Agent skill

Bundle Safety

by ZaxbyHub in ZaxbyHub/opencode-swarm

Bundle transform safety — minification variant selection, consumer-constraint verification, identifier preservation, and namespace re-export coverage for build output.

MITAuto-check passed

Install Bundle Safety

skills CLI
$ npx skills add ZaxbyHub/opencode-swarm --skill bundle-safety -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ZaxbyHub/opencode-swarm bundle-safety --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ZaxbyHub/opencode-swarm.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.opencode/skills/generated/bundle-safety .claude/skills/bundle-safety && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
bundle-safety
GitHub stars
496
Token cost
~2.3k tokens
SKILL.md length
852 words
Files
1
Skills in repo
91
Repo updated
First seen
Licence
MIT

At a glance

Bundle transform safety — minification variant selection, consumer-constraint verification, identifier preservation, and namespace re-export coverage for build output.

  • Works in 3 steps: Build the smallest possible test bundle… → Run the full build conformance suite… → Only merge if all guardrail assertions…
  • SKILL.md covers Trigger, Required Procedure, Forbidden Shortcuts and Delegation Template, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Bundle Safety is an agent skill from ZaxbyHub/opencode-swarm. Bundle transform safety — minification variant selection, consumer-constraint verification, identifier preservation, and namespace re-export coverage for build output.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Architect-centric agentic swarm plugin for OpenCode. Hub-and-spoke orchestration with SME consultation, code generation, and QA review. The licence is MIT.

Example prompts

  • “/bundle-safety”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Build the smallest possible test bundle with the proposed transform flags.
  2. Run the full build conformance suite (tests/unit/build/throw-and-verify-located.test.ts…
  3. Only merge if all guardrail assertions pass. A single grep guardrail failure blocks the change.

What it can do on your machine

Read from SKILL.md and the folder at commit a69d1a9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Bundle Safety loads about 2.3k tokens when it runs. Until then it costs about 45 tokens; SKILL.md has 852 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~45
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ZaxbyHub/opencode-swarm at commit a69d1a9, republished under its MIT licence (© ZaxbyHub). 852 words, ~2,278 tokens.

Download SKILL.mdSave it as .claude/skills/bundle-safety/SKILL.md (or your agent's skills folder).
name
bundle-safety
description
Bundle transform safety — minification variant selection, consumer-constraint verification, identifier preservation, and namespace re-export coverage for build output.
triggers
minify, minification, bundle, esbuild, build size, re-export, identifier, namespace re-export, exportLines, exportRanges, dist/index.js
generated_from_knowledge
5746c5c9-1330-4fbe-b62e-f564deb1ff77, 5d99affe-bdd1-4945-8cd8-fcf37abb8c84, 9323a8f0-c07e-41c2-9857-11a24c55dca2
source_knowledge_ids
5746c5c9-1330-4fbe-b62e-f564deb1ff77, 5d99affe-bdd1-4945-8cd8-fcf37abb8c84, 9323a8f0-c07e-41c2-9857-11a24c55dca2
generated_at
2026-07-02T20:47:50.522Z
confidence
0.6
status
active
version
1
skill_origin
generated
<!-- generated by opencode-swarm skill-generator. Do not edit by hand; edits will be preserved on regeneration only with controlled update mode. -->

Bundle Safety

Trigger

  • minify / minification / bundle / esbuild / build size
  • re-export / namespace re-export / exportLines / exportRanges
  • dist/index.js conformance checks
  • identifier preservation / stack trace readability
  • consumer-constraint verification before transforms

Required Procedure

(a) Minification Variant Selection

The standard minification configuration for the plugin bundle is identifier-preserving:

--minify-whitespace --minify-syntax

This yields ~22.3% size reduction on the main bundle (~1.28 MB absolute). The reduction is below the optimistic 35–43% range because identifier mangling is deliberately skipped.

Full identifier mangling (--minify-identifiers) is REJECTED. It breaks two hard constraints:

  1. 13 grep guardrail assertions — split across tests/unit/build/full-auto-toolbefore-fail-closed.test.ts (fail-closed hook substring/wrapping checks) and tests/unit/turbo/lean/runtime-conformance.test.ts (Lean Turbo identifier-preservation checks). Mangling would rename these identifiers and cause all 13 assertions to fail.
  2. Stack-trace readability — preserved identifier names are required for runtime debugging. The release-gate test tests/unit/build/throw-and-verify-located.test.ts asserts that thrown errors carry readable stack frames with recognizable function names (e.g. initializeOpenCodeSwarm).

Decision is final: identifier-preserving minify is the standard. Do not enable --minify-identifiers without a documented exception approved by the team.

(b) Consumer-Constraint Verification Before Transforms

Before merging any minification or transform change:

  1. Build the smallest possible test bundle with the proposed transform flags.
  2. Run the consumer's exact constraint check first — the 13 grep guardrails are split across tests/unit/build/full-auto-toolbefore-fail-closed.test.ts (fail-closed hook constraints) and tests/unit/turbo/lean/runtime-conformance.test.ts (Lean Turbo identifier-preservation checks). Together they are the authoritative consumer constraint.
  3. Run the full build conformance suite (tests/unit/build/throw-and-verify-located.test.ts, tests/unit/turbo/lean/runtime-conformance.test.ts) to verify runtime integrity and stack-trace readability.
  4. Only merge if all guardrail assertions pass. A single grep guardrail failure blocks the change.

This procedure applies to any transform that could rename, inline, or remove identifiers — not just minification flags.

(c) Identifier-Preservation Testing

Verify identifier names survive the transform via the layered test stack:

Static (grep) layer:

  • tests/unit/build/full-auto-toolbefore-fail-closed.test.ts — fail-closed hook substring/wrapping checks verifying that specific identifier substrings (e.g. fullAutoPermissionHook.toolBefore, guardrailsHooks.toolBefore, scopeGuardHook.toolBefore, delegationGateHooks.toolBefore) are present and that fail-closed hooks are not wrapped in safeHook(...).
  • tests/unit/turbo/lean/runtime-conformance.test.ts — distContains() checks verifying that Lean Turbo integration-point identifiers (verifyLeanTurboPhaseReady, verifyLeanTurboTaskCompletion, LEAN_TURBO_BANNER, enableLeanTurbo, hasActiveTurboMode) survive the build.

Runtime layer:

  • tests/unit/build/throw-and-verify-located.test.ts — asserts that thrown errors carry readable stack frames with preserved function names (e.g. initializeOpenCodeSwarm). This is the runtime complement to the static grep assertions.

Before enabling --minify-identifiers, confirm ALL of the following:

  • No eval() or Function('...') dispatch in the bundle (mangled identifiers break dynamic dispatch).
  • No constructor.name or Function.name introspection in production paths.
  • No @__PURE__ annotations or side-effectful top-level patterns that depend on identifier stability.
  • All 13 grep guardrails still pass.
  • Stack-trace readability is verified at runtime.

If any of these checks fail, --minify-identifiers must not be enabled.

(d) Namespace Re-Export Coverage

When modifying re-export or export-tracking logic (e.g. exportLines, exportRanges, parseFileImports):

Test both forms of namespace re-export — they are distinct AST forms that require separate tracking:

  1. Regular namespace re-export: export * from './module'
  2. Aliased namespace re-export: export * as ns from './module'

The regex in src/tools/repo-graph/builder.ts (parseFileImports) handles both via the pattern export\s+\*(?:\s+as\s+\w+)?\s+from\s+['"]([^'"\0\t\r\n]+)['"]`. Both forms must be tested when modifying export tracking because:

  • They produce different importType values in the parsed output (namespace for both, but the aliased form carries a local binding name).
  • They require separate tracking in exportLines/exportRanges — the aliased form creates a local binding (ns) that must be recorded alongside the re-exported symbols.
  • Missing either form causes silent graph gaps in repo-graph callers/dead-exports analysis.

Test file: tests/unit/tools/repo-graph-reexports.test.ts covers both forms (see test case "4. export * as ns from './bar' — TypeScript namespace re-export → importType: namespace"). Run this test alongside any export-tracking change.

Show full SKILL.md (291 more words)Show less

Forbidden Shortcuts

  • Enabling --minify-identifiers without confirming all 13 grep guardrails pass and runtime stack-trace readability is verified.
  • Merging a minification/transform change without first running the consumer-constraint check (the 13 grep guardrails) against the smallest possible bundle.
  • Modifying re-export/export tracking without testing export * as ns from '...' (aliased namespace) alongside export * from '...' (regular namespace).
  • Assuming identifier preservation is "good enough" without running the full grep guardrail stack plus runtime stack-trace inspection.

Delegation Template

When delegating a task affected by this skill, include:

SKILLS: file:.opencode/skills/generated/bundle-safety/SKILL.md

Reviewer Checks

  • Verify the minification config in the build script matches --minify-whitespace --minify-syntax (no --minify-identifiers).
  • Verify tests/unit/build/full-auto-toolbefore-fail-closed.test.ts passes against the built dist/index.js (fail-closed hook guardrails green).
  • Verify tests/unit/turbo/lean/runtime-conformance.test.ts passes (Lean Turbo identifier-preservation guardrails green).
  • Verify tests/unit/build/throw-and-verify-located.test.ts passes (runtime stack-trace readability).
  • If re-export tracking was modified, verify tests/unit/tools/repo-graph-reexports.test.ts covers both export * from '...' and export * as ns from '...'.
  • Verify dist/index.js size is under the packaging gate (MAIN_BUNDLE_MAX_BYTES = 8.0 MiB in tests/smoke/packaging.test.ts).

Source Knowledge IDs

  • 5746c5c9-1330-4fbe-b62e-f564deb1ff77 — Before enabling any minification or transform flag, verify it doesn't break a hard consumer constraint by testing the smallest possible bundle against the exact constraint check. Required actions: test build output against consumer constraints before merging minification changes; build a minimal test bundle and run the consumer's validation first.
  • 5d99affe-bdd1-4945-8cd8-fcf37abb8c84 — Identifier-preserving minify (--minify-whitespace --minify-syntax) yields 22.3% on this bundle (1.28MB absolute) — substantial but below the optimistic 35-43% because identifier mangling is deliberately skipped to keep stack traces readable. The standard is identifier-preserving; full mangling is REJECTED because it breaks the 13 identifier-grepping guardrail assertions and stack-trace readability.
  • 9323a8f0-c07e-41c2-9857-11a24c55dca2 — When re-export handling is modified, verify aliased namespace re-exports (export * as ns from '...') are preserved alongside regular re-exports — they are distinct AST forms that require separate tracking in exportLines/exportRanges. Required: test namespace re-exports alongside regular re-exports when modifying export tracking.

© ZaxbyHub, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .opencode/skills/generated/bundle-safety of ZaxbyHub/opencode-swarm.

Open the folder on GitHubat commit a69d1a9

Compare with similar skills

Bundle Safety next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Bundle Safety compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Bundle Safety this skillZaxbyHub/opencode-swarm496—~2.3kAutomated safety check: PassMIT
TransformersK-Dense-AI/scientific-agent-skills48k1 repos~2.8kAutomated safety check: NotesApache-2.0
Python Type Safetywshobson/agents40k—~1.4kAutomated safety check: PassMIT
Javascript Minificationthedaviddias/Front-End-Checklist74k—~456Automated safety check: PassMIT
JSON Safetythedaviddias/Front-End-Checklist74k—~512Automated safety check: PassMIT
Triage Support Bundlenetdata/netdata81k—~2.7kAutomated safety check: PassGPL-3.0

Similar skills

  • Transformers

    K-Dense-AI/scientific-agent-skills

    Hugging Face Transformers for loading Hub models, running pipeline inference, text generation, and Trainer fine-tuning on NLP, vision, audio, and multimodal tasks.

    48k GitHub starsUsed in 1 repo~2.8k tokens
    AI & LLM EngineeringAuto-check: notes
  • Python Type Safety

    wshobson/agents

    Python type safety with type hints, generics, protocols, and strict type checking.

    40k GitHub stars~1.4k tokensUpdated 6 days ago
    DevelopmentAuto-check passed
  • Javascript Minification

    thedaviddias/Front-End-Checklist

    A skill your agent uses when reviewing scripts, client components, bundles, or runtime behavior related to Minify all JavaScript files.

    74k GitHub stars~456 tokensUpdated 4 days ago
    Auto-check passed
  • JSON Safety

    thedaviddias/Front-End-Checklist

    A skill your agent uses when reviewing scripts, client components, bundles, or runtime behavior related to Parse JSON safely with error handling.

    74k GitHub stars~512 tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • Triage Support Bundle

    netdata/netdata

    Investigate a Netdata support bundle offline - the archive netdata-support-bundle produces - to explain one host's alerts, missing data, collector failures, crashes, high CPU or memory, streaming…

    81k GitHub stars~2.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Hugging Face Transformers Usage

    davila7/claude-code-templates

    Loads pre-trained Hugging Face Transformers models for text, vision and audio tasks, runs inference with pipelines and fine-tunes on custom datasets.

    33k GitHub starsUsed in 11 repos~1.2k tokens
    AI & LLM EngineeringAuto-check passed

More from ZaxbyHub/opencode-swarm

All 91 skills in this repo
  • Codebase Review Swarm

    ZaxbyHub/opencode-swarm

    Runs an evidence-gated, quote-grounded audit of a codebase for security, QA, accessibility, performance and more, and writes a verified report without changing source files.

    496 GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Issue Tracer

    ZaxbyHub/opencode-swarm

    Drives a bug report from validation and root-cause tracing through a critic-reviewed plan, an approved minimal fix and a PR-ready closure, never merging without recorded human approval.

    496 GitHub stars~4.4k tokensUpdated today
    Auto-check passed
  • Commit and PR Publishing for Codex

    ZaxbyHub/opencode-swarm

    Codex adapter for opencode-swarm that governs commits, pushes, draft PRs, PR body updates and CI closeout, deferring to the repo's canonical commit-pr protocol.

    496 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Durable Session State

    ZaxbyHub/opencode-swarm

    Keeps plans, decisions, evidence and reviewer verdicts in small files so long multi-phase tasks survive context compaction and session resumes.

    496 GitHub stars~896 tokensUpdated today
    Auto-check passed
  • Swarm PR Feedback Closer

    ZaxbyHub/opencode-swarm

    Ingests existing pull request feedback such as review comments and CI failures, verifies each claim, fixes confirmed issues and reports closure status for every item.

    496 GitHub stars~14k tokensUpdated today
    Auto-check passed
  • Swarm PR Subscribe

    ZaxbyHub/opencode-swarm

    Monitor a pull request after creation and act autonomously on pushed PR activity.

    496 GitHub stars~2.2k tokensUpdated today
    Auto-check passed

Questions about Bundle Safety

What does Bundle Safety do?

Bundle transform safety — minification variant selection, consumer-constraint verification, identifier preservation, and namespace re-export coverage for build output. Bundle Safety is an agent skill from ZaxbyHub/opencode-swarm. Bundle transform safety — minification variant selection, consumer-constraint verification, identifier preservation, and namespace re-export coverage for build output.

How do I install Bundle Safety in Claude Code?

Run `npx skills add ZaxbyHub/opencode-swarm --skill bundle-safety -a claude-code`. Or copy the skill folder (.opencode/skills/generated/bundle-safety in ZaxbyHub/opencode-swarm) into .claude/skills/bundle-safety in your project. Claude Code loads it when a task matches its description.

How do I install Bundle Safety in Codex?

Run `npx skills add ZaxbyHub/opencode-swarm --skill bundle-safety -a codex`. Or copy the skill folder (.opencode/skills/generated/bundle-safety in ZaxbyHub/opencode-swarm) into .agents/skills/bundle-safety in your project. Codex loads it when a task matches its description.

Can I use Bundle Safety in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ZaxbyHub/opencode-swarm --skill bundle-safety -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bundle-safety, .gemini/skills/bundle-safety, .github/skills/bundle-safety and .opencode/skills/bundle-safety in your project.

What does Bundle Safety need to run?

SKILL.md names no scripts, command-line tools or credentials: Bundle Safety is instructions for the agent only.

Does Bundle Safety access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Bundle Safety safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Bundle Safety use?

Bundle Safety is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Bundle Safety use?

About 2.3k tokens (SKILL.md is roughly 9.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Bundle Safety?

Skills that share tags, products or a category with Bundle Safety: Transformers (K-Dense-AI/scientific-agent-skills, 48k stars), Python Type Safety (wshobson/agents, 40k stars), Javascript Minification (thedaviddias/Front-End-Checklist, 74k stars) and JSON Safety (thedaviddias/Front-End-Checklist, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Bundle Safety?

ZaxbyHub (a GitHub organization) maintains it in ZaxbyHub/opencode-swarm, which has 496 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on October 11, 2026.

Source: ZaxbyHub/opencode-swarm on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.