Agent skill

Cross Platform Contract Propagation Audit

by sickn33 in sickn33/agentic-awesome-skills

A skill your agent uses when auditing whether a field, enum, flag, or API contract propagates consistently across storage, services, clients, analytics, and tests.

MITAuto-check passedBackend & APIs

Install Cross Platform Contract Propagation Audit

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill cross-platform-contract-propagation-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills cross-platform-contract-propagation-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cross-platform-contract-propagation-audit .claude/skills/cross-platform-contract-propagation-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cross-platform-contract-propagation-audit
GitHub stars
47k
Used in
1 other repo
Token cost
~2.3k tokens
SKILL.md length
1,018 words
Files
1
Skills in repo
1,497
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when auditing whether a field, enum, flag, or API contract propagates consistently across storage, services, clients, analytics, and tests.

  • Works in 6 steps: Write the semantic contract → Enumerate the propagation graph → Trace evidence edge by edge → …
  • Auditing whether a field
  • SKILL.md covers Overview, When to Use This Skill, How It Works and Example, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Cross Platform Contract Propagation Audit is an agent skill from sickn33/agentic-awesome-skills. Use when auditing whether a field, enum, flag, or API contract propagates consistently across storage, services, clients, analytics, and tests.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering API design. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • Auditing whether a field
  • API contract propagates consistently across storage

Example prompts

  • “/cross-platform-contract-propagation-audit”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Write the semantic contract
  2. Enumerate the propagation graph
  3. Trace evidence edge by edge
  4. Check the high-risk boundaries
  5. Build a state-by-path test matrix
  6. Decide against explicit release gates

What it can do on your machine

Read from SKILL.md and the folder at commit b84d35a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cross Platform Contract Propagation Audit loads about 2.3k tokens when it runs. Until then it costs about 46 tokens; SKILL.md has 1,018 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~46
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit b84d35a, republished under its MIT licence (© sickn33). 1,018 words, ~2,270 tokens.

Download SKILL.mdSave it as .claude/skills/cross-platform-contract-propagation-audit/SKILL.md (or your agent's skills folder).
name
cross-platform-contract-propagation-audit
description
Use when auditing whether a field, enum, flag, or API contract propagates consistently across storage, services, clients, analytics, and tests.
category
development
risk
safe
source
self
source_type
self
date_added
2026-08-18
author
Whxuan0701
tags
contract-audit, cross-platform, api, schema, feature-flags
tools
claude, cursor, gemini, codex

Cross-Platform Contract Propagation Audit

Overview

Audit a contract change from its source through every transformation and consumer before release. Treat a field that exists in one schema as incomplete until its meaning, defaults, wire behavior, rollout controls, client handling, analytics, and tests are proven across all relevant paths.

This is a read-only evidence workflow. It reports propagation gaps; it does not implement them.

When to Use This Skill

  • Use when adding or changing a field, enum value, status, capability, or feature flag shared by multiple components.
  • Use when database, backend, API, Web, Android, iOS, jobs, events, or analytics may interpret the same value differently.
  • Use when a change must preserve existing records, older clients, or a default-off rollout.
  • Use when a change looks complete in one endpoint but may be missing from alternate entry points or generated models.

How It Works

Step 1: Write the semantic contract

Before tracing files, state the business invariant and define every observable state. Distinguish values that languages and serializers often collapse:

StateQuestions to answer
missingIs the property absent on the wire or in an old record?
nullIs it unknown, inherited, unsupported, or invalid?
false or zeroIs this an explicit disabled value or a default?
true or non-zeroWhat behavior becomes available?
unknown enumMust old consumers ignore, preserve, or reject it?

Record compatibility requirements, ownership, rollout condition, and the exact user-visible or system behavior for each state. Do not accept optional, nullable, and default false as equivalent without evidence.

Step 2: Enumerate the propagation graph

List every relevant node before judging completeness:

text
source of truth
  -> persistence and migration
  -> domain model and mapper
  -> service or policy computation
  -> every API, event, cache, and job projection
  -> generated or handwritten client model
  -> client state and presentation logic
  -> analytics and operational observability
  -> tests, rollout, and rollback checks

Include alternate read/write endpoints, list/detail projections, background consumers, offline caches, admin surfaces, older app versions, and feature-flag evaluation points when they are in scope. Mark a node not applicable only with a reason.

Step 3: Trace evidence edge by edge

For each edge, cite the producer, transformation, consumer, and test using file paths, symbols, schema names, or other inspectable evidence. Assign one status:

StatusMeaning
provenProducer and consumer agree, with direct evidence and relevant test coverage.
partialSome paths or states agree, but coverage is incomplete.
missingA required propagation edge or consumer is absent.
conflictTwo layers implement different semantics.
unknownEvidence is unavailable or ambiguous.
not_applicableThe layer is outside scope, with a stated reason.

Do not upgrade likely, convention, type compatibility, or a framework default to proven. A declaration proves shape, not runtime mapping or behavior.

Step 4: Check the high-risk boundaries

Inspect these boundaries explicitly:

  • Migration and existing data: default, backfill, nullability, rollback, mixed-version reads and writes.
  • Domain mapping: missing/null coercion, enum fallbacks, validation, derived values, serialization symmetry.
  • Fan-out surfaces: list and detail DTOs, events, caches, jobs, search indexes, SDKs, and alternate API versions.
  • Client compatibility: missing and explicit-null decoding, unknown enums, generated-model drift, cached payloads, release or minified builds.
  • Rollout control: flag default, evaluation location, cohort consistency, kill switch, and behavior when stored data disagrees with the flag.
  • Analytics: offered, rendered, attempted, succeeded, and failed events carry enough contract and version context to join reliably.
Step 5: Build a state-by-path test matrix

Cross the semantic states from Step 1 with every material path from Step 2. At minimum, include existing-data defaults, enabled and disabled values, flag on and off, alternate endpoints, current clients, and representative older clients.

For each cell, record the expected result, evidence, and status. A unit test at one layer does not prove an end-to-end cell. Use unknown for unexecuted cells.

Show full SKILL.md (446 more words)Show less
Step 6: Decide against explicit release gates

Derive gates from the stated contract, not from intuition. A release is blocked when an edge or compatibility invariant that the contract explicitly requires is missing, conflict, or unknown, or when rollback cannot contain the new behavior. Use inconclusive only when the release contract itself is absent or ambiguous, so the audit cannot determine which edges or invariants are required. Do not downgrade a known required but unproven gate from blocked to inconclusive.

Return the smallest verification or repair set that would change the verdict. Keep implementation suggestions separate from proven findings.

Example

For a nullable can_complete field that should expose an action only when both the stored capability and server flag are true:

text
Invariant: show action = (feature_flag == on) AND (can_complete == true)

Path                                      Status    Evidence
DB null -> domain false -> detail API     partial   mapper exists; null case untested
DB true + flag off -> detail API          unknown   flag branch not tested
DB true + flag on -> list API             missing   list DTO omits field
missing field -> Web hidden               proven    client test covers missing
explicit null -> Android hidden           unknown   decoder behavior untested
impression -> click attribution           missing   click event lacks capability/cohort

Verdict: blocked by the missing list projection and incomplete flag enforcement;
older-client and explicit-null compatibility remain unverified.

Best Practices

  • Start from behavior and state semantics, then trace code; do not start from a filename guess.
  • Search for field names, serialized aliases, enum values, DTOs, mappers, flags, and analytics events.
  • Cite negative searches with their scope and revision; absence claims require a bounded search.
  • Separate source-of-truth behavior from client presentation and telemetry.
  • Verify all entry points that can produce the same user-visible state.
  • Keep findings reproducible: contract, revision, evidence, status, impact, and next check.

Limitations

  • Static evidence cannot prove runtime configuration, deployed schema state, generated-code freshness, or client behavior that was not exercised.
  • Repository access may omit private services, analytics schemas, remote flags, or older released clients; mark those edges unknown.
  • This skill finds propagation and semantic gaps, not every security, performance, or product-design defect.
  • A complete graph does not prove the underlying business rule is correct.

Security & Safety Notes

  • Keep the audit read-only unless the user separately authorizes implementation or runtime testing.
  • Redact production records, credentials, user identifiers, and sensitive payload fields from evidence.
  • Do not enable flags, mutate data, publish schemas, or exercise production actions merely to fill an evidence gap.

Common Pitfalls

  • Problem: The field exists in the database and one response, so the change is called complete. Solution: Trace every projection and consumer, including alternate endpoints and events.
  • Problem: Missing, null, and false are treated as the same state. Solution: Define and test each state at every serialization boundary.
  • Problem: Type declarations are treated as runtime proof. Solution: Require mapping, decoding, behavior, and test evidence before using proven.
  • Problem: The feature flag hides UI but not data or alternate APIs. Solution: Map every flag evaluation point and test stored-value/flag combinations.
  • Problem: A green unit test suite is presented as cross-platform coverage. Solution: Build the state-by-path matrix and preserve unexecuted cells as unknown.
  • @api-analyzer - Validate the correctness of an individual API request.
  • @spec-to-code-compliance - Compare formal blockchain specifications with implementations.
  • @technical-change-tracker - Record implementation progress and handoff state across sessions.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/cross-platform-contract-propagation-audit of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit b84d35a

Used in 1 other repository

We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Cross Platform Contract Propagation Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cross Platform Contract Propagation Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cross Platform Contract Propagation Audit this skillsickn33/agentic-awesome-skills47k1 repos~2.3kAutomated safety check: PassMIT
Nodejs Backend Patternsever-works/ever-works16218 repos~4kAutomated safety check: PassAGPL-3.0
API DesignerJeffallan/claude-skills12k1 repos~2kAutomated safety check: PassMIT
Pangolin CRUD Endpointsfosrl/pangolin23k—~461Automated safety check: PassCustom licence
Backend PatternshellangleZ/burn-in-cceverywhere-ralph11217 repos~3.3kAutomated safety check: PassNone
API Design Principlesjh941213/my-cc-harness12518 repos~3.4kAutomated safety check: PassNone

Similar skills

  • Nodejs Backend Patterns

    ever-works/ever-works

    Build production-ready Node.js backend services with Express/Fastify, implementing middleware patterns, error handling, authentication, database integration, and API design best practices.

    162 GitHub starsUsed in 18 repos~4k tokens
    Backend & APIsAuto-check passed
  • API Designer

    Jeffallan/claude-skills

    Designs REST and GraphQL APIs from resource modeling to an OpenAPI 3.1 contract, with versioning, pagination and RFC 7807 error handling.

    12k GitHub starsUsed in 1 repo~2k tokens
    Backend & APIsAuto-check passed
  • Use whenever asked to add, create, or scaffold a CRUD endpoint, router, or entity in this repo's server (create/list/get/update/delete handlers, new…

    23k GitHub stars~461 tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Backend Patterns

    hellangleZ/burn-in-cceverywhere-ralph

    Backend architecture patterns, API design, database optimization, and server-side best practices for Node.js, Express, and Next.js API routes.

    112 GitHub starsUsed in 17 repos~3.3k tokens
    Backend & APIsAuto-check passed
  • API Design Principles

    jh941213/my-cc-harness

    REST 및 GraphQL API 설계 원칙 가이드. An agent skill from jh941213/my-cc-harness.

    125 GitHub starsUsed in 18 repos~3.4k tokens
    Backend & APIsAuto-check passed
  • API And Interface Design

    dzhalaevd/Donatello

    Guides stable API and interface design. An agent skill from dzhalaevd/Donatello.

    135 GitHub starsUsed in 8 repos~2.6k tokens
    Backend & APIsAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,497 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Categories

Questions about Cross Platform Contract Propagation Audit

What does Cross Platform Contract Propagation Audit do?

A skill your agent uses when auditing whether a field, enum, flag, or API contract propagates consistently across storage, services, clients, analytics, and tests. Cross Platform Contract Propagation Audit is an agent skill from sickn33/agentic-awesome-skills. Use when auditing whether a field, enum, flag, or API contract propagates consistently across storage, services, clients, analytics, and tests.

When should I use Cross Platform Contract Propagation Audit?

Cross Platform Contract Propagation Audit fits situations like: auditing whether a field; API contract propagates consistently across storage.

How do I install Cross Platform Contract Propagation Audit in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill cross-platform-contract-propagation-audit -a claude-code`. Or copy the skill folder (skills/cross-platform-contract-propagation-audit in sickn33/agentic-awesome-skills) into .claude/skills/cross-platform-contract-propagation-audit in your project. Claude Code loads it when a task matches its description.

How do I install Cross Platform Contract Propagation Audit in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill cross-platform-contract-propagation-audit -a codex`. Or copy the skill folder (skills/cross-platform-contract-propagation-audit in sickn33/agentic-awesome-skills) into .agents/skills/cross-platform-contract-propagation-audit in your project. Codex loads it when a task matches its description.

Can I use Cross Platform Contract Propagation Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill cross-platform-contract-propagation-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cross-platform-contract-propagation-audit, .gemini/skills/cross-platform-contract-propagation-audit, .github/skills/cross-platform-contract-propagation-audit and .opencode/skills/cross-platform-contract-propagation-audit in your project.

What does Cross Platform Contract Propagation Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: Cross Platform Contract Propagation Audit is instructions for the agent only.

Does Cross Platform Contract Propagation Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Cross Platform Contract Propagation Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cross Platform Contract Propagation Audit use?

Cross Platform Contract Propagation Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cross Platform Contract Propagation Audit use?

About 2.3k tokens (SKILL.md is roughly 9.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cross Platform Contract Propagation Audit?

Skills that share tags, products or a category with Cross Platform Contract Propagation Audit: Nodejs Backend Patterns (ever-works/ever-works, 162 stars), API Designer (Jeffallan/claude-skills, 12k stars), Pangolin CRUD Endpoints (fosrl/pangolin, 23k stars) and Backend Patterns (hellangleZ/burn-in-cceverywhere-ralph, 112 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cross Platform Contract Propagation Audit?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,405 GitHub stars. The repository holds 1,497 skills in this directory. The repository was last updated on October 9, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.