Home / nguyenvanphituoc / shapeup-sdlc-plugin · .claude/skills/harness-maintenance-audit/SKILL.md · GitHub

harness-maintenance-audit skillA

harness-maintenance-audit is agent-read markdown (skill) from nguyenvanphituoc/shapeup-sdlc-plugin: Audit this plugin repo for two kinds of rot: documentation that no longer matches the shipped plugin, and internal bookkeeping that has leaked into files users receive. Derives every fact from the artifact itself — enums from the schema, counts from the filesystem, hook behavior by executing the hook — then fixes the docs and reports code defects separately. Use this whenever maintaining this repository: before a release or version bump, after removing/renaming/adding a skill, operation, hook or.

Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.

What the file says

# Harness maintenance audit

## What rots, and why it rots silently

This repo has an unusual shape that produces two specific failure modes.

**It is a product and its own blueprint.** `docs/` describes a plugin that `skills/`, `hooks/`,
`commands/` and `oracles/` actually implement. Both are prose-heavy, both are edited by hand, and
nothing mechanically ties a sentence in `docs/design/03-system-design.md` to the enum it describes.
So the docs drift, and they drift *plausibly* — a doc that says "11 workers" over a 10-member enum
reads perfectly.

**Not everything in the repo is product.** Development artifacts — benchmark numbers, internal
defect IDs, migration stage names, audit codenames, paths under `docs/`, `tests/`, `tools/`,
`evals/` — belong in the repo but not in what a user reads as the product. They leak easily,
because the person writing a code comment is holding all that context and it feels like useful
rationale at the time.

The leak that matters most is not in a code comment. `skills/*/SKILL.md` and
`skills/tech-lead/references/*.md` are **loaded by the model at runtime**, so a dangling
…

Read the whole file at its exact version.

How to install

Latest version
mdr add nguyenvanphituoc/shapeup-sdlc-plugin/harness-maintenance-audit@git:20260813.711eb60
Exact content
mdr add nguyenvanphituoc/shapeup-sdlc-plugin/harness-maintenance-audit@sha256:a28979cbfe5ac932

Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.

Badge

mdr badge

[![mdr](https://markdownregistry.com/badge/art_sdydtxh7hg55ijr6.svg)](https://markdownregistry.com/a/art_sdydtxh7hg55ijr6)

1 badge views in 30 days

Versions

versioncommittedcommitsizeaudit
git:20260813.711eb60 latest2026-08-13 711eb60 12,885 BA view · diff
git:20260812.92365592026-08-12 9236559 12,889 BA view · diff
git:20260812.ddd413c2026-08-12 ddd413c 12,940 BA view

Audit of the latest version

A  17 of 17 checks passed. Deterministic, no model, same answer every run.
  • pass: Frontmatter block present
  • pass: Frontmatter declares a name
  • pass: Frontmatter declares a description
  • pass: Size between 200 bytes and 200 KB (12885 bytes)
  • pass: No zero-width or bidi control characters
  • pass: No instruction hidden inside an HTML comment
  • pass: No link to an exfiltration or paste host
  • pass: No credential-shaped string
  • pass: No instruction to send local credentials anywhere
  • pass: No text hidden with inline styles
  • pass: No prompt-injection phrasing
  • pass: No curl or wget piped into a shell
  • pass: No recursive delete of root, home or parent
  • pass: No instruction to read or print local credentials
  • pass: No base64 blob over 200 characters
  • pass: No link to a raw IP address
  • pass: No script tag

Source

GitHub

nguyenvanphituoc/shapeup-sdlc-plugin · 3 stars · license MIT · pushed 2026-09-24 · branch main

API

GET https://markdownregistry.com/api/v1/artifacts/art_sdydtxh7hg55ijr6
GET https://markdownregistry.com/api/v1/resolve?ref=nguyenvanphituoc/shapeup-sdlc-plugin/harness-maintenance-audit
GET https://markdownregistry.com/api/v1/blob/a28979cbfe5ac9327f6e394ce4d1071c98364de55d38ec07749d07cd29d6133d

Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.

More from nguyenvanphituoc/shapeup-sdlc-plugin

architecture-research-report skill
nguyenvanphituoc/shapeup-sdlc-plugin · .claude/skills/architecture-research-report/SKILL.md · Research a technical question deeply, then produce an evidence-dense architecture report that takes a position, shows…
git:20260805.1a76bee · audit A · 3 stars
plan-executor skill
nguyenvanphituoc/shapeup-sdlc-plugin · .claude/skills/plan-executor/SKILL.md · Execute a staged plan document end to end — compile its recommendation into an acceptance contract, implement each…
git:20260813.711eb60 · audit A · 3 stars
svg-builder skill
nguyenvanphituoc/shapeup-sdlc-plugin · .claude/skills/svg-builder/SKILL.md · Build correct, self-contained SVG diagrams, illustrations, and animations from a description. Everything it produces…
git:20260819.b84978e · audit A · 3 stars
AGENTS.md agents
nguyenvanphituoc/shapeup-sdlc-plugin · AGENTS.md
git:20260924.f1de9d1 · audit A · 3 stars
CLAUDE.md claude
nguyenvanphituoc/shapeup-sdlc-plugin · CLAUDE.md
git:20260924.4a610f8 · audit A · 3 stars
ba-pitch-analyzer skill
nguyenvanphituoc/shapeup-sdlc-plugin · skills/ba-pitch-analyzer/SKILL.md · Use this skill whenever a user provides a product requirement, pitch, or feature description and wants it broken down…
git:20260922.52fedc2 · audit A · 3 stars
coach skill
nguyenvanphituoc/shapeup-sdlc-plugin · skills/coach/SKILL.md · Use this skill to turn raw Product Owner / Tech Lead feedback at the Ship Sign-off (L4 Gate) into structured…
git:20260920.4caf2ec · audit A · 3 stars
hill-chart skill
nguyenvanphituoc/shapeup-sdlc-plugin · skills/hill-chart/SKILL.md · Use this skill whenever the user wants to see how their Shape Up build(s) are progressing — a Hill Chart, a build…
git:20260923.1178d0f · audit A · 3 stars
orient skill
nguyenvanphituoc/shapeup-sdlc-plugin · skills/orient/SKILL.md · Use this skill for Shape Up step 7 (Orient) — the builder-led reconnaissance pass that runs AFTER kick-off and BEFORE…
git:20260913.e3dbbe1 · audit A · 3 stars
qa-edge-hunter skill
nguyenvanphituoc/shapeup-sdlc-plugin · skills/qa-edge-hunter/SKILL.md · Use this skill for the post-PASS exploratory QA pass — Shape Up's "QA is for the edges", made explicit for the harness…
git:20260913.e3dbbe1 · audit F · 3 stars
scope-architect skill
nguyenvanphituoc/shapeup-sdlc-plugin · skills/scope-architect/SKILL.md · Use this skill to map the vertical scopes of a feature — Shape Up's "map the scopes" (step 8) as committed…
git:20260919.531c9ed · audit A · 3 stars
scope-hammer skill
nguyenvanphituoc/shapeup-sdlc-plugin · skills/scope-hammer/SKILL.md · Use this skill whenever a Shape Up build run reaches its stop condition — the circuit breaker (round budget or a…
git:20260922.449c249 · audit A · 3 stars

Every file in nguyenvanphituoc/shapeup-sdlc-plugin

Browse by kind, by grade A, or by owner.