CtrlK
BlogDocsLog inGet started
Tessl Logo

toolkit-hardener

This skill should be used when the user asks to 'harden a toolkit skill', 'check a skill against the Definition of Done', 'audit packet completeness', 'validate a skill against the katas', 'bring a skill to gold-standard', or 'run the excellence gate' for the claude-native-toolkit. Enforces the packet DoD + kata best-practices + the toolkit brand + evidence honesty before a skill is declared done.

SKILL.md
Quality
Evals
Security

Toolkit Hardener

Excellence gate for claude-native-toolkit. Brings a skill packet to gold-standard and refuses to declare it done until it passes the offline Definition of Done and records the review-only gaps for katas, output quality, and runtime behavior. It can delegate Support and Guardian reviews with Agent; without a live trace, those reviews remain coverage_gap.

Conclusión (Minto)

Una skill está lista offline solo cuando pasa el DoD de packet y los gates deterministas. Katas semánticas, selección LLM y calidad de salida requieren evidencia separada. [CONFIG]

When to run

  • Cerrar (close) una skill durante la normalización profunda (Tranche 3, Fase 2).
  • Auditar all antes de un bump de versión.
  • Validar una skill nueva o editada antes de sync a standalone.

Definition of Done (gate)

  1. Frontmatter — pasa skill-creator/validate_frontmatter.py (solo keys permitidas; extras en metadata). [DOC]
  2. Eval contract schema 2 — semantic_status: not_executed, casos positivos y negativos/adversariales, checks de dominio, oráculos estáticos allowlisted y revisión de suites generadas/portadas. No stubs ni claims de ejecución LLM. [CONFIG]
  3. Lineage — metadata.lineage presente. [CONFIG]
  4. Packet por tier (${CLAUDE_PLUGIN_ROOT}/scripts/validate_packet.py): tier full requiere agents/, knowledge/body-of-knowledge.md, prompts/, examples/. Tier routing queda lean. [CONFIG]
  5. Katas — declara y revisa las katas aplicables (ver references/kata-checklist.md); el gate prueba relaciones/recursos, no juicio semántico. [DOC][coverage_gap]
  6. Marca — README/docs en Minto, evidencia honesta (G2), sin lista roja (G4), español latino neutro (G3). [DOC]
  7. Evidencia — claims con tags [CÓDIGO] [CONFIG] [DOC] [INFERENCIA] [SUPUESTO]; incógnitas como coverage_gap. [CONFIG]

Procedure

  1. Resolver el target (skill-name o all). Cargar references/dod-contract.md.
  2. Lead (agents/lead.md): autoría/relleno del packet faltante.
  3. Delegar con Agent una revisión Support de marca, evidencia y disclosure.
  4. Delegar con Agent una revisión Specialist de profundidad de dominio cuando aplique.
  5. Delegar con Agent un Guardian distinto del producer; debe correr el gate y bloquear si falla.
  6. Ejecutar la cadena de gates (todo vendorizado, portable vía ${CLAUDE_PLUGIN_ROOT}):
    R="${CLAUDE_PLUGIN_ROOT}"
    python3 "$R/scripts/lib/validate_frontmatter.py" "$R/skills/<s>/SKILL.md"   # frontmatter
    python3 "$R/scripts/lib/lint_skill.py" "$R/skills/<s>/SKILL.md" --json       # rúbrica lint
    python3 "$R/scripts/lib/validate_skill.py" "$R/skills/<s>"                    # QA estructural
    python3 "$R/scripts/validate_packet.py" "$R/skills"                          # packet DoD
    bash   "$R/scripts/check.sh"                                                  # gate completo (incl. lint_gate)
  7. Si pasa: registrar en docs/normalization-status.md. Si falla: devolver lista de gaps con tag de evidencia, no marcar done.

Anti-Patterns

  • Declarar done sin correr el gate por script.
  • Rellenar packet con contenido genérico (las katas penalizan ejemplos genéricos).
  • Inventar datos para evidencia (viola G2).
  • Sobreescribir eval contracts revisados con stubs.
  • Confundir un REF-MISSING a ruta plugin-level con un packet roto: lint_skill.py resuelve refs relativas al skill-dir, así que las refs ${CLAUDE_PLUGIN_ROOT}/scripts/* de este propio SKILL.md se marcan como REF-MISSING crítico (falso-positivo esperado, degradado a warning por lint_gate.py). [CÓDIGO]

Governance & integrity

La ley suprema es ${CLAUDE_PLUGIN_ROOT}/CONSTITUTION.md (10 artículos: honestidad de runtime, evidencia, least-privilege, marca, DoD, integridad, roles, portabilidad, verificar-al-verificador, precedencia/enmienda). [CONFIG] Al cerrar una skill, además del gate, el estado hardened se sella vía hash-lock: python3 "$R/scripts/integrity.py" --lock (re-baseline solo tras re-hardenizar). analyze.py da la salud del corpus. [CÓDIGO]

Resources

  • references/dod-contract.md — contrato DoD completo por tier.
  • references/kata-checklist.md — mapa kata → qué exige.
  • knowledge/body-of-knowledge.md — modelo de calidad y métricas.
  • prompts/primary.md, prompts/meta.md — ejecución y routing.
  • agents/{lead,support,specialist,guardian}.md — triad de hardening.
  • Scripts (plugin-level, portables): ${CLAUDE_PLUGIN_ROOT}/scripts/check.sh, ${CLAUDE_PLUGIN_ROOT}/scripts/validate_packet.py, ${CLAUDE_PLUGIN_ROOT}/scripts/harden_audit.py, ${CLAUDE_PLUGIN_ROOT}/scripts/lint_gate.py, y vendorizados en ${CLAUDE_PLUGIN_ROOT}/scripts/lib/ (validate_frontmatter, lint_skill, validate_skill, validate_inventory, package_skill).

Contract

  • Aceptación: la skill objetivo pasa frontmatter + eval contract + packet DoD + lint + harden, [EXPLICIT] cita la Constitution y separa revisión de katas/LLM como evidencia o coverage_gap.
  • Límites: valida calidad; no escribe el contenido distintivo de la skill. [EXPLICIT]
  • Casos borde: majors de lint = warn (no bloquean); criticals estructurales (frontmatter, name/description) bloquean; REF-MISSING a scripts plugin-level se degrada a warning en lint_gate.py. [CÓDIGO]
  • Supuestos: validadores vendorizados en ${CLAUDE_PLUGIN_ROOT}/scripts/lib/. [SUPUESTO]
  • Trade-off: el gate estricto sube calidad a cambio de fricción; integridad bloquea y el soft [EXPLICIT] token budget solo reporta.

Packet

Capas del packet, cargables bajo demanda (disciplina ICM: una capa por vez, nunca todas juntas): references/ guías de profundidad (cargar UNA por etapa) · knowledge/ cuerpo de conocimiento · prompts/ prompts listos · examples/ salida de ejemplo · agents/ subagentes del packet · assets/ recursos estáticos.

Repository
JaviMontano/claude-plugins
Last updated
First committed

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.