Install
$ agentstack add skill-qarium-goga-goga-accept-manifest-review ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
goga-accept-manifest-review
Identity
The Agent verifies each Cell's CODEMANIFEST against its implementation during acceptance: code vs requirements, requirements vs code, manifest accuracy.
Core Principle
The Agent compares CODEMANIFEST with the actual implementation, updates the manifest as needed, and records any unresolvable discrepancies.
User Interaction Rule
Always provide response options. When addressing the User, always offer 2–4 concrete choices.
Algorithm
Step 1. Load Context
- Load the Acceptance Scope Report.
- Invoke skill
goga-lang-dispto retrieve language conventions for the target language. - Load the DSL specification:
- Invoke skill
goga-cellto understand CODEMANIFEST DSL syntax, structural rules, and semantics. - Invoke skill
goga-cookbookto understand principles for working with Cell and CODEMANIFEST files.
- Invoke skill
goga-codemanifest-baseto retrieve baseline Usages and Annotations.
Step 2. Pre-flight Check
- Run the linter:
goga lint. - Record all errors as CRITICAL. Resolve them before proceeding.
Step 3. Per-Cell Review
Process each Cell listed in the Acceptance Scope Report:
Sub-step 1. Load Data
- Read the Cell's CODEMANIFEST.
- Parse all entities, methods, properties, imports, usages, annotations, re-exports, and locations per the goga-cell and goga-cookbook skill definitions.
- Enumerate all source files (exclude
.usages/, build artifacts, and test files). - Read every source file at its declared
location. - Verify the Facade file exists.
Sub-step 2. Code Analysis
Question: Does the code satisfy the CODEMANIFEST requirements, baseline practices, and language conventions?
- Run the contract comparison:
goga contract.
- For each Entity, compare:
- Constructor Signature: CODEMANIFEST vs implementation.
- Methods: CODEMANIFEST vs implementation — per method.
- Properties: CODEMANIFEST vs implementation — per property.
- For each Routine:
- Signature match: contract result — CODEMANIFEST vs implementation.
- Facade export: is the Routine exported through the Facade.
- Check Facade exposure — every Entity must be present in the Facade.
- Check code compliance with baseline Usages and Annotations from skill
goga-codemanifest-base. - Check code compliance with language conventions from skill
goga-lang-disp.
Additional checks:
- Location: the file at
/must exist.
Sub-step 3. CODEMANIFEST Completeness Analysis
Question: Is all meaningful code reflected in the CODEMANIFEST?
For every code element absent from CODEMANIFEST, classify criticality:
HIGH — must be added:
- Undeclared public Entity (class with state or behavior).
- Undeclared public Routine (transformer function, factory, validator).
- Re-exported types not declared via Embedding.
- Unreported Mutations (
Object::Target).
MEDIUM — must be added:
- Missing methods or properties on a declared Entity.
- Signature inaccuracies (parameters, return values, semantic labels).
- Used Imports not declared.
LOW — no action required:
- Private members, internal implementation details.
- Helper functions not included in the Facade.
- Stylistic annotation improvements.
Annotation quality checks:
- Each Annotation starts with a clear purpose statement.
- Every parameter is documented as
parameter_name: description. - Non-trivial logic includes an
Algorithm:section. - Constraints are described under
Requirements:. - No TBD, TODO, or vague wording.
Sub-step 4. Algorithm Comparison
For each Entity and Routine, compare Annotations against the implementation along these axes:
- Behavior: does the code perform what the Annotation describes.
- Algorithm: steps, order, conditions, branching.
- Operational Flow: inputs, outputs, side effects.
- Guarantees: post-conditions, invariants, constraints.
- Engineering Practices: error handling, logging, validation.
For each discrepancy:
- CODEMANIFEST inaccurate, code correct → update CODEMANIFEST.
- Code incorrect, CODEMANIFEST accurate → create a Task.
- Both partially inaccurate → propose edits for both sides, request User confirmation.
Step 4. Baseline Usages and Annotations Audit
For each Cell, verify against goga-codemanifest-base:
- Retrieve baseline Usages from
goga-codemanifest-base. - Verify every baseline Usage appears in the CODEMANIFEST
Usagesdirective. - Retrieve baseline Annotations from
goga-codemanifest-base. - Verify every baseline Annotation appears in the CODEMANIFEST
Annotationsdirective. - Auto-add any missing baseline Usages or Annotations.
Step 5. Classify Findings
For each finding:
- Assign a severity:
- CRITICAL: Facade violation, missing implementation, CODEMANIFEST syntax error, implementation contradicts a correct manifest.
- WARNING: inaccurate description, missing parameter in Annotation, stale manifest algorithm.
- INFO: writing-quality improvement recommendation.
- Propose a concrete action:
- Analysis 1 (code fails requirements) → create a Task describing the discrepancy.
- Analysis 2 (requirements diverge from code) → edit CODEMANIFEST.
- Algorithm mismatch → update manifest if implementation is correct, or create a Task.
- Request User confirmation for all CRITICAL and WARNING findings.
Step 6. Execute Approved Actions
For each approved action:
- Code fails requirements → create a Task with discrepancy details.
- Requirements diverge from code → apply CODEMANIFEST edits.
- Manifest is stale → update CODEMANIFEST and record the reason.
- Implementation is incorrect → record CRITICAL, create a Task.
Step 7. Validate Updates
- Run:
goga lint. - Fix any syntax errors.
- Repeat until the linter passes with zero errors.
STOP if:
- CRITICAL violations exist in any Cell.
- Implementation contradicts manifest and manifest is correct.
- CODEMANIFEST linter errors are present.
- Facade exposure violations are detected.
Output Format
Fill in every section. Empty sections are prohibited.
# Manifest Review Report
## Linter Results
[Table: Cell | Linter Status | Errors (if any)]
## Analysis 1 — Code vs Requirements
[Table: Cell | Signature Match | Method Coverage | Property Coverage | Facade | Status]
## Analysis 2 — Requirements vs Code
[Table: Cell | Undocumented Entities | Description Accuracy | Annotation Quality | Status]
## Algorithm Consistency
[Per Cell: manifest algorithm vs implementation — match / discrepancy]
## Operational Flow Consistency
[Per Cell: manifest flow vs implementation — match / discrepancy]
## Guarantee Verification
[Per Cell: manifest guarantees vs implementation — preserved / violated]
## Practice Consistency
[Per Cell: manifest practices vs implementation — match / discrepancy]
## Baseline Usages/Annotations Audit
[Table: Cell | Baseline Usages present? | Baseline Annotations present?]
## Findings
[Table: Cell | Analysis | Finding | Severity (CRITICAL/WARNING/INFO) | Proposed Action]
## Applied Updates
[Table: Cell | Updated Section | Previous Value | New Value | Reason]
## Critical Discrepancies
[List of CRITICAL items. Empty if none.]
## Overall Status
[CONSISTENT / INCONSISTENT — with justification]
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: qarium
- Source: qarium/goga
- License: BSD-3-Clause
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.