文件修改),不适用于 DevOps 基础设施配置(非代码层),不适用于纯对话式代码问答(无工具调用)。

  • Works in 6 steps: 安全优先 Git 工作流:任何破坏性操作(force push、hard… → 计划生命周期管理:采用 plan→review→execute… → 上下文感知文件编辑:编辑前先读取文件内容,理解上下文后再修改,避免破坏性覆盖;优先… → …
  • Tasks that involve Git workflow
  • SKILL.md covers R — 原文 (Reading), I — 方法论骨架 (Interpretation), A1 — 案例分析 (Past Application) and A2 — 触发场景 (Future Trigger) ★, plus 2 more sections
  • Calls git

What it does

Code Engineering is an agent skill from kangarooking/system-prompt-skills. 当系统提示面向编程代理(Coding Agent)场景时调用。适用于构建代码编辑、文件操作、Git 工作流、自动化编程助手的系统提示。不适用于代码解释或教学场景(无文件修改),不适用于 DevOps 基础设施配置(非代码层),不适用于纯对话式代码问答(无工具调用)。

Its SKILL.md is about 770 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in AI & LLM Engineering, covering Git workflow. It works with Git. The repository describes itself as: 从 165 个顶级 AI 产品系统提示词中蒸馏出的 15 个可执行 Agent skill. The licence is MIT.

When your agent uses it

  • Tasks that involve Git workflow

Example prompts

  • “/code-engineering”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. 安全优先 Git 工作流:任何破坏性操作(force push、hard reset、clean)需显式用户确认,优先创建新提交而非修改已有提交,保护主分支。
  2. 计划生命周期管理:采用 plan→review→execute 三阶段模型——先理解意图生成计划,用户确认后再执行,执行后验证结果。
  3. 上下文感知文件编辑:编辑前先读取文件内容,理解上下文后再修改,避免破坏性覆盖;优先使用差异编辑而非全文重写。
  4. 验证循环:代码修改后运行测试或构建验证,前端变更使用浏览器工具截图确认视觉效果。
  5. 自主与引导模式切换:简单任务可自主完成(YOLO 模式),复杂任务需逐步确认,根据任务性质自动选择模式。
  6. 反 AI 糟粕规则:禁止生成典型的 AI 风格代码(过度注释、不必要的抽象、冗余类型声明),追求简洁专业的工程代码。

What it can do on your machine

Read from SKILL.md and the folder at commit 252cd52. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Engineering loads about 769 tokens when it runs. Until then it costs about 38 tokens; SKILL.md has 211 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~38
When it runs · the whole SKILL.md, loaded when a task matches
~769

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from kangarooking/system-prompt-skills at commit 252cd52, republished under its MIT licence (© kangarooking). 211 words, ~769 tokens.

Download SKILL.mdSave it as .claude/skills/code-engineering/SKILL.md (or your agent's skills folder).
name
code-engineering
description
当系统提示面向编程代理(Coding Agent)场景时调用。适用于构建代码编辑、文件操作、Git 工作流、自动化编程助手的系统提示。不适用于代码解释或教学场景(无文件修改),不适用于 DevOps 基础设施配置(非代码层),不适用于纯对话式代码问答(无工具调用)。
tags
编程代理, Git安全, 代码编辑, 生命周期管理, 自动化
related_skills
injection-defense, citation-system

编程代理模式

R — 原文 (Reading)

Claude Code 实现文件记忆、Agent 子任务委派、并行工具调用、Git 安全协议和"量两次切一次"原则;Codex 具备脏工作树感知、Plan 工具带跳过规则、代码审查按严重度排序;Jules 定义 plan→review→execute 生命周期,用 Playwright 验证前端;Claude Design 固定 React+Babel 版本并制定反 AI 糟粕指南。核心模式:安全优先 Git 工作流、计划生命周期管理、上下文感知编辑、验证循环、自主与引导模式。

I — 方法论骨架 (Interpretation)

  1. 安全优先 Git 工作流:任何破坏性操作(force push、hard reset、clean)需显式用户确认,优先创建新提交而非修改已有提交,保护主分支。
  2. 计划生命周期管理:采用 plan→review→execute 三阶段模型——先理解意图生成计划,用户确认后再执行,执行后验证结果。
  3. 上下文感知文件编辑:编辑前先读取文件内容,理解上下文后再修改,避免破坏性覆盖;优先使用差异编辑而非全文重写。
  4. 验证循环:代码修改后运行测试或构建验证,前端变更使用浏览器工具截图确认视觉效果。
  5. 自主与引导模式切换:简单任务可自主完成(YOLO 模式),复杂任务需逐步确认,根据任务性质自动选择模式。
  6. 反 AI 糟粕规则:禁止生成典型的 AI 风格代码(过度注释、不必要的抽象、冗余类型声明),追求简洁专业的工程代码。

A1 — 案例分析 (Past Application)

案例: Claude Code 的 Git 安全协议
  • 问题: 编程代理可能执行破坏性 Git 操作(如 force push 到主分支、hard reset 丢失未提交工作),导致代码资产损失。
  • 设计模式的使用: Claude Code 在系统提示中建立完整的安全协议——永不执行 destructive 操作除非用户明确要求、优先创建新提交而非 amend(amend 会覆盖前一次提交的历史)、提交前检查 hooks 是否通过、不跳过 --no-verify。同时要求在暂存文件时指定具体文件名而非 git add -A,避免意外包含敏感文件。
  • 结论: Git 安全不能依赖模型判断,必须在系统提示中以硬性规则形式声明,将高风险操作从"建议谨慎"升级为"必须确认"。
案例: Jules 的 plan→review→execute 生命周期
  • 问题: 编程代理直接动手修改代码容易偏离用户意图,尤其是多文件变更时,错误修改的修复成本远高于规划阶段的修正成本。
  • 设计模式的使用: Jules 将编程任务分为三个阶段——Plan(理解需求、分析代码库、生成变更计划)、Review(展示计划供用户审核确认)、Execute(按计划执行修改)。前端变更还增加 Playwright 截图验证环节。
  • 结论: "量两次切一次"原则在编程代理中显著降低返工率,计划阶段的低成本修正远优于执行后的高成本修复。

A2 — 触发场景 (Future Trigger) ★

用户在什么情境下需要?
  1. 构建 IDE 内的 AI 编程助手(如 VS Code 插件)
  2. 设计自主编程代理(如根据 Issue 自动修复代码的 CI/CD 机器人)
  3. 开发命令行编程工具(如终端中的 AI 编程助手)
  4. 实现代码审查自动化系统
语言信号
  • "AI 编程助手"
  • "自动修改代码"
  • "Git 操作自动化"
  • "代码审查 Agent"
  • "需要安全地编辑文件"
与相邻 skill 的区分
  • 与 injection-defense 区别:注入防御关注外部内容的信任边界,编程代理关注代码执行操作的安全性(如 Git 破坏性操作防护)
  • 与 citation-system 区别:代码引用指向文件和行号而非文档段落,编程代理的引用是操作上下文的一部分

E — 可执行步骤 (Execution)

  1. 步骤 1:建立 Git 安全协议 - 完成标准:列出禁止自主执行的 Git 操作清单(force push、hard reset、主分支直接推送、amend 已推送的提交),为每项定义用户确认流程和替代安全方案。
  2. 步骤 2:设计 plan→review→execute 生命周期 - 完成标准:定义三阶段的输入输出——Plan 阶段输出变更文件列表和修改概要,Review 阶段要求用户确认,Execute 阶段按确认结果执行;规定何时可跳过 Review(如单行修改等低风险变更)。
  3. 步骤 3:定义上下文感知编辑规则 - 完成标准:声明"编辑前必须先读取文件"原则,优先使用差异编辑(指定 old_string/new_string)而非全文重写,暂存文件时指定具体路径而非 glob 通配。
  4. 步骤 4:添加验证循环机制 - 完成标准:规定代码修改后的验证步骤——运行相关测试套件、执行构建检查、前端变更使用截图工具确认视觉效果;定义验证失败时的回退策略(撤销修改并报告错误)。
  5. 步骤 5:编写反 AI 糟粕指南 - 完成标准:列出禁止的 AI 典型代码风格(过度注释如"// 这是一个变量"、不必要的接口抽象、冗余的类型重定义、千篇一律的错误处理模式),提供良好与糟糕示例的对比。

B — 边界 (Boundary) ★

不要在以下情况使用
  • 纯代码问答或教学(无文件修改操作,无需 Git 安全协议)
  • DevOps 基础设施配置(Terraform、Kubernetes manifest 等,属于运维领域)
  • 代码分析工具(仅读取不修改,无需编辑安全协议)
  • CI/CD 流水线设计(属于自动化部署,非代码编辑)
常见失败模式
  • 过度自主:编程代理未经确认直接执行复杂修改,导致偏离用户意图或破坏现有功能,应强制对高风险操作设置确认环节
  • 全文重写偏好:模型倾向于重写整个文件而非局部修改,增加引入意外错误的风险,应优先使用差异编辑
  • 忽视工作树状态:在脏工作树中执行操作导致未保存变更丢失,应要求操作前检查工作树状态
  • AI 糟粕代码:生成过度注释、不必要抽象、冗余类型的"AI 风格"代码,需明确的反模式指南约束

© kangarooking, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in code-engineering of kangarooking/system-prompt-skills.

Open the folder on GitHubat commit 252cd52

Compare with similar skills

Code Engineering next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Engineering compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Engineering this skillkangarooking/system-prompt-skills205—~769Automated safety check: PassMIT
Git Guardrails Claude Codefossasia/eventyay-interpretation1.6k13 repos~578Automated safety check: PassApache-2.0
Git Guardrails Claude Codevinvcn/mattpocock-skills-zh-CN4.7k—~474Automated safety check: PassMIT
Git Guardrails Claude Codedevcxl/mattpocock-skills-zh4371 repos~420Automated safety check: PassMIT
GuardHouseofmvps/ultraship123—~790Automated safety check: NotesMIT
Phx Recalloliver-kriska/claude-elixir-phoenix565—~869Automated safety check: PassMIT

Similar skills

  • Git Guardrails Claude Code

    fossasia/eventyay-interpretation

    Set up Claude Code hooks to block dangerous git commands (push, reset --hard, clean, branch -D, etc.) before they execute.

    1.6k GitHub starsUsed in 13 repos~578 tokens
    AI & LLM EngineeringAuto-check passed
  • Git Guardrails Claude Code

    vinvcn/mattpocock-skills-zh-CN

    设置 Claude Code hooks,在危险 git commands(push、reset --hard、clean、branch -D 等)执行前阻止它们。适用于用户想防止破坏性 git 操作、添加 git safety hooks,或在 Claude Code 中阻止 git push/reset 时。

    4.7k GitHub stars~474 tokensUpdated 9 days ago
    AI & LLM EngineeringAuto-check passed
  • Git Guardrails Claude Code

    devcxl/mattpocock-skills-zh

    设置 Claude Code 钩子,在危险 Git 命令(push、reset --hard、clean、branch -D 等)执行前将其拦截。当用户想要防止破坏性 Git 操作、添加 Git 安全钩子或在 Claude Code 中阻止 git push/reset 时使用。

    437 GitHub starsUsed in 1 repo~420 tokens
    AI & LLM EngineeringAuto-check passed
  • Guard

    Houseofmvps/ultraship

    Safety guardrails — blocks destructive commands (rm -rf, DROP TABLE, force-push, git reset --hard) and optionally restricts file edits to a specific directory.

    123 GitHub stars~790 tokensUpdated 3 mo ago
    AI & LLM EngineeringAuto-check: notes
  • Phx Recall

    oliver-kriska/claude-elixir-phoenix

    Recall prior work from past sessions — how a bug was fixed, what was decided, where a pattern lives.

    565 GitHub stars~869 tokensUpdated 2 days ago
    AI & LLM EngineeringAuto-check passed
  • E2b Sandbox

    agent-sandbox/agent-sandbox

    Create, manage, and use E2B sandboxes — run commands, manage files, use git, persist state, and configure networking.

    218 GitHub stars~2.6k tokensUpdated 18 days ago
    DevelopmentAuto-check passed

More from kangarooking/system-prompt-skills

All 15 skills in this repo
  • Persona Design

    kangarooking/system-prompt-skills

    当需要为 AI 产品定义核心身份、角色声明和能力边界时调用此 skill。典型场景包括:设计新 AI 产品的 system prompt 首段、为不同场景创建差异化角色(如教学助手 vs 编程代理)、重新定义 AI 与用户的关系框架。

    205 GitHub starsUsed in 1 repo~956 tokens
    Auto-check passed
  • Tool Specification

    kangarooking/system-prompt-skills

    当需要为 AI 定义工具接口、设计调用规范、实现工具发现与编排机制时调用此 skill。典型场景包括:设计 AI agent 的工具集、定义 JSON Schema/XML/TypeScript 格式的工具描述、实现工具权限控制与并行调度、设计子代理委托架构。

    205 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Memory System

    kangarooking/system-prompt-skills

    当需要为 AI 设计记忆存储、检索、应用和更新机制时调用此 skill。典型场景包括:设计持久化记忆架构(用户偏好、历史上下文、项目知识)、定义记忆的创建/读取/更新/删除生命周期、实现静默记忆应用(不在回复中透露记忆内容)、管理敏感记忆边界。

    205 GitHub stars~1.2k tokensUpdated 5 mo ago
    Auto-check passed
  • Personality System

    kangarooking/system-prompt-skills

    当需要在基础身份之上叠加可切换的人格风格层时调用此 skill。典型场景包括:为同一产品提供多种人格选项(如 GPT-5.1 的 friendly/professional/quirky 模式)、设计人格切换机制、防止人格泄露到用户内容中。

    205 GitHub stars~1k tokensUpdated 5 mo ago
    Auto-check passed
  • Conversation Flow

    kangarooking/system-prompt-skills

    当系统提示词需要定义 AI 如何分类用户意图、路由到不同处理流程、决定澄清策略和自主度级别时调用此 Skill。适用于多任务型 AI 助手、客服机器人、编程工具、研究助手等需要结构化对话管理的场景。不适用于:纯问答型系统(无任务执行)、单轮交互(无对话状态)、简单的 prompt 模板(无路由逻辑)。当需求仅涉及"输出什么格式"而非"如何决定输出什么"时,应该用…

    205 GitHub starsUsed in 1 repo~788 tokens
    Auto-check passed
  • Safety Guardrails

    kangarooking/system-prompt-skills

    当需要为 AI 系统设计多层安全防线、内容过滤策略和伦理边界时调用此 skill。典型场景包括:设计拒绝策略与升级机制、防御 prompt 注入攻击、实现领域特定安全规则(教育、医疗、金融等)、定义 AI 的价值观锚点。

    205 GitHub stars~1.2k tokensUpdated 5 mo ago
    Auto-check passed

Works with

Questions about Code Engineering

What does Code Engineering do?

当系统提示面向编程代理(Coding Agent)场景时调用。适用于构建代码编辑、文件操作、Git 工作流、自动化编程助手的系统提示。不适用于代码解释或教学场景(无文件修改),不适用于 DevOps 基础设施配置(非代码层),不适用于纯对话式代码问答(无工具调用)。. Code Engineering is an agent skill from kangarooking/system-prompt-skills.

When should I use Code Engineering?

Code Engineering fits situations like: tasks that involve Git workflow.

How do I install Code Engineering in Claude Code?

Run `npx skills add kangarooking/system-prompt-skills --skill code-engineering -a claude-code`. Or copy the skill folder (code-engineering in kangarooking/system-prompt-skills) into .claude/skills/code-engineering in your project. Claude Code loads it when a task matches its description.

How do I install Code Engineering in Codex?

Run `npx skills add kangarooking/system-prompt-skills --skill code-engineering -a codex`. Or copy the skill folder (code-engineering in kangarooking/system-prompt-skills) into .agents/skills/code-engineering in your project. Codex loads it when a task matches its description.

Can I use Code Engineering in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kangarooking/system-prompt-skills --skill code-engineering -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-engineering, .gemini/skills/code-engineering, .github/skills/code-engineering and .opencode/skills/code-engineering in your project.

What does Code Engineering need to run?

Going by SKILL.md and its folder, Code Engineering needs the command-line tools its instructions call (git).

Does Code Engineering access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Code Engineering safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Engineering use?

Code Engineering is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Engineering use?

About 769 tokens (SKILL.md is roughly 3.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Engineering?

Skills that share tags, products or a category with Code Engineering: Git Guardrails Claude Code (fossasia/eventyay-interpretation, 1.6k stars), Git Guardrails Claude Code (vinvcn/mattpocock-skills-zh-CN, 4.7k stars), Git Guardrails Claude Code (devcxl/mattpocock-skills-zh, 437 stars) and Guard (Houseofmvps/ultraship, 123 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Engineering?

kangarooking (a GitHub user) maintains it in kangarooking/system-prompt-skills, which has 205 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on May 4, 2026.

Source: kangarooking/system-prompt-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.