Install
$ agentstack add skill-iflytek-skillhub-code-conventions ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Code Conventions Skill
Java / Backend Conventions
User Identity Type
User identity is always String throughout the codebase. This covers:
- Authentication and authorization
- API parameters and responses
- Permission checks
- Audit logs
- Resource owner, creator, reviewer, actor, submittedBy fields
Never introduce int, long, or bigint as user identifiers. The platform needs to support external SSO/OIDC/SCIM identity sources whose UIDs are typically stable strings.
Exception Handling
- Use
LocalizedDomainExceptionfor user-facing error messages (supports i18n) - Use
DomainBadRequestExceptionfor invalid client input - Use
DomainNotFoundExceptionfor missing resources - Use
DomainForbiddenExceptionfor authorization failures - Exception classes live in
skillhub-domain/shared/exception/
Domain Services
- Return domain objects, not DTOs
- Contain business rules and state transitions
- Use domain events for cross-cutting side effects (publishing, notifications)
- Located in
domain/{submodule}/service/
Controllers
- Transport only: extract auth context, bind request params, wrap responses
- No business logic in controllers
- Located in
com.iflytek.skillhub.controller/
Query Repositories
- Handle read-model joins and presentation projection
- Return DTOs or presentation models
- Located in
com.iflytek.skillhub.repository/ - Named like
*QueryRepository(e.g.,GovernanceQueryRepository,MySkillQueryRepository)
App Services
- Workflow orchestration: coordinate domain services and query repositories
- Should express "what this endpoint does", not "how it assembles DTOs"
- Located in
com.iflytek.skillhub.service/
Logging
- Use SLF4J with structured logging
- Use MDC for request tracing
- Log at appropriate levels: INFO for business events, DEBUG for troubleshooting, ERROR for failures
TypeScript / Frontend Conventions
Type Safety
- Strict TypeScript mode. No
anytypes. - Use generated OpenAPI types from
web/src/api/generated/schema.d.tsfor all API interactions. - Additional types in
web/src/types/
Data Fetching
- Always use TanStack Query (
@tanstack/react-query) for server state - Never use
useEffectfor data fetching - Use
openapi-fetchclient for type-safe API calls
Component Composition
- Radix UI primitives:
@radix-ui/react-dropdown-menu,@radix-ui/react-select - class-variance-authority (cva) for component variants
- clsx + tailwind-merge for class merging
cn()utility:web/src/shared/lib/utils.ts- shadcn/ui is NOT used as a library
State Management
- TanStack Query for server state (API data, caching, invalidation)
- Zustand for local/UI state (theme, sidebar, modals, form state)
Feature-Sliced Design
| Layer | Path | Purpose | |-------|------|---------| | Pages | web/src/pages/ | Route-level page components | | Features | web/src/features/ | Self-contained business features | | Entities | web/src/entities/ | Domain entity display logic | | Shared | web/src/shared/ | Reusable UI components, hooks, utilities |
Place code at the lowest appropriate layer. Do not put page-level logic in shared.
Styling
- Tailwind CSS for all styling
- Follow existing component patterns
- Use
cn()for conditional class merging
Internationalization
- Use i18next + react-i18next
- All user-facing text must be translatable
- Translation keys in
web/src/i18n/
Testing Philosophy
Backend
- JUnit 5 + Mockito + AssertJ
- Use Spring Boot test slices where possible (
@WebMvcTest,@DataJpaTest) - Test behaviors, not implementations
- Use
make test-backend-app(includes-amfor dependent modules) - Never run
./mvnw -pl skillhub-app clean testdirectly — stale Maven cache causes misleading errors
Frontend
- Vitest for unit tests
- Playwright for E2E tests
- Test component behavior and user interactions
Common Pitfalls
- Maven multi-module: Always use
-amflag or Makefile targets to include dependent modules - OpenAPI types: Must regenerate and commit after API contract changes
- String identity: Never use numeric types for user identifiers
- Controller business logic: Move to domain service or app service
- Complex read-models in app service: Extract to query repository
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: iflytek
- Source: iflytek/skillhub
- License: Apache-2.0
- Homepage: https://skill.xfyun.cn
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.