Install
$ agentstack add skill-minwoo19930301-decant-decant-build ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Decant Build
Apply the approved change while keeping evidence and rollback obvious.
Before editing
- Reconfirm the requested outcome, allowed mutations, and acceptance checks.
- Inspect the worktree and preserve unrelated user changes.
- Identify the smallest vertical slice that demonstrates progress.
- Add or update a failing test first when the behavior is testable and the test adds useful protection.
Do not force test-first mechanics for generated artifacts, trivial text edits, or behavior that is better verified by a deterministic validator. Record why when no test is appropriate.
Hard-deadline progress gate
Use this gate for explicitly time-boxed, low-risk work. For a budget of 15 minutes or less, treat it as a fast lane and recommend medium-or-lower host effort before starting. This skill cannot change the host model or effort and cannot enforce a wall-clock timer.
- Produce a runnable primary implementation vertical slice by 30% of the budget, capped at five minutes.
- Smoke-check that slice, then run the core tests.
- Expand behavior and documentation only after the slice works.
- Stop expansion at the final 20% and spend the remainder on verification and an honest handoff.
Test-only, plan-only, and documentation-only output does not pass the first progress gate. Under a hard deadline, the runnable-slice sequence takes precedence over the general test-first preference above. Never apply this shortcut to security-sensitive, deployment, destructive, irreversible, or otherwise high-risk work, and do not weaken any applicable safety gate.
Implementation loop
- Make one coherent change.
- Run the narrowest relevant check.
- Inspect the diff and unintended file changes.
- Continue only when the slice is understood.
- Run the broader regression set in proportion to risk.
Use structured argv and safe APIs rather than shell interpolation for untrusted values. Keep optional adapters and surfaces outside the core when possible.
Completion evidence
Report:
- files changed and why;
- tests or validators run with actual exit status;
- user-visible result;
- remaining risks or unsupported paths;
- rollback or revert point.
Do not claim completion from code inspection alone when executable verification is available. Do not commit, push, publish, tag, deploy, or send external messages unless the user authorized that action.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: minwoo19930301
- Source: minwoo19930301/decant
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.