factory-audit dispatches on path shape (SKILL.md Step 0) to two flows, references/skill-flow.md and references/agent-flow.md. Both carry the same procedure: run validate.sh, validate-provenance.sh and vale-wrap.sh; read their 0/1/2 exit codes the same way; read the artifact; read a criteria file first and load rubrics only for dimensions in play; cite file and line. Only the data differs. Adding hooks, instructions and prompts (#94) would copy that procedure three more times, so the procedure moves into one generic flow first.
What to build
A references/primitive-flow.md holding the shared procedure once.
A per-primitive data table that supplies, for each primitive: Step 0 target shape, validate.sh mode, criteria file, rubric files, coverage line, and the "Run X-author to address findings" line.
Dispatch table in SKILL.md Step 0 reads from that table.
Migrate the existing skill and agent flows onto it. Behaviour-preserving: no change to what is checked or reported.
Stub rows are out of scope. The new primitives register their own row in their own issues.
Not in scope
New check suites (lib-checks-*.sh) for any new primitive. Those are the three audit issues blocked by this one.
Changing validate.sh mode detection beyond what the table needs.
Risk
skill-flow.md and agent-flow.md are model instructions, not scripts, so the bats suites do not cover them. A regression here changes every skill and agent audit. The acceptance criteria below exist to catch that.
Acceptance criteria
references/primitive-flow.md exists and skill-flow.md / agent-flow.md are removed or reduced to table rows; the shared procedure appears once.
tests/validate-skill.bats, validate-agent.bats and both validate-provenance-*.bats pass unchanged.
A fixed set of fixture skills and agents (at least one PASS, one FAIL and one SUGGESTION case per type) is audited before and after the migration; the reports are identical. Record the fixture paths and the before/after diff in the PR.
Step 0 still rejects an unrecognised path with the same message.
Skill description, metadata.version bumped per ADR-0022, and ADR-0020 description and body budgets still pass (scripts/skill-size-check.sh).
Part of #94.
## Why
`factory-audit` dispatches on path shape (SKILL.md Step 0) to two flows, `references/skill-flow.md` and `references/agent-flow.md`. Both carry the same procedure: run `validate.sh`, `validate-provenance.sh` and `vale-wrap.sh`; read their 0/1/2 exit codes the same way; read the artifact; read a criteria file first and load rubrics only for dimensions in play; cite file and line. Only the data differs. Adding hooks, instructions and prompts (#94) would copy that procedure three more times, so the procedure moves into one generic flow first.
## What to build
- A `references/primitive-flow.md` holding the shared procedure once.
- A per-primitive data table that supplies, for each primitive: Step 0 target shape, `validate.sh` mode, criteria file, rubric files, coverage line, and the "Run X-author to address findings" line.
- Dispatch table in `SKILL.md` Step 0 reads from that table.
- Migrate the existing skill and agent flows onto it. Behaviour-preserving: no change to what is checked or reported.
- Stub rows are out of scope. The new primitives register their own row in their own issues.
## Not in scope
- New check suites (`lib-checks-*.sh`) for any new primitive. Those are the three audit issues blocked by this one.
- Changing `validate.sh` mode detection beyond what the table needs.
## Risk
`skill-flow.md` and `agent-flow.md` are model instructions, not scripts, so the bats suites do not cover them. A regression here changes every skill and agent audit. The acceptance criteria below exist to catch that.
## Acceptance criteria
- [ ] `references/primitive-flow.md` exists and `skill-flow.md` / `agent-flow.md` are removed or reduced to table rows; the shared procedure appears once.
- [ ] `tests/validate-skill.bats`, `validate-agent.bats` and both `validate-provenance-*.bats` pass unchanged.
- [ ] A fixed set of fixture skills and agents (at least one PASS, one FAIL and one SUGGESTION case per type) is audited before and after the migration; the reports are identical. Record the fixture paths and the before/after diff in the PR.
- [ ] Step 0 still rejects an unrecognised path with the same message.
- [ ] Skill `description`, `metadata.version` bumped per ADR-0022, and ADR-0020 description and body budgets still pass (`scripts/skill-size-check.sh`).
- [ ] `apm audit --ci` clean.
## References
- `plugins/kyberforge/.apm/skills/factory-audit/`
- ADR-0020 (context budget), ADR-0022 (version mandatory), ADR-0025 (audit skills merged into `factory-audit`)
Claude
added this to the Kyberforge basics milestone 2026-10-01 06:23:17 +00:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Part of #94.
Why
factory-auditdispatches on path shape (SKILL.md Step 0) to two flows,references/skill-flow.mdandreferences/agent-flow.md. Both carry the same procedure: runvalidate.sh,validate-provenance.shandvale-wrap.sh; read their 0/1/2 exit codes the same way; read the artifact; read a criteria file first and load rubrics only for dimensions in play; cite file and line. Only the data differs. Adding hooks, instructions and prompts (#94) would copy that procedure three more times, so the procedure moves into one generic flow first.What to build
references/primitive-flow.mdholding the shared procedure once.validate.shmode, criteria file, rubric files, coverage line, and the "Run X-author to address findings" line.SKILL.mdStep 0 reads from that table.Not in scope
lib-checks-*.sh) for any new primitive. Those are the three audit issues blocked by this one.validate.shmode detection beyond what the table needs.Risk
skill-flow.mdandagent-flow.mdare model instructions, not scripts, so the bats suites do not cover them. A regression here changes every skill and agent audit. The acceptance criteria below exist to catch that.Acceptance criteria
references/primitive-flow.mdexists andskill-flow.md/agent-flow.mdare removed or reduced to table rows; the shared procedure appears once.tests/validate-skill.bats,validate-agent.batsand bothvalidate-provenance-*.batspass unchanged.description,metadata.versionbumped per ADR-0022, and ADR-0020 description and body budgets still pass (scripts/skill-size-check.sh).apm audit --ciclean.References
plugins/kyberforge/.apm/skills/factory-audit/factory-audit)