MCP HubMCP Hub
SKILL·7FF789

code-improver

trailofbits
Обновлено 4 days ago
6,918
596
6,918
Посмотреть на GitHub
Метаgeneral

О программе

Этот навык самостоятельно запускает цикл проверки и исправления для любого целевого кода, используя указанного агента-рецензента. Он ведет журнал обнаруженных проблем по всем итерациям, эскалирует, когда исправления перестают сходиться, и механически контролирует соблюдение границ задачи. Используйте его, когда требуется итеративно улучшать код до тех пор, пока проверка не будет пройдена с конкретным рецензентом.

Быстрая установка

Claude Code

Рекомендуется
Основной
npx skills add trailofbits/skills -a claude-code
Команда плагинаАльтернативный
/plugin add https://github.com/trailofbits/skills
Git клонированиеАльтернативный
git clone https://github.com/trailofbits/skills.git ~/.claude/skills/code-improver

Скопируйте и вставьте эту команду в Claude Code для установки этого навыка

Документация

Code Improver

Improve any code target by running /code-improver:improve — a dynamic workflow that loops the named reviewer and a fixer subagent until a review reports zero critical/major findings, then strips its own residue. The loop, its ledger, and its guards live in the workflow; this skill collects the three inputs the generic entry requires and relays the outcome.

Starting the loop

The user provided: $ARGUMENTS (if empty, take the details from the conversation).

1. Collect the three required inputs — no guessing

  1. Target: the absolute path to the directory under improvement. Resolve relative paths against the working directory; verify the directory exists.
  2. Reviewer: the installed skill or agent that performs every review. The user must name it — there is no default and no bundled reviewer. Determine the kind:
    • a namespaced agent (e.g. plugin-dev:skill-reviewer) → "kind": "agent"
    • an installed skill (e.g. pr-review-toolkit:review-pr) → "kind": "skill" If the name could be either, check the session's skill listing; if still ambiguous, ask the user. If no reviewer was named, ask — do not pick one.
  3. Scope: repo-relative globs the loop may touch. The generic entry requires it explicitly; if the user did not give one, propose the target directory (<repo-relative-target>/**) and confirm before launching.

2. Resolve the loop script

The loop is the dynamic workflow workflows/improve.js in this plugin. Launch it by path: scriptPath takes a resolved absolute path, and the Workflow tool's name resolves built-in and project workflows, so a marketplace-installed one may not answer to code-improver:improve. Try in order, first hit wins — the home directories come before . so an installed copy beats a checkout of this marketplace:

  1. Bash: ls -d -- "${CLAUDE_PLUGIN_ROOT}/workflows/improve.js"
  2. Bash: ls -d -- "${CODEX_PLUGIN_ROOT}/workflows/improve.js" (if that variable is set instead)
  3. Bash: find ~/.claude ~/.codex . -maxdepth 7 -path '*/code-improver/workflows/improve.js' -print -quit 2>/dev/null

Use the path exactly as printed. Its plugin directory — the path with /workflows/improve.js removed — is pluginRoot. If all three come back empty, try {name: "code-improver:improve"} once; if that is unavailable too, stop and say the loop could not be located. Do not assemble a path by hand and do not improvise the loop.

3. Invoke the workflow

Run it with the Workflow tool, {scriptPath: "<the path from step 2>", args: {...}}:

{
  "target": "<absolute target path>",
  "reviewer": { "kind": "agent|skill", "name": "<namespaced-name>", "notes": "<what the reviewer should know about the target>" },
  "scope": ["<repo-relative-glob>/**"],
  "pluginRoot": "<the plugin directory from step 2>",
  "maxRounds": 5
}
  • maxRounds only if the user asked for a different cap.
  • pluginRoot lets the run find its metrics collector; omit the key only if step 2 fell through to the workflow name — the workflow then searches for itself.
  • finalize ({"version_bump": bool, "narration_strip": bool, "docs_pass": bool}) only to override the defaults: version bump when the target sits inside a plugin, narration strip and docs pass always.
  • decision only on continuation (below).

The workflow runs in the background and needs no babysitting: it reviews, fixes, re-reviews, checks scope after every fix round, and can only complete on a clean review. It never commits; all changes stay in the working tree.

If the Workflow tool is unavailable or denied, stop and say so. Do not improvise the loop inline with direct edits — the ledger, scope guard, and escalation guarantees live in the workflow, and an inline imitation has none of them.

If the result is halted: "reviewer-unavailable", relay it and stop. The named reviewer is not installed in this session; tell the user which plugin provides it and re-run after installing. Do not review the target yourself.

Do not end your turn while the loop is running. The Workflow tool returns a task id immediately; the result comes later. In an interactive session the completion notification re-invokes you — wait for it. In a non-interactive run (scripted, CI, eval) there is no later turn: stopping abandons the loop mid-round, so after launching, poll the task (TaskOutput with the returned task id, or sleep-and-recheck) until it completes, then relay the result. A session that answers "the loop is running, I'll report later" has lost the run.

Relaying the result

The workflow returns a structured result. Report it honestly — the distinctions matter:

  • converged: true — the last action was a review with zero critical/major findings. Report rounds used, remaining minor findings (open_minor_count), and the artifact paths (ledger_path, metrics).
  • capped: true — the fix budget ran out and the FINAL review still found blocking issues. Say plainly: capped, NOT converged, and list open_blocking. Do not present this as success.
  • escalation — the loop detected it was not converging (recurring findings, non-decreasing counts, or a fix relocating a problem). Relay the escalation message and finding ids to the user: this needs a design decision, not more rounds.
  • halted — a guard fired (scope violation, unregistered new files, a dead or unavailable reviewer, or a finalize pass whose own edits failed the check that follows it). Relay the paths in violations/new_untracked_files, the sites in finalize_regressions, and the notes.
  • notes always travel with the result — surface them; they include loud warnings such as "a git repository was initialized".

Continuing after an escalation

The loop stops on escalation by design. When the user decides, start a fresh run with the same target and reviewer plus:

{ "decision": "<the user's ruling, verbatim>" }

The new run reloads the on-disk ledger, so every finding, rejection, and verdict carries over — rounds restart, re-derivation does not.

To stop a running loop, stop the workflow task (TaskStop); the ledger on disk is current to the last round and a re-run resumes from it.

When NOT to use

  • A Claude Code skill: use the skill-improver entry — it wires the right reviewer
  • A branch / pull request: use the pr-improver entry — it derives scope from the diff
  • One-time review: dispatch the reviewer directly; the loop's value is iteration
  • Quick single fixes: edit the file directly

GitHub репозиторий

trailofbits/skills
Путь: plugins/code-improver/skills/code-improver
0
agent-skills
FAQ

Часто задаваемые вопросы

Что такое Skill code-improver?

code-improver — это Claude Skill от trailofbits. Skills объединяют инструкции и ресурсы, которые Claude загружает по мере необходимости, чтобы выполнять задачи, связанные с code-improver, без дополнительных запросов.

Как установить code-improver?

Используйте команды установки на этой странице: добавьте code-improver в Claude Code как плагин или клонируйте репозиторий в каталог skills, затем перезапустите Claude, чтобы загрузить Skill.

К какой категории относится code-improver?

code-improver относится к категории Мета.

Можно ли использовать code-improver бесплатно?

Да. code-improver размещён на AIMCP и доступен для бесплатной установки.

Похожие навыки

content-collections
Мета

Этот навык предоставляет проверенную в продакшене настройку для Content Collections — TypeScript-ориентированного инструмента, который преобразует файлы Markdown/MDX в типобезопасные коллекции данных с валидацией Zod. Используйте его при создании блогов, сайтов документации или контентных приложений на Vite + React для обеспечения типобезопасности и автоматической проверки содержимого. Он охватывает всё: от настройки плагина Vite и компиляции MDX до оптимизации развертывания и валидации схем.

Просмотреть навык
polymarket
Мета

Этот навык позволяет разработчикам создавать приложения на платформе прогнозных рынков Polymarket, включая интеграцию с API для торговли и получения рыночных данных. Он также обеспечивает потоковую передачу данных в реальном времени через WebSocket для отслеживания текущих сделок и рыночной активности. Используйте его для реализации торговых стратегий или создания инструментов, обрабатывающих обновления рынка в реальном времени.

Просмотреть навык
creating-opencode-plugins
Мета

Этот навык помогает разработчикам создавать плагины OpenCode, которые подключаются к более чем 25 типам событий, таким как команды, файлы и операции LSP. Он предоставляет структуру плагина, спецификации API событий и шаблоны реализации для модулей на JavaScript/TypeScript. Используйте его, когда вам нужно перехватывать, отслеживать или расширять жизненный цикл ассистента OpenCode AI с помощью пользовательской событийно-ориентированной логики.

Просмотреть навык
sglang
Мета

SGLang — это высокопроизводительный фреймворк для обслуживания больших языковых моделей (LLM), специализирующийся на быстрой структурированной генерации JSON, regex и рабочих процессов агентов с использованием кэширования префиксов RadixAttention. Он обеспечивает значительно более высокую скорость вывода, особенно для задач с повторяющимися префиксами, что делает его идеальным для сложных структурированных результатов и многократных диалогов. Выбирайте SGLang вместо альтернатив, таких как vLLM, когда вам требуется ограниченное декодирование или вы создаете приложения с интенсивным совместным использованием префиксов.

Просмотреть навык