Agent skill

Rigor Protection Uplift

by rigortype in rigortype/rigor

Close the protection gaps reported by rigor coverage --protection, using generated signatures before minimal residual annotations and a no-new-diagnostics gate.

MPL-2.0Auto-check passedDevelopment

Install Rigor Protection Uplift

skills CLI
$ npx skills add rigortype/rigor --skill rigor-protection-uplift -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install rigortype/rigor rigor-protection-uplift --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/rigortype/rigor.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/rigor-protection-uplift .claude/skills/rigor-protection-uplift && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
rigor-protection-uplift
GitHub stars
106
Token cost
~1.5k tokens
SKILL.md length
734 words
Files
1
Skills in repo
36
Repo updated
First seen
Licence
MPL-2.0

At a glance

Close the protection gaps reported by rigor coverage --protection, using generated signatures before minimal residual annotations and a no-new-diagnostics gate.

  • Works in 5 steps: surface the holes → sig-gen first → author the residual (cheapest carrier… → …
  • Increasing bug-catching coverage in an adopting project
  • SKILL.md covers First: load the…, When to use, When NOT to use and Load-bearing rules (read…, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Rigor Protection Uplift is an agent skill from rigortype/rigor. Close the protection gaps reported by rigor coverage --protection, using generated signatures before minimal residual annotations and a no-new-diagnostics gate. Use when increasing bug-catching coverage in an adopting project; not for Rigor's own tree, bundled plugins, or first-time setup.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development. The repository describes itself as: Inference-first static analysis for Ruby. The licence is MPL-2.0.

When your agent uses it

  • Increasing bug-catching coverage in an adopting project
  • Not for Rigors own tree
  • Bundled plugins
  • First-time setup

Example prompts

  • “/rigor-protection-uplift”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. surface the holes
  2. sig-gen first
  3. author the residual (cheapest carrier per hole class)
  4. double-gate verify (both must hold)
  5. feed the residual back

What it can do on your machine

Read from SKILL.md and the folder at commit 3264953. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Rigor Protection Uplift loads about 1.5k tokens when it runs. Until then it costs about 79 tokens; SKILL.md has 734 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~79
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from rigortype/rigor at commit 3264953, republished under its MPL-2.0 licence (© rigortype). 734 words, ~1,523 tokens.

Download SKILL.mdSave it as .claude/skills/rigor-protection-uplift/SKILL.md (or your agent's skills folder).
name
rigor-protection-uplift
description
Close the protection gaps reported by `rigor coverage --protection`, using generated signatures before minimal residual annotations and a no-new-diagnostics gate. Use when increasing bug-catching coverage in an adopting project; not for Rigor's own tree, bundled plugins, or first-time setup.
license
MPL-2.0
metadata.version
0.1.0
metadata.homepage
https://github.com/rigortype/rigor

Rigor Protection Uplift

rigor coverage --protection (Tier 1) and rigor coverage --protection --mutation (Tier 2) surface "add a type here" — they never author the type. This skill acts on that surfacing under the discipline that keeps Rigor false-positive-safe: protection goes up, and not one line of working code starts reporting a new diagnostic.

First: load the version-current copy

This skill's exact commands, flags, carrier syntax, and rule ids drift between Rigor releases, so follow the copy that ships with the installed Rigor rather than any vendored or frozen copy of this file. Get the complete current procedure in one call:

sh
rigor skill --full rigor-protection-uplift

If you already loaded this skill via rigor skill you have the current copy — just proceed. If rigor is not on PATH, this task needs it: run rigor-next-steps to install Rigor first, then come back.

When to use

  • A user wants to raise how much of their code Rigor can actually catch bugs in.
  • You have coverage --protection output (an "add a type here" list) and want to close it.

When NOT to use

  • "Make my code more precise" with no protection goal — that is rigor coverage (precision), not --protection.
  • A project with no Rigor config yet — onboard first with rigor-project-init.

Load-bearing rules (read before touching a single type)

  1. The signal prioritises and verifies; the contract sources the type. Never write the type the coverage/mutation signal "wants". Write the type the code actually has, derived from the implementation and its callers. A type guessed from the signal is a false-confidence type — worse than no type.
  2. sig-gen first. A hand-written annotation is only the residual rigor sig-gen cannot reach. Every residual is a sig-gen-improvement to report, not just a private fix.
  3. "Minimal" = annotation footprint, not minimal-to-kill-the-mutant. Optimising literally for mutant death games the metric. Add the smallest true annotation that models the contract; if that also kills the mutant, good.
  4. Robustness (ADR-5). Tighten returns, keep parameters lenient. An over-tight param annotation breaks callers and breaches the false-positive discipline.

Procedure

Phase 1 — surface the holes
sh
rigor coverage --protection --format json PATHS

Read the ranked "add a type here" list (count, method_name, examples). Optionally confirm the highest-traffic ones actually buy catching power with the Tier 2 deep dive:

sh
rigor coverage --protection --mutation --format json   # changed-files by default
Phase 2 — sig-gen first
sh
rigor sig-gen --diff PATHS      # inspect; --write to apply

Adopt every concrete inferred signature. Note where sig-gen emits untyped for a site on the "add a type here" list — that is the residual Phase 3 owns.

Show full SKILL.md (340 more words)Show less
Phase 3 — author the residual (cheapest carrier per hole class)
Hole classCheapest carrier
Dynamic method returnannotate that method's return in sig/…rbs
Dynamic[top] | nil ivar read# @rbs @field: T (ADR-58 territory)
untyped param feeding the receivera lenient param annotation

Write the minimal true type. Prefer annotating the upstream source of the Dynamic (the method return / the ivar) over the call site itself.

Trap (carrier-additivity): a sidecar sig/…rbs is NOT purely additive. Declaring a class there flips it from inference-mode to RBS-declared mode and drops every member the RBS omits — a lone def formatted: () -> String can make Rigor forget the inferred initialize and reject Money.new(500). So either (1) adopt the full Phase-2 sig-gen base into the file and add the residual on top, or (2) use an in-place additive carrier (rbs-inline #: / a %a{rigor:v1:…} return-override) that annotates the method without re-declaring the class. "Minimal footprint" means the smallest true type, never the smallest file.

Phase 4 — double-gate verify (both must hold)
sh
rigor coverage --protection PATHS   # (a) the site is now protected / ratio up
rigor check PATHS                   # (b) no NEW diagnostic vs the post-sig-gen baseline

If (b) regresses, the annotation modeled the wrong contract — revert it, do not suppress the diagnostic. If (a) did not move, the carrier was wrong (often: you typed the call site, not the upstream Dynamic source). Gate (b) is a diff against the post-sig-gen state, not an absolute "zero diagnostics" — sig-gen itself can surface the acknowledge-mode FP envelope a project baseline absorbs; this skill owns only the increment it adds.

Phase 5 — feed the residual back

File each Phase-3 residual as a sig-gen gap (what shape did inference miss?). The hand annotation is the stopgap; the durable fix is raising inference so the residual disappears.

Honest bounds

Hand-RBS uplift is a finisher, not a path to 80% protection. The dominant remaining holes after this loop are intractable from annotation alone — external-gem Dynamic receivers, polymorphic value types, generic type parameters, dynamically-built classes. Those need parametric types / external RBS / engine folding (and are where the rigor-plugin-author escalation or a Rigor issue comes in), not another hand annotation. Expect a low-20s → low-30s% protection lift on a mature library, at zero diagnostic cost.

© rigortype, MPL-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/rigor-protection-uplift of rigortype/rigor.

Open the folder on GitHubat commit 3264953

Compare with similar skills

Rigor Protection Uplift next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Rigor Protection Uplift compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Rigor Protection Uplift this skillrigortype/rigor106—~1.5kAutomated safety check: PassMPL-2.0
Vercel Composition Patternssupabase/supabase111k58 repos~726Automated safety check: PassMIT
Finishing a Development Branchobra/superpowers297k5 repos~1.9kAutomated safety check: PassMIT
Typescript Advanced Typesrolling-scopes/rsschool-app10k25 repos~4.2kAutomated safety check: PassMPL-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k4 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • Official

    React composition patterns that scale. An agent skill from supabase/supabase.

    111k GitHub starsUsed in 58 repos~726 tokens
    DevelopmentAuto-check passed
  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    297k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Typescript Advanced Types

    rolling-scopes/rsschool-app

    Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.

    10k GitHub starsUsed in 25 repos~4.2k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 4 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed

More from rigortype/rigor

All 36 skills in this repo
  • Rigor Regression Sweep

    rigortype/rigor

    Measure Rigor's baseline drift across the tagged history of a real OSS Ruby project.

    106 GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Adjudicate a rigor unused report safely before proposing dead-code removal.

    106 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Rigor Baseline Reduce

    rigortype/rigor

    Reduce an existing .rigor-baseline.yml rule by rule by triaging sites, fixing or intentionally suppressing them, and regenerating the baseline.

    106 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Rigor Doctor

    rigortype/rigor

    Validate that a project's Rigor configuration, plugins, paths, and baseline are actually healthy.

    106 GitHub stars~767 tokensUpdated today
    Auto-check passed
  • Rigor Plugin Author

    rigortype/rigor

    Author a new Rigor plugin, choosing plugins/ for production support or examples/ for a contract walkthrough.

    106 GitHub stars~3.3k tokensUpdated today
    Auto-check: notes
  • Rigor Plugin Author

    rigortype/rigor

    Author a Rigor plugin in an adopting project or standalone rigor- gem for a DSL, framework, or metaprogramming pattern.

    106 GitHub stars~1.9k tokensUpdated today
    Auto-check passed

Categories

Questions about Rigor Protection Uplift

What does Rigor Protection Uplift do?

Close the protection gaps reported by rigor coverage --protection, using generated signatures before minimal residual annotations and a no-new-diagnostics gate. Rigor Protection Uplift is an agent skill from rigortype/rigor. Close the protection gaps reported by rigor coverage --protection, using generated signatures before minimal residual annotations and a no-new-diagnostics gate.

When should I use Rigor Protection Uplift?

Rigor Protection Uplift fits situations like: increasing bug-catching coverage in an adopting project; not for Rigors own tree; bundled plugins; first-time setup.

How do I install Rigor Protection Uplift in Claude Code?

Run `npx skills add rigortype/rigor --skill rigor-protection-uplift -a claude-code`. Or copy the skill folder (skills/rigor-protection-uplift in rigortype/rigor) into .claude/skills/rigor-protection-uplift in your project. Claude Code loads it when a task matches its description.

How do I install Rigor Protection Uplift in Codex?

Run `npx skills add rigortype/rigor --skill rigor-protection-uplift -a codex`. Or copy the skill folder (skills/rigor-protection-uplift in rigortype/rigor) into .agents/skills/rigor-protection-uplift in your project. Codex loads it when a task matches its description.

Can I use Rigor Protection Uplift in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rigortype/rigor --skill rigor-protection-uplift -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/rigor-protection-uplift, .gemini/skills/rigor-protection-uplift, .github/skills/rigor-protection-uplift and .opencode/skills/rigor-protection-uplift in your project.

What does Rigor Protection Uplift need to run?

SKILL.md names no scripts, command-line tools or credentials: Rigor Protection Uplift is instructions for the agent only.

Does Rigor Protection Uplift access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Rigor Protection Uplift safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Rigor Protection Uplift use?

Rigor Protection Uplift is published under the MPL-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Rigor Protection Uplift use?

About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Rigor Protection Uplift?

Skills that share tags, products or a category with Rigor Protection Uplift: Vercel Composition Patterns (supabase/supabase, 111k stars), Finishing a Development Branch (obra/superpowers, 297k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Rigor Protection Uplift?

rigortype (a GitHub organization) maintains it in rigortype/rigor, which has 106 GitHub stars. The repository holds 36 skills in this directory. The repository was last updated on October 10, 2026.

Source: rigortype/rigor on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.