Install
$ agentstack add skill-prinova-pi-agent-codebase-workflows-codebase-recon ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Codebase Reconstruction — Structured API Only
Goal: reconstruct durable project understanding into canonical YAML artifacts for coding-agent ingestion.
Structured Artifact API Contract
Legacy prose artifacts are deprecated. Do not create, update, or rely on docs/agent/*.md, scoped prose docs, or generated human-readable Markdown views. Use structured YAML for canonical artifacts. Root AGENTS.md remains a harness interoperability file and may be generated/updated only by workflows that explicitly say so.
Resolved structured docs root:
Treat docs/agent/api as a logical layout rooted at a resolved structured docs root, not a fixed repo path.
Resolution rules:
- Resolve
workspace_rootwithgit rev-parse --show-toplevel 2>/dev/nullor fallback topwd. - Canonicalize
workspace_rootbefore fingerprinting when possible (realpath,pwd -P,Path(...).resolve(), or equivalent). safe-startalways creates and uses the initial repo-local root:/docs/agent/api.codebase-reconuses repo-local only when/docs/agent/apialready exists.- Otherwise use the global overlay root:
~/.pi/agent/workspaces//docs/agent/api. - Compute `
exactly from canonicalworkspace_root: strip one leading slash/backslash, replace every slash, backslash, and colon with-, then wrap with--`. This keeps the same workspace stable. - Example:
/data/data/com.termux/files/home/CodeProjects/pi-mono->--data-data-com.termux-files-home-CodeProjects-pi-mono--. - Do not create new repo-local structured docs in unadopted repos unless the user explicitly asks for repo-local adoption there.
Logical structured layout under the resolved docs root:
repo/
scopes.yaml
repo-inventory.yaml
project-intent.yaml
architecture.yaml
data-flow.yaml
data-model.yaml
invariants.yaml
dependency-rules.yaml
design-issues.yaml
risk-register.yaml
change-guide.yaml
testing-strategy.yaml
validation-baseline.yaml
contracts.yaml
adr.yaml
agent-operating-guide.yaml
scopes/
by-path//...
by-domain//...
Every structured artifact must conform to ../_shared/references/schemas/common.schema.json plus its artifact-specific schema. Do not inline, invent, or vary envelope fields.
Stable IDs required: scope:*, component:*, entity:*, invariant:*, risk:*, contract:*, flow:*, command:*, issue:*, adr:*, testplan:*.
Ownership rules:
scopes: scope routing, ownership, cross-scope discovery only.repo-inventory: file tree, commands index, entry points, external boundaries, configs.validation-baseline: command status, blockers, recommended validation order.project-intent: product goal, users, journeys, must-have features, non-goals, constraints, assumptions, open questions, success metrics, prioritized quality attributes, operating constraints, risk areas.architecture: components, architecture style, style rationale, alternatives/tradeoffs, side-effect boundaries, deployment/operating shape, reliability expectations, observability expectations, security assumptions, high-level flow refs.data-flow: typed flow graph/steps, trust boundaries, sensitive-data handling steps, inputs, outputs, error states, degradation/recovery notes.data-model: entities, IDs, schemas, relationships, lifecycles, serialized formats, retention/compliance notes.invariants: rules, forbidden states, enforcement locations, invariant-test refs.dependency-rules: layers, allowed/forbidden dependencies, violations, coupling hotspots.design-issues: structural drift, deferred decisions, ambiguity, ownership gaps.risk-register: failure modes, severity/confidence, affected refs, mitigations/recommended actions, suggested tests/fixes.contracts: cross-scope APIs, schemas, events, generated clients, DB/file/deployment/env/auth/telemetry contracts.testing-strategy: test topology, quality-attribute coverage, coverage gaps, risk-to-test priorities, operability checks.change-guide: workflow routing and checklists; references owner artifacts, duplicates no facts.adr: structured decision records with bounded prose fields, including alternatives and consequences for major design choices.agent-operating-guide: structured source for agent operating rules. RootAGENTS.mdmay mirror this in compact harness-readable Markdown when produced by safe-start or codebase-recon Pass 6.
Redundancy rule: define each fact in its owner artifact exactly once. Other artifacts reference IDs. Current truth rule: canonical YAML artifacts represent current state, not audit history. Remove resolved or superseded records from canonical owner artifacts by default. Keep them only when another live record still references them or an active migration requires temporary continuity. Use Git history, PRs, issues, or ADRs for audit/history. Prose rule: bounded prose allowed only in summary, notes, rationale, context, decision, recommended_action, and similar scalar fields. Scope rule: if focus is path-like, write under /scopes/by-path//; otherwise under /scopes/by-domain//. Always update /repo/scopes.yaml.
Runtime Schema Loading
When a workflow creates, updates, migrates, or validates structured artifacts, read ../_shared/references/artifact-api.md first. Then read only the shared skill package schemas needed for the artifacts being written:
../_shared/references/schemas/common.schema.json../_shared/references/schemas/.schema.json
Do not read all schemas. Do not use templates. Schemas are runtime API contracts; project docs outside the shared runtime refs are maintainer aids unless the user asks about this package itself.
Structured Artifact Write/Update Protocol
Use this protocol whenever creating or updating YAML artifacts.
1. Scope and owner resolution
- Resolve scope first from task/focus and
/repo/scopes.yamlwhen present. - Path focus uses longest prefix match; domain focus requires explicit domain/contract/task evidence.
- Select the single owner artifact for each fact using the ownership rules above.
- Never duplicate owner facts in router/checklist artifacts; reference stable IDs instead.
2. Read-before-write
- Read the existing target YAML if it exists.
- Read directly referenced owner artifacts needed to preserve refs and avoid duplication.
- If target YAML is absent, create it with the common envelope and artifact-specific top-level keys.
- Preserve unknown fields unless they conflict with this protocol; do not silently drop agent/user-added structured data.
3. Stable ID generation
- Reuse existing IDs whenever the semantic object is the same, even if name/path changed.
- New record IDs use deterministic slugs from owner scope + semantic name:
risk:,entity:,component:, etc. - Envelope
artifact_idvalues userepo:for repo-level artifacts and/for scoped artifacts, e.g.repo:architectureandscope:packages/ai/architecture. - Never append an artifact slug to a scope ID with a second colon;
scope:packages/ai:architectureis invalid. - If two objects slug-collide, append shortest stable discriminator from path/component/contract, not a random suffix.
- Never renumber IDs because order changed.
4. Upsert semantics
For each discovered fact/object:
- Match existing record by ID first.
- If no ID match, match by stable source-of-truth fields: path+symbol, contract source path, command string+cwd, entity name+owner scope, rule owner+kind.
- If matched, update only changed fields, append/refresh evidence, and preserve unrelated fields.
- If unmatched, insert new record in deterministic order by ID or explicit
orderfield. - If an existing observed record is resolved, superseded, or no longer supported, delete it from the canonical owner artifact by default.
- Keep a record with
status: staleordeprecatedonly when a live reference still depends on it or an active migration needs temporary continuity. Add evidence/unknown explaining why, and link replacement ID when known. - Delete accidental duplicates, malformed records, and unreferenced resolved/superseded records, and mention deletion in final response.
5. Evidence and confidence
- Every observed record needs at least one evidence ref with file/symbol/command/doc/diff observation.
- Planned records may use
evidence_mode: plannedand confidencelowormedium. - Mixed records must separate observed fields from planned/assumed fields via evidence refs or
unknowns. - Do not upgrade
status: currentor confidencehighwithout source or command evidence.
6. Reference integrity
Before writing final artifacts:
- Check every
*_ref,*_refs, anddepends_onID points to a record in the same artifact set or is explicitly listed as external/unknown. - Prefer adding missing owner records as compact stubs over leaving dangling refs.
- For cross-scope refs, ensure
scopes.yamlandcontracts.yamlidentify owner/consumer relationship. - If ownership is ambiguous, create/update
design-issues.yamlwithkind: ownership_gapand reference it.
7. Status transitions
Allowed transitions:
planned -> partial -> currentcurrent -> stale -> currentcurrent|stale|partial -> deprecated
Rules:
currentrequires sufficient observed evidence for the represented scope.partialmeans useful but incomplete evidence.stalemeans contradicted by newer source evidence or missing source path. Use it as a temporary migration/quarantine state, not a permanent archive state.deprecatedmeans superseded; includereplacement_refwhen known. Use it only when a live reference still needs continuity during migration; otherwise remove the record from the canonical artifact.
8. Deterministic formatting
- Use YAML with two-space indentation.
- Use stable top-level key order: envelope keys first, artifact-specific keys next.
- Sort unordered arrays by
id; keep ordered flow/checklist arrays byorder. - Use
null,[], or{}consistently rather than omitting required envelope fields. - Keep prose scalar fields concise; no long narrative blocks.
9. Validation before completion
Perform best-effort validation after writing:
- Re-read changed YAML for parse/syntax sanity when practical.
- Validate against the shared schemas by inspection/re-read: envelope keys, artifact-specific top-level keys, required arrays/items, stable ID prefixes, and obvious dangling refs.
- Verify no legacy Markdown artifacts were created or updated by the workflow, except root
AGENTS.mdwhen explicitly produced for harness interoperability. - Report changed YAML files, validation performed, unresolved unknowns, and any records intentionally retained or pruned as part of compaction.
Core Rules
- Do not edit production code.
- No Markdown artifacts except root
AGENTS.mdfor harness interoperability in Pass 6. - Each pass writes/updates only its owner artifacts.
- Later passes read prior YAML artifacts instead of re-reading whole repo.
- Evidence is mandatory for observed claims.
- Unknowns are explicit records, not vague prose.
- When newer schemas require fields that are not inferable from the codebase, still create those fields with evidence-backed low-confidence placeholders, empty arrays, null-capable subfields, and explicit unknowns rather than omitting them.
- Reconstruct decision-driving quality attributes, trust boundaries, reliability/observability/security expectations, and tradeoffs when the repo provides enough evidence; otherwise record the ambiguity explicitly.
- Use stable IDs and cross-references to mirror codebase ownership and relationships.
Passes
Users may invoke this skill directly for any pass, or use the matching prompt template as a pass shortcut.
- Inventory (
/recon-01-inventory): writerepo-inventory.yaml,validation-baseline.yaml, and initialproject-intent.yaml; updatescopes.yamlfor focus. Infer product goal, users, journeys, quality attributes, operating constraints, and risk areas from repo evidence when possible; otherwise record explicit unknowns. - Architecture (
/recon-02-architecture): writearchitecture.yamlwith components, style, style rationale, alternatives/tradeoffs when inferable, boundaries, execution flow refs, and reliability/observability/security expectations. - Data/invariants (
/recon-03-data-invariants): writedata-model.yamlandinvariants.yaml; surface trust boundaries, sensitive data, retention/compliance implications, and correctness/safety rules. - Dependencies/drift (
/recon-04-dependency-rules): writedependency-rules.yamlanddesign-issues.yaml; record structural gaps where quality/security/operability evidence is weak. - Risks (
/recon-05-risk-register): writerisk-register.yamlwith affected refs, recommended actions, and quality/security/reliability risks. - Agent operating guide (
/recon-06-agents): writeagent-operating-guide.yamland rootAGENTS.md. - Change guide (
/recon-07-change-guide): writechange-guide.yaml. - Consolidation (
/recon-08-consolidate): reconcile YAML artifacts, resolve contradictions with evidence, preserve owner-only facts, and backfill required schema fields when older artifacts are incomplete. - ADR (
/recon-09-adr): writeadr.yamlwith structured ADR records, alternatives, and consequences where architectural decisions are inferable from history/docs/code. - Risk-to-tests (
/recon-10-risk-tests): write/updatetesting-strategy.yamlwith quality-attribute coverage, risk-to-test priorities, and operability checks.
All-in-one shortcut: /recon-all runs the pass sequence until the requested focus is complete or the repo size requires stopping at a pass boundary.
Artifact Shape Source
For each pass, use the shared runtime schemas as the only shape contract: ../_shared/references/artifact-api.md, ../_shared/references/schemas/common.schema.json, and the matching artifact schema(s). Do not rely on prose key lists.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: PriNova
- Source: PriNova/pi-agent-codebase-workflows
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.