- Repository:
coding-agent-skills - Branch:
main - Pilot skills:
repo-map,route-trace,env-audit,secret-audit,api-contract-audit,migration-review,github-handoff,deployment-preflight,build-verify,git-preflight,runtime-truth,llm-drift-control - Adapter discovery, project adapter installation, stale-pin detection, upgrade evidence, compatibility-chain validation, evidence-bundle verification, retention policy, provenance design, archive-report rendering, archive-index fixtures, retention-expiry advisory reporting, and detached-signature verification planning are implemented.
- Real-project adapter adoption readiness is documented as a planning-only approval gate.
- First external project-owned adapter adoption completed for
/home/oneclickwebsitedesignfactory/tax-lien-platformat candidate commitc548b1a6cbb3455a70b89d0e301e22435bfccac9. - The adopted adapter is
repo-maponly, docs/metadata-only, and contains no commands, runtime checks, build/test/package behavior, platform/deployment behavior, or secret-aware behavior. - The shared repository does not contain real adapter manifests; real project adapters remain owned by their project repositories.
- Public npm package release
v0.2.19exposes the dependency-freecoding-agent-skillsCLI under MIT license. v0.2.18formalizes the public JSON result schema, corrects missing-input and safety-refusal semantics, and adds deterministic aggregateauditoutput.route-traceis implemented as an audit-only static route tracing skill.env-auditis implemented as an audit-only value-free environment variable name mapping skill.secret-auditis implemented as an audit-only redacted secret exposure detection skill.api-contract-auditis implemented as an audit-only static API contract surface mapping skill.migration-reviewis implemented as an audit-only static migration and schema evidence review skill.github-handoffis implemented as an audit-only local Git handoff evidence skill.deployment-preflightis implemented as an audit-only static deployment readiness evidence skill.- Builder-mode approval: complete the remaining read-only skill wave for
coding-agent-skillsitself. Real-world project execution constraints remain unchanged.
v0.2.19
The formal public CLI result schema and aggregate read-only audit command are released.
The OpenClaw wrapper exposes coding_audit as an optional ToolGate-controlled tool.
The v0.2.19 compatibility patch normalizes controlled legacy empty and unsafe states
into the formal schema. Reassess current evidence before selecting another bounded
read-only capability.
- Inspect local repository state.
- Read
ROADMAP.md,CHANGELOG.md, and this ledger. - Run pack validation.
- Run release tests.
- Run maintainer-loop validation.
- Select the next bounded milestone.
- Maintain planning documentation for the approved real-project adapter adoption gate.
- Write maintainer-loop evidence to
runs/skill-runs.md. - Update this ledger with local maintainer decisions.
- Record completed real-project adapter adoption evidence in shared docs and run logs.
- Maintain public package metadata and release evidence for approved patch releases.
- Adding skills outside the approved builder-mode read-only wave.
- Creating real project adapters.
- Modifying real project repositories.
- Publishing release artifacts without explicit approval.
- Adding dependencies without explicit approval.
- Weakening safety, adapter, evidence, command-policy, or completion rules.
- Running infrastructure, database, service, or process mutations.
- Current branch and tag summary.
- Clean or dirty Git state.
- Validation commands and results.
- Selected milestone and required permission.
- Files changed by the maintainer-loop run.
- Stop boundary reached.
- Recommended next action.
- Working tree is dirty before the loop starts.
- No permission flag is supplied.
- Supplied permission does not match the next required action.
- Validation fails.
- The next action would exceed the approved repository scope.
- The next action requires human approval.
- Implementing the next evidence-retention or provenance milestone.
- Selecting a real project adapter candidate.
- Gathering evidence from a real project repository.
- Creating, changing, or removing skills outside the approved builder-mode read-only wave.
- Adding real project adapters.
- Expanding the adopted
tax-lien-platformadapter beyondrepo-map. - Enabling candidate repo package scripts, build verification, runtime checks, or command aliases.
- Allowing or bypassing project Git hooks during future adapter publication.
- Touching real project repositories.
- Changing release publication behavior.
- Publishing a new npm version outside the approved builder-mode read-only wave or another explicitly approved release.
- Commit, tag, or push operations.
- Any action not listed in the allowed next actions above.
No next runner command is currently queued.No autonomous maintainer-loop run has been recorded yet.
- Latest tag observed:
v0.2.13 - Implemented milestone:
github-handoffaudit-only local Git handoff evidence skill and CLI command. - Required permission:
builder-mode-skill-implementation - Validation result: passed;
v0.2.14commit, tag, npm publication, registry smoke, npm exec, and GitHub Release completed - Next recommended milestone: continue builder-mode wave with
deployment-preflight-skillafterv0.2.14publication completes.
- Latest tag observed:
v0.2.14 - Implemented milestone:
deployment-preflightaudit-only static deployment readiness evidence skill and CLI command. - Required permission:
builder-mode-skill-implementation - Validation result: passed;
v0.2.15commit, tag, npm publication, registry smoke, npm exec, and GitHub Release completed - Next recommended milestone: implement the OpenClaw-compatible JSON output and exit-code
contract before continuing to
cloudflare-preflight-skill.
- Latest tag observed:
v0.2.15 - Implemented milestone: OpenClaw-compatible optional
--jsonoutput and documented exit-code semantics for every public CLI command. - Required permission:
orchestrator-output-contract - Validation result: pass pending final release validation matrix
- Next recommended milestone: continue builder-mode wave with
cloudflare-preflight-skillafterv0.2.16publication completes.
- Latest tag observed:
v0.2.17 - Implemented milestone: formal public CLI result schema, corrected missing-project and
unsafe-adapter exit semantics, and deterministic aggregate
auditcommand. - Required permission: approved end-to-end package and OpenClaw integration release.
- Validation result: passed; package commit
d610704, tagv0.2.18, npm publication, registry install, npm exec, GitHub Release, OpenClaw plugin PR #2, merge88933d6, global install, gateway restart, and 12-tool runtime inspection completed. - Next recommended milestone: select from current evidence after
v0.2.18publication andcoding_auditregistration complete.
- Latest tag observed:
v0.2.19 - Implemented milestone: normalize controlled legacy empty/unsafe CLI statuses into the formal public result schema.
- Required permission: bounded release compatibility fix.
- Validation result: passed; commit
0c811f8, tagv0.2.19, npm publication, GitHub Release, tarball and registry installs, npm exec, global install, schema regression checks, and aggregate global audit completed. OpenClaw remained loaded with 12 optional tools includingcoding_audit; no wrapper change or gateway restart was required. - Next recommended milestone: reassess current evidence before selecting another bounded read-only capability.
- Latest tag observed:
v0.2.12 - Implemented milestone:
migration-reviewaudit-only static migration and schema evidence review skill and CLI command. - Required permission:
builder-mode-skill-implementation - Validation result: passed;
v0.2.13commit, tag, npm publication, registry smoke, npm exec, and GitHub Release completed - Next recommended milestone: continue builder-mode wave with
github-handoff-skillafterv0.2.13publication completes.
- Latest tag observed:
v0.2.11 - Implemented milestone:
api-contract-auditaudit-only static API contract surface mapping skill and CLI command. - Required permission:
builder-mode-skill-implementation - Validation result: pass pending final publication evidence
- Next recommended milestone: continue builder-mode wave with
migration-review-skillafterv0.2.12publication completes.
- Latest tag observed:
v0.2.10 - Implemented milestone:
secret-auditaudit-only redacted secret exposure detection skill and CLI command. - Required permission:
builder-mode-skill-implementation - Validation result: pass pending final publication evidence
- Next recommended milestone: continue builder-mode wave with
api-contract-audit-skillafterv0.2.11publication completes.
- Latest tag observed:
v0.2.9 - Implemented milestone:
env-auditaudit-only environment variable name mapping skill and CLI command. - Required permission:
builder-mode-skill-implementation - Validation result: pass pending final publication evidence
- Next recommended milestone: continue builder-mode wave with
secret-audit-skillafterv0.2.10publication completes.
- Latest tag observed:
v0.2.7 - Implemented milestone: Public npm release for
coding-agent-skills. - Required permission:
release-preflight - Validation result: pass pending final publication evidence
- Next recommended milestone: No next runner command is queued; future package publication, new skills, real adapter expansion, platform work, and deployment/preflight skills require separate human approval.
- Latest tag observed:
v0.2.8 - Implemented milestone:
route-traceaudit-only static route tracing skill and CLI command. - Required permission:
skill-implementation - Validation result: pass pending final publication evidence
- Next recommended milestone: no next runner command is queued; future real adapter expansion, new skills, platform work, deployment/preflight skills, and release-policy changes require separate human approval.
- Latest tag observed:
v0.2.0 - Selected milestone: Evidence-bundle verification, deterministic replay, and cross-release compatibility regression reporting.
- Required permission:
evidence-harness - Validation result: pass
- Stop boundary: implementation requires human approval
- Latest tag observed:
v0.2.0 - Implemented milestone: Evidence-bundle verification, deterministic replay, and cross-release compatibility regression reporting.
- Required permission:
evidence-harness - Validation result: pass
- Next recommended milestone: Evidence-bundle retention policy, signed provenance design, and report archival hardening.
- Latest tag observed:
v0.2.1 - Selected milestone: Evidence-bundle retention policy, signed provenance design, and report archival hardening.
- Required permission:
evidence-harness - Validation result: pass
- Stop boundary: implementation requires human approval
- Latest tag observed:
v0.2.1 - Implemented milestone: Evidence-bundle retention policy, signed provenance design, and report archival hardening.
- Required permission:
evidence-harness - Validation result: pass
- Next recommended milestone: Evidence-bundle archive index fixtures, retention-expiry advisory reporting, and detached-signature verification planning.
- Latest tag observed:
v0.2.2 - Selected milestone: Evidence-bundle archive index fixtures, retention-expiry advisory reporting, and detached-signature verification planning.
- Required permission:
evidence-harness - Validation result: pass
- Stop boundary: implementation requires human approval
- Latest tag observed:
v0.2.2 - Implemented milestone: Evidence-bundle archive index fixtures, retention-expiry advisory reporting, and detached-signature verification planning.
- Required permission:
evidence-harness - Validation result: pass
- Next recommended milestone: human direction required before selecting the next bounded milestone.