Install
$ agentstack add skill-nklisch-skilltap-patterns ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ● Shell / process execution Used
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Project Patterns Reference
This skill contains documented code patterns for this project — recurring structures, shared abstractions, and architectural approaches that keep the codebase consistent.
Each pattern file has a rationale explaining why the pattern exists, concrete code examples with file references, and guidance on when to use it (and when not to).
How to Use
When writing new code or reviewing changes, check if an established pattern applies. If it does, follow it. If you have a good reason to deviate, note why.
The dense index at .claude/rules/patterns.md loads automatically and provides one-line summaries with pointers to full pattern files. Read the individual pattern file when you need full details.
Available Patterns
Core Architecture
- result-type.md —
Resultdiscriminated union withok()/err()constructors for railway-oriented error handling across all core functions - error-hierarchy.md —
SkilltapErrorbase class with typed subclasses (UserError,GitError,ScanError,NetworkError) and optionalhintfield - zod-boundary.md — Zod schema as single source of truth for types + validation;
safeParse+z.prettifyErrorat every data boundary;.prefault({})for nested defaults;parseWithResult()helper - config-io.md — Config/state load-save algorithm: ensureDirs → exists check → read → parse → Zod validate → Result; state.json uses
loadState/saveState - json-state-io.md —
loadJsonStateandsaveJsonStategeneric helpers; all state modules delegate to these, no ad-hoc JSON I/O
Adapter Patterns
- source-adapter.md —
SourceAdapterstrategy pattern: plain object literals withcanHandle()+resolve(), iterated by a priority-ordered resolver - agent-adapter-strategy.md —
AgentAdapterinterface withdetect()/invoke(), factory functions for CLI/custom/Ollama adapters, three-priority resolution viaresolveAgent() - adapter-driven-branching.md —
resolved.adapterfromresolveSource()gates source-type-specific logic (npm vs git vs local) throughout install, update, and trust flows
Command Patterns
- output-interface.md —
setupOutput(args)→Outputhandle; 3 modes (tty/plain/json); all command output goes throughout.*methods; replaces old agent-mode-branching split - callback-driven-options.md — Core functions accept typed option objects with async callbacks for decision points; omitting callback = auto-proceed;
out?: Outputfor progress - policy-composition.md —
composePolicy(config, flags)→EffectivePolicy;composePolicyForSourceadds trust overlay;loadPolicyOrExit()is CLI-layer entry point - scope-base.md —
scopeBase(scope, projectRoot?)pure helper — single-source scope-to-base-dir; use derived helpers (skillInstallDir, etc.) for full paths
State Management
- apply-state-change.md —
applySkillStateChange({scope, projectRoot, mutate, manifestSync?})atomic load→mutate→save for skills[]; fires manifest sync hooks on diff
Git & Security
- bun-shell-git.md — All git operations via
wrapGit()wrapper + Bun's$template tag with.quiet();extractStderr()for consistent error extraction - security-detector-composition.md — 7 independent detector functions composed in a for-loop inside
scanStatic();StaticWarningextendsPatternMatchwith afilefield - install-result-with-warnings.md —
installSkill()returnsInstallResult { records, warnings, semanticWarnings, updates, pluginRecord? }; unifiedonWarnings(warnings, kind, name)callback
Testing
- test-fixtures.md — Fixture repo factories:
createX()returns{ path, cleanup }; copies static fixtures, initializes git repo, commits; alwaysdot:truein Bun.Glob.scan - test-result-assertions.md — Result assertion pattern:
expect(result.ok).toBe(true)+ discriminated union guard;VALID_*constants with spread for schema test variants - test-env-isolation.md —
createTestEnv()from@skilltap/test-utilsreturns{ homeDir, configDir, cleanup() }; replaces per-test manual env save/restore - cli-subprocess-testing.md — Use
runSkilltap(args, homeDir, configDir)+cliCmd()from@skilltap/test-utils; routes to compiled binary whenSKILLTAP_TEST_BINset
Trust & Source Handling
- injectable-dependencies.md — Core functions with external I/O accept
_dep = realImploptional params; tests inject mocks as 2nd/3rd args; privatetype Fn = typeof realFnaliases enforce signature compatibility - graceful-fallback-chain.md — Optional verifiers return
T | nullnotResult; caller cascades through priority tiers (provenance → publisher → curated → unverified); outertry/catchguarantees a valid result always - single-source-definitions.md — One authoritative constant per enumerable concept; agent metadata in
symlink.ts; config enum arrays inschemas/config.ts
Deprecated / Removed
- agent-mode-branching.md — ⚠️ REMOVED.
policy.agentModeandrunAgentMode()/runInteractiveMode()no longer exist. See output-interface.md.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: nklisch
- Source: nklisch/skilltap
- License: MIT
- Homepage: https://skilltap.dev/
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.