Agent skill

Workflow Audit

by mfish-qf in mfish-qf/mfish-nocode

为 mfish-nocode-pro 项目集成 Flowable 工作流审批能力,包括注册 FlowKey、实体审批状态字段、Service 启动/撤回流程、Controller 审批回调接口、Feign 回调接口注册五个步骤的完整代码模板。当用户说"带工作流审批"、"发布审核流程"、"集成工作流"、"审批回调"时使用此 skill。

Apache-2.0Auto-check passedBackend & APIs

Install Workflow Audit

skills CLI
$ npx skills add mfish-qf/mfish-nocode --skill workflow-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mfish-qf/mfish-nocode workflow-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mfish-qf/mfish-nocode.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/workflow-audit .claude/skills/workflow-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
workflow-audit
GitHub stars
747
Token cost
~2.3k tokens
SKILL.md length
265 words
Files
1
Skills in repo
3
Repo updated
First seen
Licence
Apache-2.0

At a glance

为 mfish-nocode-pro 项目集成 Flowable 工作流审批能力,包括注册 FlowKey、实体审批状态字段、Service 启动/撤回流程、Controller 审批回调接口、Feign 回调接口注册五个步骤的完整代码模板。当用户说"带工作流审批"、"发布审核流程"、"集成工作流"、"审批回调"时使用此 skill。

  • Works in 4 steps: 新审批业务必须先在 mf-api 下提供独立 Feign 回调接口模块(例如… → FlowableParam.callback 必须填写 API 模块中的… → 单体模式覆盖实现必须放在… → …
  • Backend & APIs work in your project
  • SKILL.md covers 核心概念, 审批状态约定, 集成步骤 and 注意事项, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Workflow Audit is an agent skill from mfish-qf/mfish-nocode. 为 mfish-nocode-pro 项目集成 Flowable 工作流审批能力,包括注册 FlowKey、实体审批状态字段、Service 启动/撤回流程、Controller 审批回调接口、Feign 回调接口注册五个步骤的完整代码模板。当用户说"带工作流审批"、"发布审核流程"、"集成工作流"、"审批回调"时使用此 skill。

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs. It works with Spring Boot. The repository describes itself as: 摸鱼低代码平台,是一款致力于让开发像摸鱼一样轻松的低代码/无代码平台。首创微服务单体服务一体化架构。基于SpringBoot4、Spring Ai、Vue3等最新前后端技术栈。已用于多个成熟项目,学习和实战两不误。我们希望打破技术门槛,让程序员和非程序员都能快速构建业务系统,提升效率,释放创造力。 The licence is Apache-2.0.

When your agent uses it

  • Backend & APIs work in your project

Example prompts

  • “带工作流审批”
  • “发布审核流程”
  • “/workflow-audit”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. 新审批业务必须先在 mf-api 下提供独立 Feign 回调接口模块(例如 mf-demo-api),接口继承 RemoteAuditApi,并提供 fallbackFactory。
  2. FlowableParam.callback 必须填写 API 模块中的 Feign 接口全限定名(不要填写业务模块本地类路径)。
  3. 单体模式覆盖实现必须放在 mf-common/mf-common-api,Bean 名与 Feign contextId 对应(如 remoteDemoLeaveApplyService)。
  4. mf-common-api 通过依赖 API 模块实现解耦,不直接依赖 mf-business;如需调用业务方法,优先通过 Spring 容器按 Bean 名调用。

What it can do on your machine

Read from SKILL.md and the folder at commit 664fc6b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are java).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Workflow Audit loads about 2.3k tokens when it runs. Until then it costs about 46 tokens; SKILL.md has 265 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~46
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mfish-qf/mfish-nocode at commit 664fc6b, republished under its Apache-2.0 licence (© mfish-qf). 265 words, ~2,328 tokens.

Download SKILL.mdSave it as .claude/skills/workflow-audit/SKILL.md (or your agent's skills folder).
name
workflow-audit
description
为 mfish-nocode-pro 项目集成 Flowable 工作流审批能力,包括注册 FlowKey、实体审批状态字段、Service 启动/撤回流程、Controller 审批回调接口、Feign 回调接口注册五个步骤的完整代码模板。当用户说"带工作流审批"、"发布审核流程"、"集成工作流"、"审批回调"时使用此 skill。

工作流审批集成

适用于需要发布/审核流程的业务模块(如大屏发布、内容审核等),在标准 CRUD 基础上叠加工作流能力。

核心概念

组件说明
FlowableParam<T>启动工作流参数:key(流程定义key)、id(业务id)、prefix(回调URL前缀)、callback(回调Feign接口全路径)
FlowKey 枚举流程定义key枚举,新业务须在此注册,路径:mf-api/mf-workflow-api/.../FlowKey.java
RemoteAuditApi<T>审批回调接口,Controller 需实现 approved/rejected/canceled 三个方法
WorkflowCompleteResult回调结果体:processInstanceId、comment、eventName
RemoteWorkflowServiceFeign 客户端,用于启动/删除流程实例

审批状态约定

auditState 值含义触发时机
0审核中发布提交时设置
1已通过approved 回调时设置
2未通过rejected 回调时设置
null已取消canceled 回调时设置

集成步骤

第一步:注册 FlowKey

在 FlowKey.java 枚举中添加新流程定义 key:

java
// mf-api/mf-workflow-api/src/main/java/cn/com/mfish/common/workflow/api/enums/FlowKey.java
新业务名称 ("xxx_release"),  // key 需与 BPMN 文件中的 process id 一致
第二步:实体新增审批状态字段
java
@Schema(description = "审核状态 null 未发布 0 审核中 1 已通过 2 未通过")
private Integer auditState;

注意:实体类必须添加完整的 Swagger 注解:

  • 类级别:@Schema(description = "描述信息", name = "类名")
  • 字段级别:每个字段都需添加 @Schema(description = "字段描述")
  • 便于生成完整的 API 文档和 Swagger UI 展示
第三步:Service 中启动和撤回工作流
java
import cn.com.mfish.common.core.constants.RPCConstants;
import cn.com.mfish.common.core.entity.WorkflowCompleteResult;
import cn.com.mfish.common.core.exception.MyRuntimeException;
import cn.com.mfish.common.core.web.Result;
import cn.com.mfish.common.workflow.api.entity.FlowableParam;
import cn.com.mfish.common.workflow.api.enums.FlowKey;
import cn.com.mfish.common.workflow.api.remote.RemoteWorkflowService;
import jakarta.annotation.Resource;
import org.springframework.transaction.annotation.Transactional;

@Service
public class {类名}ServiceImpl extends ServiceImpl<{类名}Mapper, {类名}> implements {类名}Service {

    @Resource
    RemoteWorkflowService remoteWorkflowService;

    /** 发布(新增并启动工作流) */
    @Override
    @Transactional
    public Result<{类名}> insert{类名}({类名} entity) {
        // 业务唯一性校验:避免重复发布
        if (baseMapper.exists(new LambdaQueryWrapper<{类名}>()
                .eq({类名}::getSourceId, entity.getSourceId()))) {
            throw new MyRuntimeException("错误:已存在,不能重复发布!");
        }
        entity.setAuditState(0);
        if (save(entity)) {
            startProcess(entity);
            return Result.ok(entity, "{中文名称}-发布成功!");
        }
        return Result.fail(entity, "错误:{中文名称}-发布失败!");
    }

    /** 撤回(删除记录并撤销工作流) */
    @Override
    @Transactional
    public Result<Boolean> delete{类名}(String id) {
        {类名} entity = getById(id);
        if (entity == null) {
            return Result.ok(false, "错误:记录不存在!");
        }
        if (remove(new LambdaQueryWrapper<{类名}>().eq({类名}::getId, id))) {
            Result<String> result = remoteWorkflowService.delProcessByBusinessKey(
                    RPCConstants.INNER, entity.getId(), "用户撤回");
            if (!result.isSuccess()) {
                throw new MyRuntimeException(result.getMsg());
            }
            return Result.ok(true, "撤回成功!");
        }
        return Result.fail(false, "错误:撤回失败!");
    }

    /** 审批回调:更新审批状态 */
    @Override
    public Result<String> audit(String id, Integer auditState, WorkflowCompleteResult result) {
        {类名} entity = baseMapper.selectById(id);
        if (entity == null) throw new MyRuntimeException("错误:记录不存在!");
        entity.setAuditState(auditState);
        if (!updateById(entity)) throw new MyRuntimeException("错误:审批操作异常!");
        return Result.ok(id, "审批操作成功!");
    }

    /** 启动工作流 */
    private void startProcess({类名} entity) {
        Result<String> result = remoteWorkflowService.startProcess(RPCConstants.INNER,
            new FlowableParam<String>()
                .setKey(FlowKey.{对应枚举}.toString())
                .setId(entity.getId())            // 业务id 作为 businessKey
                .setPrefix("{回调URL前缀}")         // Controller @RequestMapping 路径(不含 /)
                .setCallback("{Feign接口全路径}")   // 例如:cn.com.mfish.xxx.api.remote.RemoteXxxService
        );
        if (!result.isSuccess()) throw new MyRuntimeException(result.getMsg());
    }
}
第四步:Controller 追加审批回调接口

工作流引擎审批完成后,通过 Feign 回调这三个接口,无需 @RequiresPermissions:

java
import cn.com.mfish.common.core.entity.WorkflowCompleteResult;

// 追加到现有 Controller 末尾

@PostMapping("/approved/{id}")
public Result<String> approved(
        @PathVariable String id,
        @RequestBody WorkflowCompleteResult result) {
    return {变量名}Service.audit(id, 1, result);
}

@PostMapping("/rejected/{id}")
public Result<String> rejected(
        @PathVariable String id,
        @RequestBody WorkflowCompleteResult result) {
    return {变量名}Service.audit(id, 2, result);
}

@PostMapping("/canceled/{id}")
public Result<String> canceled(
        @PathVariable String id,
        @RequestBody WorkflowCompleteResult result) {
    return {变量名}Service.audit(id, null, result);
}
第五步:注册 Feign 回调接口(微服务模式)

在 mf-api/mf-xxx-api 模块中定义回调 Feign 接口,继承 RemoteAuditApi<String>:

java
import cn.com.mfish.common.core.entity.RemoteAuditApi;

@FeignClient(
    contextId = "remote{类名}Service",
    value = ServiceConstants.XXX_SERVICE,
    fallbackFactory = Remote{类名}FallBack.class
)
public interface Remote{类名}Service extends RemoteAuditApi<String> {
    // 其他跨服务调用方法...
}
  • FlowableParam.callback 填写此接口的全路径类名
  • FlowableParam.prefix 填写 Controller 的 @RequestMapping 路径(不含 /)

注意事项

  • prefix 与 Controller @RequestMapping 必须一致,回调 URL 拼接规则:/{prefix}/approved/{id}
  • 编辑已发布记录前需校验审核状态:auditState=1 的记录禁止直接编辑,需先撤回
  • 重复发布校验:发布前通过 sourceId 或业务唯一键检查是否已存在记录
  • 撤回时需同步调用 remoteWorkflowService.delProcessByBusinessKey(...) 删除工作流实例
  • Service 接口中需声明 audit(String id, Integer auditState, WorkflowCompleteResult result) 方法
  • 异常处理规范:人为抛出的业务异常统一采用 MyRuntimeException 处理
    • 引入包:import cn.com.mfish.common.core.exception.MyRuntimeException;
    • 使用场景:记录不存在、重复提交、状态校验失败等业务异常情况
    • 示例代码:
      java
      // 记录不存在
      if (entity == null) {
          throw new MyRuntimeException("错误:记录不存在!");
      }
      
      // 重复发布校验
      if (baseMapper.exists(new LambdaQueryWrapper<Entity>()
              .eq(Entity::getSourceId, sourceId))) {
          throw new MyRuntimeException("错误:已存在,不能重复发布!");
      }
      
      // 审批状态校验
      if (!"approved".equals(entity.getAuditState())) {
          throw new MyRuntimeException("错误:审批状态不正确!");
      }
    • 消息格式:建议以 "错误:" 开头,便于前端统一处理和识别
    • 不要使用:避免直接使用 RuntimeException 或其他自定义异常
  • 安全规范 - 异常信息不暴露给前端:
    • 核心原则:返回给前端的错误消息必须是友好的、通用的提示,不能包含具体的异常堆栈或技术细节
    • 错误示例:return Result.fail(false, "错误:流程配置不正确," + e.getMessage()); ❌
    • 正确示例:return Result.fail(false, "错误:流程配置不正确,请检查流程设计是否完整且符合规范"); ✅
    • 日志记录:详细的异常信息应通过 log.error() 记录到日志文件中,便于开发人员排查
    • 实现模式:
      java
      try {
          // 业务逻辑
          BpmnConverter.convertToBpmn(...);
      } catch (Exception e) {
          // 详细异常信息记录到日志
          log.error("流程格式化失败:{}", e.getMessage(), e);
          // 返回给前端的是友好的提示信息
          return Result.fail(false, "错误:流程配置不正确,请检查流程设计是否完整且符合规范");
      }

相关参考


规范补充(2026-04)

  1. 新审批业务必须先在 mf-api 下提供独立 Feign 回调接口模块(例如 mf-demo-api),接口继承 RemoteAuditApi<T>,并提供 fallbackFactory。
  2. FlowableParam.callback 必须填写 API 模块中的 Feign 接口全限定名(不要填写业务模块本地类路径)。
  3. 单体模式覆盖实现必须放在 mf-common/mf-common-api,Bean 名与 Feign contextId 对应(如 remoteDemoLeaveApplyService)。
  4. mf-common-api 通过依赖 API 模块实现解耦,不直接依赖 mf-business;如需调用业务方法,优先通过 Spring 容器按 Bean 名调用。

优化记录(2026-04-19)

  1. mf-demo-api 创建后,必须同步加入根 pom.xml 的 dependencyManagement,避免子模块遗漏版本管理。
  2. BootDemoLeaveApplyService 禁止通过反射获取 demoLeaveApplyService,应改为依赖注入 DemoLeaveApplyService。
  3. DemoLeaveApplyService 直接下沉到 mf-common(例如 mf-common-demo),不要再额外拆分 DemoLeaveApplyAuditService。
  4. 该模式下保持依赖方向为:mf-common-api -> mf-common-demo、mf-business -> mf-common-demo,并为后续 Feign 扩展预留统一服务接口。

依赖约束(2026-04-19)

  1. mf-common-demo 的 pom.xml 默认仅引入: <dependency><groupId>com.baomidou</groupId><artifactId>mybatis-plus-spring</artifactId></dependency>。
  2. 不要默认引入 mybatis-plus-annotation、mybatis-plus-extension、fastexcel;仅在确有直接编译依赖时再按最小集补充。
  3. 若公共模块实体/接口仅用于跨层共享,优先保持依赖最小化,避免把业务模块的技术依赖扩散到 mf-common。

© mfish-qf, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .codex/skills/workflow-audit of mfish-qf/mfish-nocode.

Open the folder on GitHubat commit 664fc6b

Compare with similar skills

Workflow Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Workflow Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Workflow Audit this skillmfish-qf/mfish-nocode747—~2.3kAutomated safety check: PassApache-2.0
Mall4jgz-yami/mall4j5.3k—~640Automated safety check: NotesAGPL-3.0
Spring Bootpiomin/claude-ai-spring-boot1.3k—~2kAutomated safety check: PassApache-2.0
Dr Jskilljdubois/dr-jskill342—~4.6kAutomated safety check: NotesApache-2.0
Gsgo-spring/go-spring1.8k—~1.1kAutomated safety check: PassApache-2.0
WxJava Integration Guidebinarywang/WxJava33k—~123Automated safety check: PassApache-2.0

Similar skills

  • Mall4j

    gz-yami/mall4j

    Mall4j 开源版现有功能副驾驶:本地启动、mall4v/mall4m/mall4uni、商品/SKU、购物车、下单支付、订单发货、会员、运费、权限、部署排查。适用于下载 mall4j / yami-shop 后按现有功能使用或二次开发;不要编造开源版没有的能力。

    5.3k GitHub stars~640 tokensUpdated 8 days ago
    Backend & APIsAuto-check: notes
  • Spring Boot

    piomin/claude-ai-spring-boot

    Spring Boot 3.x development - REST APIs, JPA, Security, Testing, and Cloud-native patterns.

    1.3k GitHub stars~2k tokensUpdated 5 mo ago
    Backend & APIsAuto-check passed
  • Dr Jskill

    jdubois/dr-jskill

    Creates Java + Spring Boot projects: Web applications, full-stack apps with Vue.js or Angular or React or vanilla JS, PostgreSQL, REST APIs, and Docker.

    342 GitHub stars~4.6k tokensUpdated 7 days ago
    Backend & APIsAuto-check: notes
  • Gs

    go-spring/go-spring

    Go-Spring 项目研发托管入口:一句话诉求经 规划(Plan)→ 执行(Execute)→ 交付(Settle)循环,从工具集(起骨架/加接口/重生成/接组件/补测试)中选取组合并落地。在 Go-Spring 项目中开展任一研发任务时触发;由 Plan 判定是否接管,超范围时放手。

    1.8k GitHub stars~1.1k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • WxJava Integration Guide

    binarywang/WxJava

    Plans a WxJava setup for Java, Spring Boot or Solon projects that call WeChat services, from module and BOM choice to config and a minimal working call.

    33k GitHub stars~123 tokensUpdated 11 days ago
    Backend & APIsAuto-check passed
  • Grails Developer Guide

    apache/grails-core

    Guides building Grails web applications and REST APIs with GORM, controllers, services, views, plugins and Spock and Geb testing.

    2.9k GitHub stars~4.9k tokensUpdated today
    Backend & APIsAuto-check passed

More from mfish-qf/mfish-nocode

  • Crud Generator

    mfish-qf/mfish-nocode

    为 mfish-nocode-pro 项目生成标准增删改查(CRUD)代码,包括 Entity、Req、Mapper、Service、ServiceImpl、Controller 六层结构。当用户说"帮我生成增删改查"、"新增一个模块"、"生成CRUD代码"时使用此 skill。

    747 GitHub stars~4.6k tokensUpdated 22 days ago
    Auto-check passed
  • Frontend Crud

    mfish-qf/mfish-nocode

    为 mfish-nocode-pro 项目前端(Vue3 + TypeScript)生成标准增删改查页面代码,包括 Model、API、data、index.vue、Modal、ViewModal 六个文件。当用户说"帮我生成前端增删改查"、"新增前端页面"、"生成前端CRUD"时使用此 skill。

    747 GitHub stars~3.8k tokensUpdated 22 days ago
    Auto-check passed

Works with

Categories

Questions about Workflow Audit

What does Workflow Audit do?

为 mfish-nocode-pro 项目集成 Flowable 工作流审批能力,包括注册 FlowKey、实体审批状态字段、Service 启动/撤回流程、Controller 审批回调接口、Feign 回调接口注册五个步骤的完整代码模板。当用户说"带工作流审批"、"发布审核流程"、"集成工作流"、"审批回调"时使用此 skill。. Workflow Audit is an agent skill from mfish-qf/mfish-nocode.

When should I use Workflow Audit?

Workflow Audit fits situations like: backend & APIs work in your project.

How do I install Workflow Audit in Claude Code?

Run `npx skills add mfish-qf/mfish-nocode --skill workflow-audit -a claude-code`. Or copy the skill folder (.codex/skills/workflow-audit in mfish-qf/mfish-nocode) into .claude/skills/workflow-audit in your project. Claude Code loads it when a task matches its description.

How do I install Workflow Audit in Codex?

Run `npx skills add mfish-qf/mfish-nocode --skill workflow-audit -a codex`. Or copy the skill folder (.codex/skills/workflow-audit in mfish-qf/mfish-nocode) into .agents/skills/workflow-audit in your project. Codex loads it when a task matches its description.

Can I use Workflow Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mfish-qf/mfish-nocode --skill workflow-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/workflow-audit, .gemini/skills/workflow-audit, .github/skills/workflow-audit and .opencode/skills/workflow-audit in your project.

What does Workflow Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: Workflow Audit is instructions for the agent only.

Does Workflow Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Workflow Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Workflow Audit use?

Workflow Audit is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Workflow Audit use?

About 2.3k tokens (SKILL.md is roughly 9.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Workflow Audit?

Skills that share tags, products or a category with Workflow Audit: Mall4j (gz-yami/mall4j, 5.3k stars), Spring Boot (piomin/claude-ai-spring-boot, 1.3k stars), Dr Jskill (jdubois/dr-jskill, 342 stars) and Gs (go-spring/go-spring, 1.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Workflow Audit?

mfish-qf (a GitHub user) maintains it in mfish-qf/mfish-nocode, which has 747 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on September 15, 2026.

Source: mfish-qf/mfish-nocode on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.