Install
$ agentstack add skill-michelkerkmeester-skilled-harness-spec-driven-agent-loops-sk-code-opencode ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
opencode Surface — System-Code Evidence
Domain evidence and shared workflow doctrine for OpenCode system code (the .opencode/ tree: skills, agents, commands, plugins, MCP servers, config, changelogs, and runtime bridge wiring). This surface owns the implement -> debug -> verify phases through the workflow references below, then slices evidence by the detected language so a TypeScript task never pulls the Python/shell/config guides.
Detection is two-step. First, the surface trigger is work under .opencode/ (including SKILL.md, descriptors, commands, agents, plugins, MCP servers, assets, scripts, and changelogs). Second, once the OpenCode surface is selected, file extensions and local markers select the language trio: .cjs/.mjs/.js -> JavaScript, .ts/.tsx/.mts/.d.ts -> TypeScript, .py plus argparse -> Python, .sh/.bash -> shell, .rs -> Rust, .json/.jsonc/.yaml/.yml plus graph-metadata or spec-folder -> config. For Rust, when no .rs file is present, local Cargo.toml/Cargo.lock markers select it after the OpenCode surface is established; napi-rs and wasm-bindgen vocabulary are additional intent signals, not cross-project surface detectors.
1. WHEN THE HUB BUNDLES THIS
- The task touches
.opencode/system code — a skill, agent, command, plugin, MCP server, or descriptor/config. - The active workflow phase needs a language standard, a language-agnostic organization pattern, a hook contract, an alignment-verification procedure, or an authoring checklist.
- This surface owns edits, tests, and verification through the workflow references; hand off formal findings-first review to
code-reviewand author-side quality gates tocode-quality.
2. REFERENCE MAP
Language standards — after .opencode/ selects this surface, load the exact split resources for the detected language:
- TypeScript —
references/typescript/style-guide/overview-strict-and-naming.md,references/typescript/style-guide/formatting-imports-and-coexistence.md,references/typescript/quality-standards/overview-and-type-system.md,references/typescript/quality-standards/tsdoc-errors-and-async.md,references/typescript/quality-standards/tsconfig-and-modules.md,references/typescript/quick-reference/template-naming-and-types.md,references/typescript/quick-reference/imports-errors-and-tsconfig.md - Python —
references/python/style-guide.md,references/python/quality-standards.md,references/python/quick-reference.md - Shell —
references/shell/style-guide/overview-structure-and-naming.md,references/shell/style-guide/variables-functions-and-output.md,references/shell/quality-standards/overview-and-priority-blockers.md,references/shell/quality-standards/validation-security-and-shellcheck.md,references/shell/quick-reference/template-variables-and-loops.md,references/shell/quick-reference/functions-strings-and-checklist.md - Rust —
references/rust/style-guide/overview-and-file-header.md,references/rust/style-guide/toolchain-and-project-structure.md,references/rust/style-guide/naming-conventions.md,references/rust/style-guide/formatting-and-imports.md,references/rust/style-guide/commenting-and-rustdoc.md,references/rust/style-guide/interop-model.md,references/rust/style-guide/interop-errors-and-parity.md,references/rust/quality-standards/overview-and-data-ownership.md,references/rust/quality-standards/modeling-collections-and-api.md,references/rust/quality-standards/docs-errors-and-async.md,references/rust/quality-standards/build-and-organization.md,references/rust/quality-standards/determinism-and-parity.md,references/rust/quick-reference/overview-and-boundary-template.md,references/rust/quick-reference/naming-ordering-and-signatures.md,references/rust/quick-reference/collections-imports-and-errors.md,references/rust/quick-reference/rustdoc-and-cargo.md,references/rust/quick-reference/determinism-parity-and-related.md - Config (JSON/JSONC/YAML descriptors and route assets) —
references/config/style-guide.md,references/config/quality-standards.md,references/config/quick-reference.md,assets/checklists/config-checklist.md - JavaScript (CommonJS/ESM plugins) —
references/javascript/style-guide.md,references/javascript/quality-standards/overview-modules-and-docs.md,references/javascript/quality-standards/security-testing-and-exemptions.md,references/javascript/quick-reference.md
Language-agnostic shared tier (references/shared/, always kept within OpenCode regardless of language):
references/shared/universal-patterns/naming-and-commenting.md,references/shared/universal-patterns/organization-security-and-examples.md,references/shared/code-organization/overview-and-module-organization.md,references/shared/code-organization/imports-and-exports.md,references/shared/code-organization/directory-and-test-conventions.mdhooks.md— runtime hook entrypoints, checked-in Claude wiring, OpenCode plugin-bridge delivery, and wrapper reachability; defer to that file for current hook infrastructure instead of duplicating it herealignment-verification-automation.md— the alignment-drift verifier
Authoring and validation assets: assets/checklists/agent-authoring.md, assets/checklists/command-authoring.md, assets/checklists/javascript-checklist.md, assets/checklists/mcp-server-authoring.md, assets/checklists/python-checklist.md, assets/checklists/rust-checklist/overview-and-p0-parity.md, assets/checklists/rust-checklist/p0-safety-and-boundary-discipline.md, assets/checklists/rust-checklist/p1-required.md, assets/checklists/rust-checklist/p2-evidence-validation-and-resources.md, assets/checklists/shell-checklist.md, assets/checklists/skill-authoring.md, assets/checklists/typescript-checklist.md, assets/checklists/universal-checklist.md, assets/scripts/README.md, references/shared/alignment-verification-automation.md, references/shared/hooks.md
Workflow: the implement -> debug -> verify phases use the split shared, language, hook, and alignment resources above; no root-level workflow-*.md trio is assumed.
2b. SMART ROUTING (machine-readable)
This block is the deterministic projection of code-opencode's own reference/asset routing, consumed by the skill-benchmark router-replay; keep it in sync with the parent hub union.
# code-opencode owns its intent -> reference/asset routing. Paths are relative to
# this skill root. The parent sk-code hub RESOURCE_MAP is the union of this map
# (re-prefixed with sk-code-opencode/) and the sibling code-webflow map plus the
# parent-owned universal/shared tier; the sk-code-router-sync.vitest.ts suite
# (under system-deep-loop's skill-benchmark tests) is the guard that enforces
# that equality. verify_alignment_drift.py is markdown-blind by default and does
# not check this map unless invoked with --check-router (dead-route existence
# only), so it is not the equality authority.
DEFAULT_RESOURCE = [
"references/shared/universal-patterns/naming-and-commenting.md",
"references/shared/universal-patterns/organization-security-and-examples.md",
"references/shared/code-organization/overview-and-module-organization.md",
"references/shared/code-organization/imports-and-exports.md",
"references/shared/code-organization/directory-and-test-conventions.md",
]
INTENT_SIGNALS = {
"IMPLEMENTATION": {"weight": 1, "keywords": ["implement", "build", "create", "feature", "component", "module", "authoring"]},
"CODE_QUALITY": {"weight": 1, "keywords": ["lint", "format", "quality gate", "naming", "standards", "code smell"]},
"VERIFICATION": {"weight": 1, "keywords": ["verify", "passing", "type-check", "alignment drift", "completion claim"]},
"HOOKS": {"weight": 1, "keywords": ["session-prime", "user-prompt-submit", "pre-tool-use", "post-tool-use"]},
"CONFIG": {"weight": 1, "keywords": ["jsonc", ".json", ".jsonc", "descriptor", "config schema"]},
"JAVASCRIPT": {"weight": 1, "keywords": ["javascript", ".js", "commonjs", ".cjs", ".mjs"]},
"TYPESCRIPT": {"weight": 1, "keywords": ["typescript", ".ts", ".tsx"]},
"PYTHON": {"weight": 1, "keywords": ["python", ".py", "docstring"]},
"SHELL": {"weight": 1, "keywords": ["shell script", "bash", ".sh"]},
"RUST": {"weight": 1, "keywords": ["rust", ".rs", "cargo.toml", "cargo.lock", "napi-rs", "napi_rs", "#[napi]", "wasm-bindgen", "wasm_bindgen", "#[wasm_bindgen]", "wasi", "cdylib"]},
}
RESOURCE_MAP = {
"IMPLEMENTATION": [
"references/shared/universal-patterns/naming-and-commenting.md",
"references/shared/universal-patterns/organization-security-and-examples.md",
"references/shared/code-organization/overview-and-module-organization.md",
"references/shared/code-organization/imports-and-exports.md",
"references/shared/code-organization/directory-and-test-conventions.md",
"assets/checklists/agent-authoring.md",
"assets/checklists/command-authoring.md",
"assets/checklists/skill-authoring.md",
"assets/checklists/mcp-server-authoring.md",
],
"CODE_QUALITY": [
"assets/checklists/universal-checklist.md",
"assets/checklists/javascript-checklist.md",
"assets/checklists/typescript-checklist.md",
"assets/checklists/python-checklist.md",
"assets/checklists/shell-checklist.md",
"assets/checklists/rust-checklist/overview-and-p0-parity.md",
"assets/checklists/rust-checklist/p0-safety-and-boundary-discipline.md",
"assets/checklists/rust-checklist/p1-required.md",
"assets/checklists/rust-checklist/p2-evidence-validation-and-resources.md",
],
"VERIFICATION": [
"references/shared/alignment-verification-automation.md",
"assets/scripts/README.md",
],
"HOOKS": [
"references/shared/hooks.md",
],
"CONFIG": [
"references/config/style-guide.md",
"references/config/quality-standards.md",
"references/config/quick-reference.md",
"assets/checklists/config-checklist.md",
],
"JAVASCRIPT": [
"references/javascript/style-guide.md",
"references/javascript/quality-standards/overview-modules-and-docs.md",
"references/javascript/quality-standards/security-testing-and-exemptions.md",
"references/javascript/quick-reference.md",
],
"TYPESCRIPT": [
"references/typescript/style-guide/overview-strict-and-naming.md",
"references/typescript/style-guide/formatting-imports-and-coexistence.md",
"references/typescript/quality-standards/overview-and-type-system.md",
"references/typescript/quality-standards/tsdoc-errors-and-async.md",
"references/typescript/quality-standards/tsconfig-and-modules.md",
"references/typescript/quick-reference/template-naming-and-types.md",
"references/typescript/quick-reference/imports-errors-and-tsconfig.md",
],
"PYTHON": [
"references/python/style-guide.md",
"references/python/quality-standards.md",
"references/python/quick-reference.md",
],
"SHELL": [
"references/shell/style-guide/overview-structure-and-naming.md",
"references/shell/style-guide/variables-functions-and-output.md",
"references/shell/quality-standards/overview-and-priority-blockers.md",
"references/shell/quality-standards/validation-security-and-shellcheck.md",
"references/shell/quick-reference/template-variables-and-loops.md",
"references/shell/quick-reference/functions-strings-and-checklist.md",
],
"RUST": [
"references/rust/style-guide/overview-and-file-header.md",
"references/rust/style-guide/toolchain-and-project-structure.md",
"references/rust/style-guide/naming-conventions.md",
"references/rust/style-guide/formatting-and-imports.md",
"references/rust/style-guide/commenting-and-rustdoc.md",
"references/rust/style-guide/interop-model.md",
"references/rust/style-guide/interop-errors-and-parity.md",
"references/rust/quality-standards/overview-and-data-ownership.md",
"references/rust/quality-standards/modeling-collections-and-api.md",
"references/rust/quality-standards/docs-errors-and-async.md",
"references/rust/quality-standards/build-and-organization.md",
"references/rust/quality-standards/determinism-and-parity.md",
"references/rust/quick-reference/overview-and-boundary-template.md",
"references/rust/quick-reference/naming-ordering-and-signatures.md",
"references/rust/quick-reference/collections-imports-and-errors.md",
"references/rust/quick-reference/rustdoc-and-cargo.md",
"references/rust/quick-reference/determinism-parity-and-related.md",
],
}
3. SURFACE STANDARDS (the non-negotiables)
- Plugins never write to the TUI. OpenCode plugins must not print to the process stdout/stderr (no overlay on the chat input); user/agent-visible output goes through system-context injection, tools, or append-only log files; DEBUG-gated stderr is allowed only behind an env flag. See
references/javascript/quality-standards/overview-modules-and-docs.mdand the plugin exemption tier. - Descriptors are load-bearing.
graph-metadata.json/description.jsonshape drives discovery; validate JSON/JSONC againstreferences/config/quality-standards.md. - Alignment drift is a verification gate. System-code changes re-run all three sk-code drift guards before any completion claim —
assets/scripts/verify_alignment_drift.py(language integrity; add--check-routerfor dead RESOURCEMAP routes),assets/scripts/verify_stack_folders.py(language reference folders resolve), and thesk-code-router-sync.vitest.tssuite (machine router vs filesystem/prose, plus the compiled-destination ↔ leaf-manifest ↔ RESOURCEMAP bijection) — through the single entry pointscripts/run-all-drift-guards.sh. Seereferences/shared/alignment-verification-automation.md. Interim: the wrapper now scans the whole repository and reports a known pre-existing backlog, so while that backlog is being worked off a completion claim reports its packet-scoped delta against the frozen baseline in the conformance program's directory manifest rather than requiring wrapper rc 0. - Rust preserves the TypeScript contract. Rust napi-rs, WASM/WASI, and sidecar modules are compatibility implementations, not independent behavior authorities. JS-visible bytes, six-decimal numeric behavior, comparator tie-breaks, deterministic IDs, collection order, DTOs, and error shapes must remain identical to the TypeScript oracle.
- Touched-language set, not one-per-task. Most
.opencode/tasks touch a single language — keep that slice tight and lean on the shared tier for cross-language rules. An interop task that spans a language pair (a napi-rs / WASM / sidecar Rust module held to its TypeScript oracle) legitimately touches both languages: the router slices to the set the task actually touches and loads both trios plus the shared tier, because you cannot hold Rust byte-identical to TypeScript without seeing both standards.
4. ASSETS AND OTHER SURFACE AREAS — ON-DEMAND
Component authoring (assets/checklists/): skill-authoring.md, agent-authoring.md, command-authoring.md, mcp-server-authoring.md
Language quality gates (assets/checklists/): universal-checklist.md, typescript-checklist.md, python-checklist.md, shell-checklist.md, javascript-checklist.md, rust-checklist/ (split into topic parts), config-checklist.md
Verifier assets (assets/scripts/): alignment-drift and stack-folder verifier scripts used by this surface. scripts/run-all-drift-guards.sh is the single entry point that runs both of them
…
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: MichelKerkmeester
- Source: MichelKerkmeester/skilled-harness_spec-driven-agent-loops
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.