{"id":"7221c083-53c4-4486-8852-d001c1d63667","entityType":"agent","slug":"clawhub-chen6896qqwee-dawn-code-master","name":"代码大师｜编程铁律","canonicalUrl":"https://www.xpersona.co/agent/clawhub-chen6896qqwee-dawn-code-master","canonicalPath":"/agent/clawhub-chen6896qqwee-dawn-code-master","generatedAt":"2026-10-11T07:39:20.764Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-11T03:44:49.131Z","emptyReason":null},"description":"AI 写的代码一上生产就崩——不是它不会写，是没人给它立规矩。 代码大师把「写、审、测、重构」的标准炼成一条硬规矩，整合 80k★ agent-skills、23k★ claude-skills 等顶级技能集，让每一行 AI 代码都过验收。 触发词：写代码、修bug、代码审查、PR review、重构、设计评审、API设计、测试用例、spec 驱动开发。 Skill: 代码大师｜编程铁律 Owner: chen6896qqwee Summary: AI 写的代码一上生产就崩——不是它不会写，是没人给它立规矩。 代码大师把「写、审、测、重构」的标准炼成一条硬规矩，整合 80k★ agent-skills、23k★ claude-skills 等顶级技能集，让每一行 AI 代码都过验收。 触发词：写代码、修bug、代码审查、PR review、重构、设计评审、API设计、测试用例、spec 驱动开发。 Tags: code-review:6.1.1, coding:6.1.1, latest:6.1.1, python:6.1.1, typescript:6.1.1 Version history: v6.1.1 | 2026-10-09T02:47:37.361Z | user 技能页文案升级：痛点钩子前置 + 保留触发词 v6.1.0 | 2026-07-27T02:55:37.","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.2K downloads reported by the source. Last updated 10/11/2026.","installCommand":"clawhub skill install s17d04jj6mht3atggbc0865zph83hbzy:dawn-code-master","sourceUrl":"https://clawhub.ai/chen6896qqwee/dawn-code-master","homepage":"https://clawhub.ai/chen6896qqwee/skills/dawn-code-master","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/chen6896qqwee/dawn-code-master","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/chen6896qqwee/skills/dawn-code-master","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":61,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"AI 写的代码一上生产就崩——不是它不会写，是没人给它立规矩。 代码大师把「写、审、测、重构」的标准炼成一条硬规矩，整合 80k★ agent-skills、23k★ claude-skills 等顶级技能集，让每一行 AI 代码都过验收。 触发词：写代码、修bug、代码审查、PR review、重构、设计评审、API"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-11T03:44:49.131Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T03:44:49.131Z","emptyReason":null},"stars":null,"forks":null,"downloads":1169,"packageName":null,"latestVersion":"6.1.1","tractionLabel":"1.2K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T03:44:49.065Z","emptyReason":null},"lastUpdatedAt":"2026-10-11T03:44:49.131Z","lastCrawledAt":"2026-10-11T03:44:49.065Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-12T03:44:49.065Z","lastVerifiedAt":null,"highlights":[{"version":"6.1.1","createdAt":"2026-10-09T02:47:37.361Z","changelog":"技能页文案升级：痛点钩子前置 + 保留触发词","fileCount":3,"zipByteSize":8475},{"version":"6.1.0","createdAt":"2026-07-27T02:55:37.149Z","changelog":"## dawn-code-master v6.1.0 - Updated SKILL.md metadata version from 6.0.0 to 6.1.0. - No content changes to logic, workflows, or skill descriptions. - Version bump for SKILL.md to reflect current release.","fileCount":3,"zipByteSize":8427},{"version":"6.0.0","createdAt":"2026-07-27T02:54:40.271Z","changelog":"- No file changes detected in this version. - No updates made to functionality, features, or documentation. - This release preserves all prior behavior and skill integrations.","fileCount":3,"zipByteSize":8350},{"version":"2.0.2","createdAt":"2026-07-27T02:53:19.414Z","changelog":"Dawn Code Master v2.0.2 - Major upgrade: integrated sources from 80k star agent-skills, yao-meta-skill, ratel, and several top open-source skill sets. - Expanded best practices coverage: now supports 50+ top coding skills and full lifecycle workflows. - Added a skill router section for clear phase-task-skill mapping throughout the development lifecycle. - Completely revised and extended methodology: more anti-rationalization rules, new context engineering, and doubt-driven development. - File `skill-card.md` was removed; all key information is now consolidated in an enhanced `SKILL.md`.","fileCount":3,"zipByteSize":8458},{"version":"2.0.1","createdAt":"2026-07-26T15:35:40.976Z","changelog":"Major upgrade: Integrates 30+ advanced coding and review skills into one comprehensive standard. - Unified coding, testing, PR review, API design, E2E testing, self-eval, and more into a single skill covering Python, TypeScript, Go, PowerShell, and beyond. - New SKILL.md includes extensive checklists, workflows, failure diagnosis, risk management, and language-specific conventions. - Adds thorough bug-fixing framework, PR audit process, spec-driven development workflow, and anti-pattern detection. - Dropped legacy and redundant documentation files (_meta.json, skill-card.md) for simplicity. - Vastly expanded coverage, bringing together best practices from many top GitHub skills and modern engineering guidelines.","fileCount":3,"zipByteSize":11554},{"version":"2.0.0","createdAt":"2026-07-11T16:32:25.580Z","changelog":"**Major update: v2.0.0 introduces structural and metadata changes.** - Updated skill version to 2.0.0 in SKILL.md and metadata. - Added _meta.json for enhanced metadata handling. - Removed skill-card.md file. - No changes to user-facing coding standards content.","fileCount":3,"zipByteSize":5974},{"version":"1.0.0","createdAt":"2026-07-06T07:50:40.745Z","changelog":"Consolidated 5 code skills into 1: code-quality + python + typescript + python-testing + code-smell-analyzer. Universal checklist, Python PEP8, TypeScript strict, pytest, smell detection.","fileCount":3,"zipByteSize":5647}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17d04jj6mht3atggbc0865zph83hbzy:dawn-code-master","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-chen6896qqwee-dawn-code-master/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-chen6896qqwee-dawn-code-master/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-chen6896qqwee-dawn-code-master/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-chen6896qqwee-dawn-code-master/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-chen6896qqwee-dawn-code-master/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-chen6896qqwee-dawn-code-master/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-11T07:39:20.761Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-chen6896qqwee-dawn-code-master/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-chen6896qqwee-dawn-code-master/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-chen6896qqwee-dawn-code-master/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-chen6896qqwee-dawn-code-master/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-11T03:44:49.131Z","emptyReason":null},"readme":"Skill: 代码大师｜编程铁律\n\nOwner: chen6896qqwee\n\nSummary: AI 写的代码一上生产就崩——不是它不会写，是没人给它立规矩。 代码大师把「写、审、测、重构」的标准炼成一条硬规矩，整合 80k★ agent-skills、23k★ claude-skills 等顶级技能集，让每一行 AI 代码都过验收。 触发词：写代码、修bug、代码审查、PR review、重构、设计评审、API设计、测试用例、spec 驱动开发。\n\nTags: code-review:6.1.1, coding:6.1.1, latest:6.1.1, python:6.1.1, typescript:6.1.1\n\nVersion history:\n\nv6.1.1 | 2026-10-09T02:47:37.361Z | user\n\n技能页文案升级：痛点钩子前置 + 保留触发词\n\nv6.1.0 | 2026-07-27T02:55:37.149Z | auto\n\n## dawn-code-master v6.1.0\n\n- Updated SKILL.md metadata version from 6.0.0 to 6.1.0.\n- No content changes to logic, workflows, or skill descriptions. \n- Version bump for SKILL.md to reflect current release.\n\nv6.0.0 | 2026-07-27T02:54:40.271Z | auto\n\n- No file changes detected in this version.\n- No updates made to functionality, features, or documentation.\n- This release preserves all prior behavior and skill integrations.\n\nv2.0.2 | 2026-07-27T02:53:19.414Z | auto\n\nDawn Code Master v2.0.2\n\n- Major upgrade: integrated sources from 80k star agent-skills, yao-meta-skill, ratel, and several top open-source skill sets.\n- Expanded best practices coverage: now supports 50+ top coding skills and full lifecycle workflows.\n- Added a skill router section for clear phase-task-skill mapping throughout the development lifecycle.\n- Completely revised and extended methodology: more anti-rationalization rules, new context engineering, and doubt-driven development.\n- File `skill-card.md` was removed; all key information is now consolidated in an enhanced `SKILL.md`.\n\nv2.0.1 | 2026-07-26T15:35:40.976Z | auto\n\nMajor upgrade: Integrates 30+ advanced coding and review skills into one comprehensive standard.\n\n- Unified coding, testing, PR review, API design, E2E testing, self-eval, and more into a single skill covering Python, TypeScript, Go, PowerShell, and beyond.\n- New SKILL.md includes extensive checklists, workflows, failure diagnosis, risk management, and language-specific conventions.\n- Adds thorough bug-fixing framework, PR audit process, spec-driven development workflow, and anti-pattern detection.\n- Dropped legacy and redundant documentation files (_meta.json, skill-card.md) for simplicity.\n- Vastly expanded coverage, bringing together best practices from many top GitHub skills and modern engineering guidelines.\n\nv2.0.0 | 2026-07-11T16:32:25.580Z | auto\n\n**Major update: v2.0.0 introduces structural and metadata changes.**\n\n- Updated skill version to 2.0.0 in SKILL.md and metadata.\n- Added _meta.json for enhanced metadata handling.\n- Removed skill-card.md file.\n- No changes to user-facing coding standards content.\n\nv1.0.0 | 2026-07-06T07:50:40.745Z | user\n\nConsolidated 5 code skills into 1: code-quality + python + typescript + python-testing + code-smell-analyzer. Universal checklist, Python PEP8, TypeScript strict, pytest, smell detection.\n\nArchive index:\n\nArchive v6.1.1: 3 files, 8475 bytes\n\nFiles: skill-card.md (1525b), SKILL.md (15470b), _meta.json (135b)\n\nFile v6.1.1:SKILL.md\n\n---\r\nname: dawn-code-master\r\ndescription: >\r\n  AI 写的代码一上生产就崩——不是它不会写，是没人给它立规矩。\r\n  代码大师把「写、审、测、重构」的标准炼成一条硬规矩，整合 80k★ agent-skills、23k★ claude-skills 等顶级技能集，让每一行 AI 代码都过验收。\r\n  触发词：写代码、修bug、代码审查、PR review、重构、设计评审、API设计、测试用例、spec 驱动开发。\r\nmetadata:\r\n  version: 6.1.0\r\n  sources:\r\n    - focused-fix (alirezarezvani/claude-skills)\r\n    - pr-review-expert (alirezarezvani/claude-skills)\r\n    - spec-driven-workflow (alirezarezvani/claude-skills)\r\n    - api-design-reviewer (alirezarezvani/claude-skills)\r\n    - api-test-suite-builder (alirezarezvani/claude-skills)\r\n    - self-eval — alirezarezvani/claude-skills\r\n    - skill-tester (alirezarezvani/claude-skills)\r\n    - mcp-server-builder (alirezarezvani/claude-skills)\r\n    - e2e-skills (voidmatcha/e2e-skills)\r\n    - avoid-ai-writing (conorbronsdon/avoid-ai-writing)\r\n    - cc-skills-golang (samber/cc-skills-golang)\r\n    - agentic-stack (codejunkie99/agentic-stack)\r\n    - antigravity-skills (krishnakanthb13)\r\n    - codebase-onboarding / migration-architect / ci-cd-pipeline-builder\r\n    - performance-profiler / database-designer / sql-database-assistant\r\n    - observability-designer / ship-gate / tech-debt-tracker\r\n    - changelog-generator / dependency-auditor / git-worktree-manager\r\n    - monorepo-navigator / rag-architect / agent-designer / agent-workflow-designer\r\n    - dawn-code-master v4.0 (local)\r\n    - agent-skills (addyosmani/agent-skills, 80k star)\r\n    - yao-meta-skill (yaojingang/yao-meta-skill, 2.1k star)\r\n    - ratel-ai/ratel (ratel-ai/ratel, 351 star)\r\n    - context-engineering-kit (NeoLabHQ/context-engineering-kit, 1.3k star)\r\n    - claude-skills (borghei/Claude-Skills, 411 star)\r\n  dawn:\r\n    requires:\r\n      bins: [python, node, pwsh, git]\r\n    permissions:\r\n      - exec: [python, node, ruff, black, pytest, pwsh, git]\r\n      - filesystem: [read/write workspace]\r\n---\r\n\r\n# Dawn Code Master v6.0\r\n\r\n**50+ 顶级编码技能集成 + 全生命周期工作流 + 反合理化验证门禁。** 写代码、修bug、审PR、做设计，按这个来。\r\n\r\n---\r\n\r\n## 0. Skill Router\r\n\r\n### Core Operating Behaviors\r\n\r\n1. Surface Assumptions - Before implementing, explicitly state assumptions\r\n2. Manage Confusion - Stop, name confusion, present tradeoff, wait for resolution\r\n3. Push Back - Point out problems directly, quantify downsides, propose alternatives\r\n\r\n### When to Use What\r\n\r\n| Phase | Task | Skill |\r\n|-------|------|-------|\r\n| Define | Dont know what you want | interview-me |\r\n| Define | Rough concept needs refining | [s2] Spec-Driven Dev |\r\n| Plan | Have spec, need tasks | [s3] Planning |\r\n| Build | Implementing code | [s4] Incremental Impl |\r\n| Build | UI work | Frontend principles |\r\n| Build | API work | [s16] API Design |\r\n| Build | Need better context | [s6] Context Eng |\r\n| Build | High stakes / unfamiliar code | [s7] Doubt-Driven |\r\n| Verify | Writing/running tests | [s5] TDD |\r\n| Verify | Bug fixing | [s8] Focused-Fix |\r\n| Review | Reviewing code | [s9] PR Review |\r\n| Review | Too complex | [s10] Code Simplification |\r\n| Review | Security concerns | [s11] Security |\r\n| Review | Performance concerns | [s12] Performance |\r\n| Ship | Committing/branching | [s14] Git Workflow |\r\n| Ship | CI/CD pipeline | [s15] CI/CD |\r\n| Ship | Deploying/launching | [s13] Ship Gate |\r\n| Maintain | Migration/deprecation | [s19] Migration |\r\n| Maintain | Tech debt | [s20] Tech Debt |\r\n| Docs | Writing docs/ADRs | Doc standards |\r\n| Ops | Logs/metrics/alerts | [s18] Observability |\r\n\r\n---\r\n\r\n## 1. Coding Laws\r\n\r\n**Pre-Commit Checklist:** syntax clean, tests pass, type hints, no bare except, no hardcoded secrets, f-string (not format()), pathlib (not os.path), docstrings, functions <= 30 lines.\r\n\r\n**File Structure:** <= 300 lines per file, <= 30 lines per function, one thing per function.\r\n\r\n**Error Handling:** async ops must have error handling, network requests must timeout, user input must be validated, external deps assumed to fail.\r\n\r\n**Anti-Rationalization:**\r\n\r\n| Rationalization | Reality |\r\n|----------------|---------|\r\n| \"Write now, refactor later\" | Later never comes. |\r\n| \"Just one line, no need to check\" | Small diffs push files past boundaries. |\r\n| \"AI-generated code is probably fine\" | AI code needs more scrutiny. |\r\n| \"Tests pass, it is good\" | Tests dont catch architecture or security issues. |\r\n\r\n---\r\n\r\n## 2. Spec-Driven Development\r\n\r\n**Law: NO CODE WITHOUT AN APPROVED SPEC.**\r\n\r\n**9 Mandatory Sections:** Title/Metadata, Context, Functional Requirements (RFC 2119), Non-Functional Requirements, Acceptance Criteria, Edge Cases, API Contract, Data Model, Out of Scope.\r\n\r\n**4-Phase Gated Workflow:** SPECIFY -> PLAN -> TASKS -> IMPLEMENT (each reviewed by human)\r\n\r\n**Stop-and-Ask Rules:** Scope creep, >30% ambiguity, breaking changes, security implications, unknown performance.\r\n\r\n**Anti-Rationalization:**\r\n| Rationalization | Reality |\r\n| \"Clear requirements, no spec needed\" | Clear reqs take 5 min. Unclear ones need it. |\r\n| \"Quick prototype first\" | The prototype is the final product. |\r\n| \"Specs are too slow\" | Specs save 10x refactoring time. |\r\n| \"I will document later\" | Later never comes. |\r\n\r\n---\r\n\r\n## 3. Planning and Task Breakdown\r\n\r\nEach task <= 30 min, independently testable, with clear AC. Slicing strategies: Vertical (preferred), Contract-First, Risk-First.\r\n\r\n---\r\n\r\n## 4. Incremental Implementation\r\n\r\n**Cycle:** Implement -> Test -> Verify -> Commit -> Next slice\r\n\r\n**Anti-Rationalization:** \"Writing everything at once is faster\" -> 500 lines untested = 10x debugging. \"Just a few lines, no need to commit separately\" -> atomic commits make rollback/review clean. \"I will test later\" -> never happens.\r\n\r\n---\r\n\r\n## 5. Test-Driven Development + E2E\r\n\r\n**TDD Cycle:** RED (write failing test) -> GREEN (min code to pass) -> REFACTOR (clean up)\r\n\r\n**Prove-It Pattern:** Write test reproducing bug (RED) -> Fix bug (GREEN) -> Write regression test -> Refactor\r\n\r\n**E2E Silent-Pass Detection:** toBeDefined()/not.toBeNull() on Locator always passes. Use toBeVisible()/toHaveText().\r\n\r\n**P0 Anti-patterns:** toBeDefined() on Locator, forgotten it.only, empty catch blocks, un-awaited async.\r\n\r\n**Anti-Rationalization:** \"Tests pass, it is good\" -> tests dont catch architecture/security. \"AI-generated code is fine\" -> needs more scrutiny. \"Write code first, add tests later\" -> tests what code does, not what it should do.\r\n\r\n---\r\n\r\n## 6. Context Engineering\r\n\r\n**From: ratel-ai/ratel (351 star) + NeoLabHQ/context-engineering-kit (1.3k star)**\r\n\r\n**Core Principle: Progressive Disclosure** - Load only what each turn needs.\r\n\r\n**Context Hierarchy:** 1. Rules Files (persistent) -> 2. Spec/Arch (per feature) -> 3. Source Files (per task) -> 4. Error Output (per iteration) -> 5. History (accumulates, compacts)\r\n\r\n**Ratel-Style Catalog:** All skills in SkillCatalog, tools in ToolCatalog. Each turn loads only matching ones.\r\n\r\n**Anti-Rationalization:** \"All rules in system prompt\" -> noise reduces accuracy. \"Same project, no need to separate\" -> different modules need different context. \"Write rules once\" -> projects evolve.\r\n\r\n---\r\n\r\n## 7. Doubt-Driven Development\r\n\r\n**From: addyosmani/agent-skills -- doubt-driven-development**\r\n\r\nA confident answer is not a correct one. For non-trivial decisions (branching logic, crossing boundaries, unverifiable assertions, irreversible blast radius).\r\n\r\n**Doubt Cycle:** 1. CLAIM (write claim + why matters) -> 2. EXTRACT (isolate artifact) -> 3. DOUBT (fresh-context adversarial review) -> 4. RECONCILE (classify findings) -> 5. STOP (trivial findings, 3 cycles, or user override)\r\n\r\n**Anti-Rationalization:** \"This is obviously correct\" -> hides most dangerous assumptions. \"Tests pass\" -> only cover known scenarios. \"No time\" -> doubt cycle is faster than debugging.\r\n\r\n---\r\n\r\n## 8. Bug Fixing (Focused-Fix)\r\n\r\n**Law: NO FIXES WITHOUT SCOPE -> TRACE -> DIAGNOSE FIRST.**\r\n\r\n**Phase 1: SCOPE** - Identify feature, find files, understand purpose.\r\n**Phase 2: TRACE** - Map inbound dependencies (imports) and outbound (who imports this).\r\n**Phase 3: DIAGNOSE** - Risk tags: HIGH (public API/DB schema/security), MED (internal module), LOW (isolated file).\r\n**Phase 4: FIX** - Dependencies -> Types -> Logic -> Tests -> Integration. Fix one at a time, run tests after each.\r\n**Phase 5: VERIFY** - Feature tests -> referencing tests -> full suite.\r\n\r\n---\r\n\r\n## 9. PR Review (5-Axis + Anti-Rationalization)\r\n\r\n**From: addyosmani/agent-skills -- code-review-and-quality**\r\n\r\n**Axis 1: Correctness** - Matches spec? Edge cases? Error paths? Tests pass?\r\n**Axis 2: Readability & Simplicity** - Descriptive names? Straightforward flow? Logical organization? No clever tricks? Lines can be reduced? Abstractions earning complexity?\r\n**Axis 3: Architecture** - Fits system design? Clean boundaries? No circular deps? Appropriate abstraction?\r\n**Axis 4: Security** - Input validated? Secrets safe? Auth checked? SQL parameterized? XSS prevented?\r\n**Axis 5: Performance** - N+1 queries? Large object allocations? Uncached hot paths?\r\n\r\n**Output Format:** Blast radius, per-axis assessment, severity labels (CRITICAL/REQUIRED/NIT), verdict (Approve/Request changes).\r\n\r\n**Anti-Rationalization:** 9-item table covering \"It works, good enough\", \"I wrote it, I know it is correct\", \"Clean up later\", \"AI-generated code is fine\", \"Tests pass\", \"Refactor makes it cleaner\", \"Just a small addition\", \"Just a version bump\".\r\n\r\n---\r\n\r\n## 10. Code Simplification\r\n\r\n**From: addyosmani/agent-skills -- code-simplification**\r\n\r\n**Principles:** Chestertons Fence, Rule of 500 (>500 lines = decompose), reduce complexity not relocate it.\r\n\r\n**Checklist:** Dead code? Conditionals can be simplified? Duplicate code? Complex expressions named? Nesting flattened? Single responsibility? Abstraction worth it? More code deleted than added?\r\n\r\n---\r\n\r\n## 11. Security Hardening\r\n\r\n**From: addyosmani/agent-skills -- security-and-hardening**\r\n\r\n**OWASP Top 10 Prevention:** SQL injection, XSS, auth, authorization, sensitive data, config security, dependency scanning, logging.\r\n\r\n**3-Tier Boundary:** External (untrusted, validate all) -> Service (semi-trusted, auth) -> Internal (trusted, business logic).\r\n\r\n---\r\n\r\n## 12. Performance Optimization\r\n\r\n**From: addyosmani/agent-skills -- performance-optimization**\r\n\r\n**Measure First, Optimize Second:** Baseline -> Hypothesize -> Validate -> Optimize -> Verify -> Repeat.\r\n\r\n**Checklist:** N+1 queries? Repeated computation? Large objects? Sync blocking? Caching? Lazy loading? Bundle size? Indexes? Connection pool?\r\n\r\n---\r\n\r\n## 13. Ship Gate and Deployment\r\n\r\n**From: addyosmani/agent-skills -- shipping-and-launch**\r\n\r\n**Pre-Launch Checklist:** All tests pass, code review approved, no P0/P1 vulns, CHANGELOG updated, version bumped, DB migrations forward-compatible, rollback plan, monitoring configured, docs updated, performance baseline, feature flags, staged rollout plan.\r\n\r\n---\r\n\r\n## 14. Git Workflow and Versioning\r\n\r\n**From: addyosmani/agent-skills -- git-workflow-and-versioning**\r\n\r\n**Principles:** Trunk-based development, atomic commits, ~100 lines per PR, commit as save point.\r\n\r\n**Convention:** <type>: <description> (feat/fix/refactor/chore/docs/test/ci)\r\n\r\n**Anti-Rationalization:** \"Commit first, organize later\" -> commit history IS code history. \"One PR for everything\" -> no one reviews large PRs. \"Long feature branch is fine\" -> merge hell.\r\n\r\n---\r\n\r\n## 15. CI/CD Pipeline and Automation\r\n\r\n**From: addyosmani/agent-skills -- ci-cd-and-automation**\r\n\r\n**Stages:** Lint -> Type check -> Unit test -> Integration test -> Build -> Security scan -> Deploy\r\n\r\n**Gates:** Lint 0 errors (block), Unit test 100% (block), Coverage >=80% (block), Security scan 0 critical (block), Build success (block).\r\n\r\n---\r\n\r\n## 16. API Design Review\r\n\r\n**REST:** kebab-case plural nouns (/api/v1/users). HTTP methods: GET (retrieve), POST (create), PUT (replace), PATCH (partial), DELETE (remove).\r\n\r\n**5-Dimension Score:** Consistency (30%), Documentation (20%), Security (20%), Usability (15%), Performance (15%).\r\n\r\n---\r\n\r\n## 17. Database Design\r\n\r\n**Principles:** Plural table names, UUID PK, created_at/updated_at, soft delete optional, indexes on query conditions, explicit FKs, forward-compatible migrations.\r\n\r\n**Performance Checklist:** Indexes used? N+1 queries? Reasonable joins? Cursor pagination? Correct transaction scope?\r\n\r\n---\r\n\r\n## 18. Observability Design\r\n\r\n**Three Pillars:** Structured logging, business metrics (latency/error rate/throughput), distributed tracing.\r\n\r\n**Health Endpoints:** GET /health (liveness), GET /health/ready (readiness), GET /health/debug (internal only).\r\n\r\n---\r\n\r\n## 19. Code Migration\r\n\r\n**Strategies:** Direct replacement (high risk, small module), Parallel run (medium, need rollback), Gradual (low, large system), Abstraction layer (low, dual maintenance).\r\n\r\n**Flow:** Inventory -> Impact analysis -> Compatibility layer -> Execute -> Verify -> Cleanup\r\n\r\n---\r\n\r\n## 20. Tech Debt Tracking\r\n\r\n**Classification:** Architecture (HIGH), Code quality (MED), Testing (HIGH), Documentation (LOW), Infrastructure (MED).\r\n\r\n**Entry Format:** Type, Location, Description, Impact, Estimate, Created.\r\n\r\n---\r\n\r\n## 21. De-AI-Writing Check\r\n\r\n**Tier 1 (Always Flag):** leverage/use, utilize/utilize, implement/build, nevertheless/but, furthermore/and, commence/start, endeavor/try.\r\n\r\n**Tier 2 (Cluster Flag):** robust/reliable, seamless/smooth, facilitate/help, granular/detailed, holistic/complete, ecosystem/system.\r\n\r\n**Tier 3 (High Density):** cutting-edge/modern, state-of-the-art/best available, game-changer/big change.\r\n\r\n**Detection Flow:** First pass (flag all Tier 1) -> Structure check -> Rhythm check -> Second pass -> Output\r\n\r\n---\r\n\r\n## 22. Self Evaluation\r\n\r\n**Two-Axis:** Task Difficulty (Low/Medium/High) x Execution Quality (Poor/Adequate/Strong) -> Score 1-5.\r\n\r\n**Forced Counter-Argument:** Before final score, write reasons for lower, reasons for higher, then resolve.\r\n\r\n**Inflation Detection:** 4+ of last 5 same score -> flag inflation. 3 consecutive 4s -> stricter evaluation.\r\n\r\n---\r\n\r\n## 23. Language Quick Reference\r\n\r\n**Python:** snake_case, type hints, pathlib, f-strings, try/except/raise.\r\n**TypeScript:** camelCase, PascalCase for types, interfaces, async/await with try/catch.\r\n**Go:** camelCase, capitalized exports, error wrapping with fmt.Errorf.%w.\r\n**PowerShell:** Verb-Noun naming, CmdletBinding, ErrorAction Stop.\r\n\r\n---\r\n\r\n## Appendix: Quick Reference\r\n\r\n### When to Use What\r\n\r\n| Scenario | Use |\r\n|----------|-----|\r\n| Write new code | Spec-Driven -> Plan -> TDD -> Incremental Impl |\r\n| Fix bugs | Focused-Fix 5-phase |\r\n| Review PR | 5-Axis PR Review |\r\n| Design API | API Design + Score |\r\n| Write tests | TDD + E2E silent-pass detection |\r\n| Migration | Migration flow |\r\n| CI/CD | Pipeline stages |\r\n| Database | Design principles |\r\n| Release | Ship gate checklist |\r\n| Tech debt | Debt tracking format |\r\n| Self-eval | 2-axis scoring |\r\n| De-AI-fy | Writing check |\r\n\r\n### Never Do\r\n\r\n1. Fix bugs without scoping first\r\n2. Write code without spec\r\n3. Merge without review\r\n4. Commit without tests\r\n5. Release without CHANGELOG\r\n6. Change API without impact assessment\r\n7. Dishonest self-eval\r\n8. Ship without de-AI-fying\n\nFile v6.1.1:_meta.json\n\n{\n  \"ownerId\": \"kn71mxvdsyxaq6jpehtw8pc8t183hwzn\",\n  \"slug\": \"dawn-code-master\",\n  \"version\": \"6.1.1\",\n  \"publishedAt\": 1791514057361\n}\n\nFile v6.1.1:skill-card.md\n\n## Description:\n\nGuides coding agents through specification, implementation, testing, review, and release with structured quality checks.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[chen6896qqwee](https://clawhub.ai/user/chen6896qqwee)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers use this skill to guide coding agents through scoped fixes, feature development, API design, testing, code review, and release preparation.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Broad coding workflows can change project files or run commands beyond the intended task.\n\nMitigation: Use a bounded workspace and review proposed commands, file changes, and commits before execution.\n\n## Reference(s):\n\n- [代码大师｜编程铁律 on ClawHub](https://clawhub.ai/chen6896qqwee/skills/dawn-code-master)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Code, Markdown, Shell commands, Configuration instructions]\n\n**Output Format:** [Text and Markdown, with code or commands as needed]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May guide workspace file changes, tests, reviews, and release checks.]\n\n## Skill Version(s):\n\n6.1.1 (source: ClawHub release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v6.1.0: 3 files, 8427 bytes\n\nFiles: skill-card.md (2117b), SKILL.md (15263b), _meta.json (135b)\n\nFile v6.1.0:SKILL.md\n\n---\r\nname: dawn-code-master\r\ndescription: >\r\n  Dawn Code Master v6.0 -- 综合编码技能，整合了80k star agent-skills、23k star claude-skills + yao-meta-skill、ratel等顶级技能集。\r\n  写代码、修bug、审PR、做设计，按这个来。\r\nmetadata:\r\n  version: 6.1.0\r\n  sources:\r\n    - focused-fix (alirezarezvani/claude-skills)\r\n    - pr-review-expert (alirezarezvani/claude-skills)\r\n    - spec-driven-workflow (alirezarezvani/claude-skills)\r\n    - api-design-reviewer (alirezarezvani/claude-skills)\r\n    - api-test-suite-builder (alirezarezvani/claude-skills)\r\n    - self-eval (alirezarezvani/claude-skills)\r\n    - skill-tester (alirezarezvani/claude-skills)\r\n    - mcp-server-builder (alirezarezvani/claude-skills)\r\n    - e2e-skills (voidmatcha/e2e-skills)\r\n    - avoid-ai-writing (conorbronsdon/avoid-ai-writing)\r\n    - cc-skills-golang (samber/cc-skills-golang)\r\n    - agentic-stack (codejunkie99/agentic-stack)\r\n    - antigravity-skills (krishnakanthb13)\r\n    - codebase-onboarding / migration-architect / ci-cd-pipeline-builder\r\n    - performance-profiler / database-designer / sql-database-assistant\r\n    - observability-designer / ship-gate / tech-debt-tracker\r\n    - changelog-generator / dependency-auditor / git-worktree-manager\r\n    - monorepo-navigator / rag-architect / agent-designer / agent-workflow-designer\r\n    - dawn-code-master v4.0 (local)\r\n    - agent-skills (addyosmani/agent-skills, 80k star)\r\n    - yao-meta-skill (yaojingang/yao-meta-skill, 2.1k star)\r\n    - ratel-ai/ratel (ratel-ai/ratel, 351 star)\r\n    - context-engineering-kit (NeoLabHQ/context-engineering-kit, 1.3k star)\r\n    - claude-skills (borghei/Claude-Skills, 411 star)\r\n  dawn:\r\n    requires:\r\n      bins: [python, node, pwsh, git]\r\n    permissions:\r\n      - exec: [python, node, ruff, black, pytest, pwsh, git]\r\n      - filesystem: [read/write workspace]\r\n---\r\n\r\n# Dawn Code Master v6.0\r\n\r\n**50+ 顶级编码技能集成 + 全生命周期工作流 + 反合理化验证门禁。** 写代码、修bug、审PR、做设计，按这个来。\r\n\r\n---\r\n\r\n## 0. Skill Router\r\n\r\n### Core Operating Behaviors\r\n\r\n1. Surface Assumptions - Before implementing, explicitly state assumptions\r\n2. Manage Confusion - Stop, name confusion, present tradeoff, wait for resolution\r\n3. Push Back - Point out problems directly, quantify downsides, propose alternatives\r\n\r\n### When to Use What\r\n\r\n| Phase | Task | Skill |\r\n|-------|------|-------|\r\n| Define | Dont know what you want | interview-me |\r\n| Define | Rough concept needs refining | [s2] Spec-Driven Dev |\r\n| Plan | Have spec, need tasks | [s3] Planning |\r\n| Build | Implementing code | [s4] Incremental Impl |\r\n| Build | UI work | Frontend principles |\r\n| Build | API work | [s16] API Design |\r\n| Build | Need better context | [s6] Context Eng |\r\n| Build | High stakes / unfamiliar code | [s7] Doubt-Driven |\r\n| Verify | Writing/running tests | [s5] TDD |\r\n| Verify | Bug fixing | [s8] Focused-Fix |\r\n| Review | Reviewing code | [s9] PR Review |\r\n| Review | Too complex | [s10] Code Simplification |\r\n| Review | Security concerns | [s11] Security |\r\n| Review | Performance concerns | [s12] Performance |\r\n| Ship | Committing/branching | [s14] Git Workflow |\r\n| Ship | CI/CD pipeline | [s15] CI/CD |\r\n| Ship | Deploying/launching | [s13] Ship Gate |\r\n| Maintain | Migration/deprecation | [s19] Migration |\r\n| Maintain | Tech debt | [s20] Tech Debt |\r\n| Docs | Writing docs/ADRs | Doc standards |\r\n| Ops | Logs/metrics/alerts | [s18] Observability |\r\n\r\n---\r\n\r\n## 1. Coding Laws\r\n\r\n**Pre-Commit Checklist:** syntax clean, tests pass, type hints, no bare except, no hardcoded secrets, f-string (not format()), pathlib (not os.path), docstrings, functions <= 30 lines.\r\n\r\n**File Structure:** <= 300 lines per file, <= 30 lines per function, one thing per function.\r\n\r\n**Error Handling:** async ops must have error handling, network requests must timeout, user input must be validated, external deps assumed to fail.\r\n\r\n**Anti-Rationalization:**\r\n\r\n| Rationalization | Reality |\r\n|----------------|---------|\r\n| \"Write now, refactor later\" | Later never comes. |\r\n| \"Just one line, no need to check\" | Small diffs push files past boundaries. |\r\n| \"AI-generated code is probably fine\" | AI code needs more scrutiny. |\r\n| \"Tests pass, it is good\" | Tests dont catch architecture or security issues. |\r\n\r\n---\r\n\r\n## 2. Spec-Driven Development\r\n\r\n**Law: NO CODE WITHOUT AN APPROVED SPEC.**\r\n\r\n**9 Mandatory Sections:** Title/Metadata, Context, Functional Requirements (RFC 2119), Non-Functional Requirements, Acceptance Criteria, Edge Cases, API Contract, Data Model, Out of Scope.\r\n\r\n**4-Phase Gated Workflow:** SPECIFY -> PLAN -> TASKS -> IMPLEMENT (each reviewed by human)\r\n\r\n**Stop-and-Ask Rules:** Scope creep, >30% ambiguity, breaking changes, security implications, unknown performance.\r\n\r\n**Anti-Rationalization:**\r\n| Rationalization | Reality |\r\n| \"Clear requirements, no spec needed\" | Clear reqs take 5 min. Unclear ones need it. |\r\n| \"Quick prototype first\" | The prototype is the final product. |\r\n| \"Specs are too slow\" | Specs save 10x refactoring time. |\r\n| \"I will document later\" | Later never comes. |\r\n\r\n---\r\n\r\n## 3. Planning and Task Breakdown\r\n\r\nEach task <= 30 min, independently testable, with clear AC. Slicing strategies: Vertical (preferred), Contract-First, Risk-First.\r\n\r\n---\r\n\r\n## 4. Incremental Implementation\r\n\r\n**Cycle:** Implement -> Test -> Verify -> Commit -> Next slice\r\n\r\n**Anti-Rationalization:** \"Writing everything at once is faster\" -> 500 lines untested = 10x debugging. \"Just a few lines, no need to commit separately\" -> atomic commits make rollback/review clean. \"I will test later\" -> never happens.\r\n\r\n---\r\n\r\n## 5. Test-Driven Development + E2E\r\n\r\n**TDD Cycle:** RED (write failing test) -> GREEN (min code to pass) -> REFACTOR (clean up)\r\n\r\n**Prove-It Pattern:** Write test reproducing bug (RED) -> Fix bug (GREEN) -> Write regression test -> Refactor\r\n\r\n**E2E Silent-Pass Detection:** toBeDefined()/not.toBeNull() on Locator always passes. Use toBeVisible()/toHaveText().\r\n\r\n**P0 Anti-patterns:** toBeDefined() on Locator, forgotten it.only, empty catch blocks, un-awaited async.\r\n\r\n**Anti-Rationalization:** \"Tests pass, it is good\" -> tests dont catch architecture/security. \"AI-generated code is fine\" -> needs more scrutiny. \"Write code first, add tests later\" -> tests what code does, not what it should do.\r\n\r\n---\r\n\r\n## 6. Context Engineering\r\n\r\n**From: ratel-ai/ratel (351 star) + NeoLabHQ/context-engineering-kit (1.3k star)**\r\n\r\n**Core Principle: Progressive Disclosure** - Load only what each turn needs.\r\n\r\n**Context Hierarchy:** 1. Rules Files (persistent) -> 2. Spec/Arch (per feature) -> 3. Source Files (per task) -> 4. Error Output (per iteration) -> 5. History (accumulates, compacts)\r\n\r\n**Ratel-Style Catalog:** All skills in SkillCatalog, tools in ToolCatalog. Each turn loads only matching ones.\r\n\r\n**Anti-Rationalization:** \"All rules in system prompt\" -> noise reduces accuracy. \"Same project, no need to separate\" -> different modules need different context. \"Write rules once\" -> projects evolve.\r\n\r\n---\r\n\r\n## 7. Doubt-Driven Development\r\n\r\n**From: addyosmani/agent-skills -- doubt-driven-development**\r\n\r\nA confident answer is not a correct one. For non-trivial decisions (branching logic, crossing boundaries, unverifiable assertions, irreversible blast radius).\r\n\r\n**Doubt Cycle:** 1. CLAIM (write claim + why matters) -> 2. EXTRACT (isolate artifact) -> 3. DOUBT (fresh-context adversarial review) -> 4. RECONCILE (classify findings) -> 5. STOP (trivial findings, 3 cycles, or user override)\r\n\r\n**Anti-Rationalization:** \"This is obviously correct\" -> hides most dangerous assumptions. \"Tests pass\" -> only cover known scenarios. \"No time\" -> doubt cycle is faster than debugging.\r\n\r\n---\r\n\r\n## 8. Bug Fixing (Focused-Fix)\r\n\r\n**Law: NO FIXES WITHOUT SCOPE -> TRACE -> DIAGNOSE FIRST.**\r\n\r\n**Phase 1: SCOPE** - Identify feature, find files, understand purpose.\r\n**Phase 2: TRACE** - Map inbound dependencies (imports) and outbound (who imports this).\r\n**Phase 3: DIAGNOSE** - Risk tags: HIGH (public API/DB schema/security), MED (internal module), LOW (isolated file).\r\n**Phase 4: FIX** - Dependencies -> Types -> Logic -> Tests -> Integration. Fix one at a time, run tests after each.\r\n**Phase 5: VERIFY** - Feature tests -> referencing tests -> full suite.\r\n\r\n---\r\n\r\n## 9. PR Review (5-Axis + Anti-Rationalization)\r\n\r\n**From: addyosmani/agent-skills -- code-review-and-quality**\r\n\r\n**Axis 1: Correctness** - Matches spec? Edge cases? Error paths? Tests pass?\r\n**Axis 2: Readability & Simplicity** - Descriptive names? Straightforward flow? Logical organization? No clever tricks? Lines can be reduced? Abstractions earning complexity?\r\n**Axis 3: Architecture** - Fits system design? Clean boundaries? No circular deps? Appropriate abstraction?\r\n**Axis 4: Security** - Input validated? Secrets safe? Auth checked? SQL parameterized? XSS prevented?\r\n**Axis 5: Performance** - N+1 queries? Large object allocations? Uncached hot paths?\r\n\r\n**Output Format:** Blast radius, per-axis assessment, severity labels (CRITICAL/REQUIRED/NIT), verdict (Approve/Request changes).\r\n\r\n**Anti-Rationalization:** 9-item table covering \"It works, good enough\", \"I wrote it, I know it is correct\", \"Clean up later\", \"AI-generated code is fine\", \"Tests pass\", \"Refactor makes it cleaner\", \"Just a small addition\", \"Just a version bump\".\r\n\r\n---\r\n\r\n## 10. Code Simplification\r\n\r\n**From: addyosmani/agent-skills -- code-simplification**\r\n\r\n**Principles:** Chestertons Fence, Rule of 500 (>500 lines = decompose), reduce complexity not relocate it.\r\n\r\n**Checklist:** Dead code? Conditionals can be simplified? Duplicate code? Complex expressions named? Nesting flattened? Single responsibility? Abstraction worth it? More code deleted than added?\r\n\r\n---\r\n\r\n## 11. Security Hardening\r\n\r\n**From: addyosmani/agent-skills -- security-and-hardening**\r\n\r\n**OWASP Top 10 Prevention:** SQL injection, XSS, auth, authorization, sensitive data, config security, dependency scanning, logging.\r\n\r\n**3-Tier Boundary:** External (untrusted, validate all) -> Service (semi-trusted, auth) -> Internal (trusted, business logic).\r\n\r\n---\r\n\r\n## 12. Performance Optimization\r\n\r\n**From: addyosmani/agent-skills -- performance-optimization**\r\n\r\n**Measure First, Optimize Second:** Baseline -> Hypothesize -> Validate -> Optimize -> Verify -> Repeat.\r\n\r\n**Checklist:** N+1 queries? Repeated computation? Large objects? Sync blocking? Caching? Lazy loading? Bundle size? Indexes? Connection pool?\r\n\r\n---\r\n\r\n## 13. Ship Gate and Deployment\r\n\r\n**From: addyosmani/agent-skills -- shipping-and-launch**\r\n\r\n**Pre-Launch Checklist:** All tests pass, code review approved, no P0/P1 vulns, CHANGELOG updated, version bumped, DB migrations forward-compatible, rollback plan, monitoring configured, docs updated, performance baseline, feature flags, staged rollout plan.\r\n\r\n---\r\n\r\n## 14. Git Workflow and Versioning\r\n\r\n**From: addyosmani/agent-skills -- git-workflow-and-versioning**\r\n\r\n**Principles:** Trunk-based development, atomic commits, ~100 lines per PR, commit as save point.\r\n\r\n**Convention:** <type>: <description> (feat/fix/refactor/chore/docs/test/ci)\r\n\r\n**Anti-Rationalization:** \"Commit first, organize later\" -> commit history IS code history. \"One PR for everything\" -> no one reviews large PRs. \"Long feature branch is fine\" -> merge hell.\r\n\r\n---\r\n\r\n## 15. CI/CD Pipeline and Automation\r\n\r\n**From: addyosmani/agent-skills -- ci-cd-and-automation**\r\n\r\n**Stages:** Lint -> Type check -> Unit test -> Integration test -> Build -> Security scan -> Deploy\r\n\r\n**Gates:** Lint 0 errors (block), Unit test 100% (block), Coverage >=80% (block), Security scan 0 critical (block), Build success (block).\r\n\r\n---\r\n\r\n## 16. API Design Review\r\n\r\n**REST:** kebab-case plural nouns (/api/v1/users). HTTP methods: GET (retrieve), POST (create), PUT (replace), PATCH (partial), DELETE (remove).\r\n\r\n**5-Dimension Score:** Consistency (30%), Documentation (20%), Security (20%), Usability (15%), Performance (15%).\r\n\r\n---\r\n\r\n## 17. Database Design\r\n\r\n**Principles:** Plural table names, UUID PK, created_at/updated_at, soft delete optional, indexes on query conditions, explicit FKs, forward-compatible migrations.\r\n\r\n**Performance Checklist:** Indexes used? N+1 queries? Reasonable joins? Cursor pagination? Correct transaction scope?\r\n\r\n---\r\n\r\n## 18. Observability Design\r\n\r\n**Three Pillars:** Structured logging, business metrics (latency/error rate/throughput), distributed tracing.\r\n\r\n**Health Endpoints:** GET /health (liveness), GET /health/ready (readiness), GET /health/debug (internal only).\r\n\r\n---\r\n\r\n## 19. Code Migration\r\n\r\n**Strategies:** Direct replacement (high risk, small module), Parallel run (medium, need rollback), Gradual (low, large system), Abstraction layer (low, dual maintenance).\r\n\r\n**Flow:** Inventory -> Impact analysis -> Compatibility layer -> Execute -> Verify -> Cleanup\r\n\r\n---\r\n\r\n## 20. Tech Debt Tracking\r\n\r\n**Classification:** Architecture (HIGH), Code quality (MED), Testing (HIGH), Documentation (LOW), Infrastructure (MED).\r\n\r\n**Entry Format:** Type, Location, Description, Impact, Estimate, Created.\r\n\r\n---\r\n\r\n## 21. De-AI-Writing Check\r\n\r\n**Tier 1 (Always Flag):** leverage/use, utilize/utilize, implement/build, nevertheless/but, furthermore/and, commence/start, endeavor/try.\r\n\r\n**Tier 2 (Cluster Flag):** robust/reliable, seamless/smooth, facilitate/help, granular/detailed, holistic/complete, ecosystem/system.\r\n\r\n**Tier 3 (High Density):** cutting-edge/modern, state-of-the-art/best available, game-changer/big change.\r\n\r\n**Detection Flow:** First pass (flag all Tier 1) -> Structure check -> Rhythm check -> Second pass -> Output\r\n\r\n---\r\n\r\n## 22. Self Evaluation\r\n\r\n**Two-Axis:** Task Difficulty (Low/Medium/High) x Execution Quality (Poor/Adequate/Strong) -> Score 1-5.\r\n\r\n**Forced Counter-Argument:** Before final score, write reasons for lower, reasons for higher, then resolve.\r\n\r\n**Inflation Detection:** 4+ of last 5 same score -> flag inflation. 3 consecutive 4s -> stricter evaluation.\r\n\r\n---\r\n\r\n## 23. Language Quick Reference\r\n\r\n**Python:** snake_case, type hints, pathlib, f-strings, try/except/raise.\r\n**TypeScript:** camelCase, PascalCase for types, interfaces, async/await with try/catch.\r\n**Go:** camelCase, capitalized exports, error wrapping with fmt.Errorf.%w.\r\n**PowerShell:** Verb-Noun naming, CmdletBinding, ErrorAction Stop.\r\n\r\n---\r\n\r\n## Appendix: Quick Reference\r\n\r\n### When to Use What\r\n\r\n| Scenario | Use |\r\n|----------|-----|\r\n| Write new code | Spec-Driven -> Plan -> TDD -> Incremental Impl |\r\n| Fix bugs | Focused-Fix 5-phase |\r\n| Review PR | 5-Axis PR Review |\r\n| Design API | API Design + Score |\r\n| Write tests | TDD + E2E silent-pass detection |\r\n| Migration | Migration flow |\r\n| CI/CD | Pipeline stages |\r\n| Database | Design principles |\r\n| Release | Ship gate checklist |\r\n| Tech debt | Debt tracking format |\r\n| Self-eval | 2-axis scoring |\r\n| De-AI-fy | Writing check |\r\n\r\n### Never Do\r\n\r\n1. Fix bugs without scoping first\r\n2. Write code without spec\r\n3. Merge without review\r\n4. Commit without tests\r\n5. Release without CHANGELOG\r\n6. Change API without impact assessment\r\n7. Dishonest self-eval\r\n8. Ship without de-AI-fying\n\nFile v6.1.0:_meta.json\n\n{\n  \"ownerId\": \"kn71mxvdsyxaq6jpehtw8pc8t183hwzn\",\n  \"slug\": \"dawn-code-master\",\n  \"version\": \"6.1.0\",\n  \"publishedAt\": 1785120937149\n}\n\nFile v6.1.0:skill-card.md\n\n## Description:\n\nDawn Code Master is a broad coding workflow skill that guides agents through specification, planning, implementation, testing, review, security, performance, deployment, maintenance, and documentation tasks.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[chen6896qqwee](https://clawhub.ai/user/chen6896qqwee)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and coding agents use this skill to structure software engineering work across requirements, planning, coding, testing, review, security, deployment, and maintenance. It is best suited to teams or users who want a comprehensive, process-heavy coding workflow.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill applies a broad, opinionated engineering process across many coding tasks.\n\nMitigation: Use it when specification, testing, review, and release gates fit the task; choose a narrower skill for lightweight or narrowly scoped work.\n\nRisk: The skill declares normal workspace read/write access and common developer-tool execution permissions.\n\nMitigation: Review proposed file edits and commands before execution, and run the skill in a least-privileged workspace or sandbox when possible.\n\n## Reference(s):\n\n- [Dawn Code Master on ClawHub](https://clawhub.ai/chen6896qqwee/skills/dawn-code-master)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Text, Markdown, Code, Shell commands, Configuration]\n\n**Output Format:** [Markdown or text guidance with code, command, and configuration snippets when relevant]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May require workspace read/write access and developer tools such as python, node, pwsh, git, ruff, black, and pytest.]\n\n## Skill Version(s):\n\n6.1.0 (source: server release metadata and SKILL.md frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v6.0.0: 3 files, 8350 bytes\n\nFiles: skill-card.md (1983b), SKILL.md (15263b), _meta.json (135b)\n\nFile v6.0.0:SKILL.md\n\n---\r\nname: dawn-code-master\r\ndescription: >\r\n  Dawn Code Master v6.0 -- 综合编码技能，整合了80k star agent-skills、23k star claude-skills + yao-meta-skill、ratel等顶级技能集。\r\n  写代码、修bug、审PR、做设计，按这个来。\r\nmetadata:\r\n  version: 6.0.0\r\n  sources:\r\n    - focused-fix (alirezarezvani/claude-skills)\r\n    - pr-review-expert (alirezarezvani/claude-skills)\r\n    - spec-driven-workflow (alirezarezvani/claude-skills)\r\n    - api-design-reviewer (alirezarezvani/claude-skills)\r\n    - api-test-suite-builder (alirezarezvani/claude-skills)\r\n    - self-eval (alirezarezvani/claude-skills)\r\n    - skill-tester (alirezarezvani/claude-skills)\r\n    - mcp-server-builder (alirezarezvani/claude-skills)\r\n    - e2e-skills (voidmatcha/e2e-skills)\r\n    - avoid-ai-writing (conorbronsdon/avoid-ai-writing)\r\n    - cc-skills-golang (samber/cc-skills-golang)\r\n    - agentic-stack (codejunkie99/agentic-stack)\r\n    - antigravity-skills (krishnakanthb13)\r\n    - codebase-onboarding / migration-architect / ci-cd-pipeline-builder\r\n    - performance-profiler / database-designer / sql-database-assistant\r\n    - observability-designer / ship-gate / tech-debt-tracker\r\n    - changelog-generator / dependency-auditor / git-worktree-manager\r\n    - monorepo-navigator / rag-architect / agent-designer / agent-workflow-designer\r\n    - dawn-code-master v4.0 (local)\r\n    - agent-skills (addyosmani/agent-skills, 80k star)\r\n    - yao-meta-skill (yaojingang/yao-meta-skill, 2.1k star)\r\n    - ratel-ai/ratel (ratel-ai/ratel, 351 star)\r\n    - context-engineering-kit (NeoLabHQ/context-engineering-kit, 1.3k star)\r\n    - claude-skills (borghei/Claude-Skills, 411 star)\r\n  dawn:\r\n    requires:\r\n      bins: [python, node, pwsh, git]\r\n    permissions:\r\n      - exec: [python, node, ruff, black, pytest, pwsh, git]\r\n      - filesystem: [read/write workspace]\r\n---\r\n\r\n# Dawn Code Master v6.0\r\n\r\n**50+ 顶级编码技能集成 + 全生命周期工作流 + 反合理化验证门禁。** 写代码、修bug、审PR、做设计，按这个来。\r\n\r\n---\r\n\r\n## 0. Skill Router\r\n\r\n### Core Operating Behaviors\r\n\r\n1. Surface Assumptions - Before implementing, explicitly state assumptions\r\n2. Manage Confusion - Stop, name confusion, present tradeoff, wait for resolution\r\n3. Push Back - Point out problems directly, quantify downsides, propose alternatives\r\n\r\n### When to Use What\r\n\r\n| Phase | Task | Skill |\r\n|-------|------|-------|\r\n| Define | Dont know what you want | interview-me |\r\n| Define | Rough concept needs refining | [s2] Spec-Driven Dev |\r\n| Plan | Have spec, need tasks | [s3] Planning |\r\n| Build | Implementing code | [s4] Incremental Impl |\r\n| Build | UI work | Frontend principles |\r\n| Build | API work | [s16] API Design |\r\n| Build | Need better context | [s6] Context Eng |\r\n| Build | High stakes / unfamiliar code | [s7] Doubt-Driven |\r\n| Verify | Writing/running tests | [s5] TDD |\r\n| Verify | Bug fixing | [s8] Focused-Fix |\r\n| Review | Reviewing code | [s9] PR Review |\r\n| Review | Too complex | [s10] Code Simplification |\r\n| Review | Security concerns | [s11] Security |\r\n| Review | Performance concerns | [s12] Performance |\r\n| Ship | Committing/branching | [s14] Git Workflow |\r\n| Ship | CI/CD pipeline | [s15] CI/CD |\r\n| Ship | Deploying/launching | [s13] Ship Gate |\r\n| Maintain | Migration/deprecation | [s19] Migration |\r\n| Maintain | Tech debt | [s20] Tech Debt |\r\n| Docs | Writing docs/ADRs | Doc standards |\r\n| Ops | Logs/metrics/alerts | [s18] Observability |\r\n\r\n---\r\n\r\n## 1. Coding Laws\r\n\r\n**Pre-Commit Checklist:** syntax clean, tests pass, type hints, no bare except, no hardcoded secrets, f-string (not format()), pathlib (not os.path), docstrings, functions <= 30 lines.\r\n\r\n**File Structure:** <= 300 lines per file, <= 30 lines per function, one thing per function.\r\n\r\n**Error Handling:** async ops must have error handling, network requests must timeout, user input must be validated, external deps assumed to fail.\r\n\r\n**Anti-Rationalization:**\r\n\r\n| Rationalization | Reality |\r\n|----------------|---------|\r\n| \"Write now, refactor later\" | Later never comes. |\r\n| \"Just one line, no need to check\" | Small diffs push files past boundaries. |\r\n| \"AI-generated code is probably fine\" | AI code needs more scrutiny. |\r\n| \"Tests pass, it is good\" | Tests dont catch architecture or security issues. |\r\n\r\n---\r\n\r\n## 2. Spec-Driven Development\r\n\r\n**Law: NO CODE WITHOUT AN APPROVED SPEC.**\r\n\r\n**9 Mandatory Sections:** Title/Metadata, Context, Functional Requirements (RFC 2119), Non-Functional Requirements, Acceptance Criteria, Edge Cases, API Contract, Data Model, Out of Scope.\r\n\r\n**4-Phase Gated Workflow:** SPECIFY -> PLAN -> TASKS -> IMPLEMENT (each reviewed by human)\r\n\r\n**Stop-and-Ask Rules:** Scope creep, >30% ambiguity, breaking changes, security implications, unknown performance.\r\n\r\n**Anti-Rationalization:**\r\n| Rationalization | Reality |\r\n| \"Clear requirements, no spec needed\" | Clear reqs take 5 min. Unclear ones need it. |\r\n| \"Quick prototype first\" | The prototype is the final product. |\r\n| \"Specs are too slow\" | Specs save 10x refactoring time. |\r\n| \"I will document later\" | Later never comes. |\r\n\r\n---\r\n\r\n## 3. Planning and Task Breakdown\r\n\r\nEach task <= 30 min, independently testable, with clear AC. Slicing strategies: Vertical (preferred), Contract-First, Risk-First.\r\n\r\n---\r\n\r\n## 4. Incremental Implementation\r\n\r\n**Cycle:** Implement -> Test -> Verify -> Commit -> Next slice\r\n\r\n**Anti-Rationalization:** \"Writing everything at once is faster\" -> 500 lines untested = 10x debugging. \"Just a few lines, no need to commit separately\" -> atomic commits make rollback/review clean. \"I will test later\" -> never happens.\r\n\r\n---\r\n\r\n## 5. Test-Driven Development + E2E\r\n\r\n**TDD Cycle:** RED (write failing test) -> GREEN (min code to pass) -> REFACTOR (clean up)\r\n\r\n**Prove-It Pattern:** Write test reproducing bug (RED) -> Fix bug (GREEN) -> Write regression test -> Refactor\r\n\r\n**E2E Silent-Pass Detection:** toBeDefined()/not.toBeNull() on Locator always passes. Use toBeVisible()/toHaveText().\r\n\r\n**P0 Anti-patterns:** toBeDefined() on Locator, forgotten it.only, empty catch blocks, un-awaited async.\r\n\r\n**Anti-Rationalization:** \"Tests pass, it is good\" -> tests dont catch architecture/security. \"AI-generated code is fine\" -> needs more scrutiny. \"Write code first, add tests later\" -> tests what code does, not what it should do.\r\n\r\n---\r\n\r\n## 6. Context Engineering\r\n\r\n**From: ratel-ai/ratel (351 star) + NeoLabHQ/context-engineering-kit (1.3k star)**\r\n\r\n**Core Principle: Progressive Disclosure** - Load only what each turn needs.\r\n\r\n**Context Hierarchy:** 1. Rules Files (persistent) -> 2. Spec/Arch (per feature) -> 3. Source Files (per task) -> 4. Error Output (per iteration) -> 5. History (accumulates, compacts)\r\n\r\n**Ratel-Style Catalog:** All skills in SkillCatalog, tools in ToolCatalog. Each turn loads only matching ones.\r\n\r\n**Anti-Rationalization:** \"All rules in system prompt\" -> noise reduces accuracy. \"Same project, no need to separate\" -> different modules need different context. \"Write rules once\" -> projects evolve.\r\n\r\n---\r\n\r\n## 7. Doubt-Driven Development\r\n\r\n**From: addyosmani/agent-skills -- doubt-driven-development**\r\n\r\nA confident answer is not a correct one. For non-trivial decisions (branching logic, crossing boundaries, unverifiable assertions, irreversible blast radius).\r\n\r\n**Doubt Cycle:** 1. CLAIM (write claim + why matters) -> 2. EXTRACT (isolate artifact) -> 3. DOUBT (fresh-context adversarial review) -> 4. RECONCILE (classify findings) -> 5. STOP (trivial findings, 3 cycles, or user override)\r\n\r\n**Anti-Rationalization:** \"This is obviously correct\" -> hides most dangerous assumptions. \"Tests pass\" -> only cover known scenarios. \"No time\" -> doubt cycle is faster than debugging.\r\n\r\n---\r\n\r\n## 8. Bug Fixing (Focused-Fix)\r\n\r\n**Law: NO FIXES WITHOUT SCOPE -> TRACE -> DIAGNOSE FIRST.**\r\n\r\n**Phase 1: SCOPE** - Identify feature, find files, understand purpose.\r\n**Phase 2: TRACE** - Map inbound dependencies (imports) and outbound (who imports this).\r\n**Phase 3: DIAGNOSE** - Risk tags: HIGH (public API/DB schema/security), MED (internal module), LOW (isolated file).\r\n**Phase 4: FIX** - Dependencies -> Types -> Logic -> Tests -> Integration. Fix one at a time, run tests after each.\r\n**Phase 5: VERIFY** - Feature tests -> referencing tests -> full suite.\r\n\r\n---\r\n\r\n## 9. PR Review (5-Axis + Anti-Rationalization)\r\n\r\n**From: addyosmani/agent-skills -- code-review-and-quality**\r\n\r\n**Axis 1: Correctness** - Matches spec? Edge cases? Error paths? Tests pass?\r\n**Axis 2: Readability & Simplicity** - Descriptive names? Straightforward flow? Logical organization? No clever tricks? Lines can be reduced? Abstractions earning complexity?\r\n**Axis 3: Architecture** - Fits system design? Clean boundaries? No circular deps? Appropriate abstraction?\r\n**Axis 4: Security** - Input validated? Secrets safe? Auth checked? SQL parameterized? XSS prevented?\r\n**Axis 5: Performance** - N+1 queries? Large object allocations? Uncached hot paths?\r\n\r\n**Output Format:** Blast radius, per-axis assessment, severity labels (CRITICAL/REQUIRED/NIT), verdict (Approve/Request changes).\r\n\r\n**Anti-Rationalization:** 9-item table covering \"It works, good enough\", \"I wrote it, I know it is correct\", \"Clean up later\", \"AI-generated code is fine\", \"Tests pass\", \"Refactor makes it cleaner\", \"Just a small addition\", \"Just a version bump\".\r\n\r\n---\r\n\r\n## 10. Code Simplification\r\n\r\n**From: addyosmani/agent-skills -- code-simplification**\r\n\r\n**Principles:** Chestertons Fence, Rule of 500 (>500 lines = decompose), reduce complexity not relocate it.\r\n\r\n**Checklist:** Dead code? Conditionals can be simplified? Duplicate code? Complex expressions named? Nesting flattened? Single responsibility? Abstraction worth it? More code deleted than added?\r\n\r\n---\r\n\r\n## 11. Security Hardening\r\n\r\n**From: addyosmani/agent-skills -- security-and-hardening**\r\n\r\n**OWASP Top 10 Prevention:** SQL injection, XSS, auth, authorization, sensitive data, config security, dependency scanning, logging.\r\n\r\n**3-Tier Boundary:** External (untrusted, validate all) -> Service (semi-trusted, auth) -> Internal (trusted, business logic).\r\n\r\n---\r\n\r\n## 12. Performance Optimization\r\n\r\n**From: addyosmani/agent-skills -- performance-optimization**\r\n\r\n**Measure First, Optimize Second:** Baseline -> Hypothesize -> Validate -> Optimize -> Verify -> Repeat.\r\n\r\n**Checklist:** N+1 queries? Repeated computation? Large objects? Sync blocking? Caching? Lazy loading? Bundle size? Indexes? Connection pool?\r\n\r\n---\r\n\r\n## 13. Ship Gate and Deployment\r\n\r\n**From: addyosmani/agent-skills -- shipping-and-launch**\r\n\r\n**Pre-Launch Checklist:** All tests pass, code review approved, no P0/P1 vulns, CHANGELOG updated, version bumped, DB migrations forward-compatible, rollback plan, monitoring configured, docs updated, performance baseline, feature flags, staged rollout plan.\r\n\r\n---\r\n\r\n## 14. Git Workflow and Versioning\r\n\r\n**From: addyosmani/agent-skills -- git-workflow-and-versioning**\r\n\r\n**Principles:** Trunk-based development, atomic commits, ~100 lines per PR, commit as save point.\r\n\r\n**Convention:** <type>: <description> (feat/fix/refactor/chore/docs/test/ci)\r\n\r\n**Anti-Rationalization:** \"Commit first, organize later\" -> commit history IS code history. \"One PR for everything\" -> no one reviews large PRs. \"Long feature branch is fine\" -> merge hell.\r\n\r\n---\r\n\r\n## 15. CI/CD Pipeline and Automation\r\n\r\n**From: addyosmani/agent-skills -- ci-cd-and-automation**\r\n\r\n**Stages:** Lint -> Type check -> Unit test -> Integration test -> Build -> Security scan -> Deploy\r\n\r\n**Gates:** Lint 0 errors (block), Unit test 100% (block), Coverage >=80% (block), Security scan 0 critical (block), Build success (block).\r\n\r\n---\r\n\r\n## 16. API Design Review\r\n\r\n**REST:** kebab-case plural nouns (/api/v1/users). HTTP methods: GET (retrieve), POST (create), PUT (replace), PATCH (partial), DELETE (remove).\r\n\r\n**5-Dimension Score:** Consistency (30%), Documentation (20%), Security (20%), Usability (15%), Performance (15%).\r\n\r\n---\r\n\r\n## 17. Database Design\r\n\r\n**Principles:** Plural table names, UUID PK, created_at/updated_at, soft delete optional, indexes on query conditions, explicit FKs, forward-compatible migrations.\r\n\r\n**Performance Checklist:** Indexes used? N+1 queries? Reasonable joins? Cursor pagination? Correct transaction scope?\r\n\r\n---\r\n\r\n## 18. Observability Design\r\n\r\n**Three Pillars:** Structured logging, business metrics (latency/error rate/throughput), distributed tracing.\r\n\r\n**Health Endpoints:** GET /health (liveness), GET /health/ready (readiness), GET /health/debug (internal only).\r\n\r\n---\r\n\r\n## 19. Code Migration\r\n\r\n**Strategies:** Direct replacement (high risk, small module), Parallel run (medium, need rollback), Gradual (low, large system), Abstraction layer (low, dual maintenance).\r\n\r\n**Flow:** Inventory -> Impact analysis -> Compatibility layer -> Execute -> Verify -> Cleanup\r\n\r\n---\r\n\r\n## 20. Tech Debt Tracking\r\n\r\n**Classification:** Architecture (HIGH), Code quality (MED), Testing (HIGH), Documentation (LOW), Infrastructure (MED).\r\n\r\n**Entry Format:** Type, Location, Description, Impact, Estimate, Created.\r\n\r\n---\r\n\r\n## 21. De-AI-Writing Check\r\n\r\n**Tier 1 (Always Flag):** leverage/use, utilize/utilize, implement/build, nevertheless/but, furthermore/and, commence/start, endeavor/try.\r\n\r\n**Tier 2 (Cluster Flag):** robust/reliable, seamless/smooth, facilitate/help, granular/detailed, holistic/complete, ecosystem/system.\r\n\r\n**Tier 3 (High Density):** cutting-edge/modern, state-of-the-art/best available, game-changer/big change.\r\n\r\n**Detection Flow:** First pass (flag all Tier 1) -> Structure check -> Rhythm check -> Second pass -> Output\r\n\r\n---\r\n\r\n## 22. Self Evaluation\r\n\r\n**Two-Axis:** Task Difficulty (Low/Medium/High) x Execution Quality (Poor/Adequate/Strong) -> Score 1-5.\r\n\r\n**Forced Counter-Argument:** Before final score, write reasons for lower, reasons for higher, then resolve.\r\n\r\n**Inflation Detection:** 4+ of last 5 same score -> flag inflation. 3 consecutive 4s -> stricter evaluation.\r\n\r\n---\r\n\r\n## 23. Language Quick Reference\r\n\r\n**Python:** snake_case, type hints, pathlib, f-strings, try/except/raise.\r\n**TypeScript:** camelCase, PascalCase for types, interfaces, async/await with try/catch.\r\n**Go:** camelCase, capitalized exports, error wrapping with fmt.Errorf.%w.\r\n**PowerShell:** Verb-Noun naming, CmdletBinding, ErrorAction Stop.\r\n\r\n---\r\n\r\n## Appendix: Quick Reference\r\n\r\n### When to Use What\r\n\r\n| Scenario | Use |\r\n|----------|-----|\r\n| Write new code | Spec-Driven -> Plan -> TDD -> Incremental Impl |\r\n| Fix bugs | Focused-Fix 5-phase |\r\n| Review PR | 5-Axis PR Review |\r\n| Design API | API Design + Score |\r\n| Write tests | TDD + E2E silent-pass detection |\r\n| Migration | Migration flow |\r\n| CI/CD | Pipeline stages |\r\n| Database | Design principles |\r\n| Release | Ship gate checklist |\r\n| Tech debt | Debt tracking format |\r\n| Self-eval | 2-axis scoring |\r\n| De-AI-fy | Writing check |\r\n\r\n### Never Do\r\n\r\n1. Fix bugs without scoping first\r\n2. Write code without spec\r\n3. Merge without review\r\n4. Commit without tests\r\n5. Release without CHANGELOG\r\n6. Change API without impact assessment\r\n7. Dishonest self-eval\r\n8. Ship without de-AI-fying\n\nFile v6.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn71mxvdsyxaq6jpehtw8pc8t183hwzn\",\n  \"slug\": \"dawn-code-master\",\n  \"version\": \"6.0.0\",\n  \"publishedAt\": 1785120880271\n}\n\nFile v6.0.0:skill-card.md\n\n## Description: <br>\nDawn Code Master v6.0 is a Chinese-first coding workflow skill that guides agents through specification, implementation, testing, review, security, performance, deployment, and maintenance work. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[chen6896qqwee](https://clawhub.ai/user/chen6896qqwee) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and engineers use this skill to steer an agent through coding, bug fixing, PR review, API and design review, testing, release, and maintenance workflows with explicit gates and checklists. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill has broad activation criteria and strict workflow rules that may change how an agent behaves in sensitive repositories. <br>\nMitigation: Confirm the workflow matches repository policy before installing, and review the skill before deployment. <br>\nRisk: The skill can guide agents toward running development tools and editing workspace files. <br>\nMitigation: Review proposed commands and file changes before execution, especially in repositories with sensitive data or release controls. <br>\n\n\n## Reference(s): <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Guidance, Markdown, Code, Shell commands, Configuration] <br>\n**Output Format:** [Markdown prose with checklists, tables, and code or command snippets] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May ask clarifying questions and recommend tests, reviews, or workflow gates.] <br>\n\n## Skill Version(s): <br>\n6.0.0 (source: server release metadata and artifact metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v2.0.2: 3 files, 8458 bytes\n\nFiles: skill-card.md (2222b), SKILL.md (15263b), _meta.json (135b)\n\nFile v2.0.2:SKILL.md\n\n---\r\nname: dawn-code-master\r\ndescription: >\r\n  Dawn Code Master v6.0 -- 综合编码技能，整合了80k star agent-skills、23k star claude-skills + yao-meta-skill、ratel等顶级技能集。\r\n  写代码、修bug、审PR、做设计，按这个来。\r\nmetadata:\r\n  version: 6.0.0\r\n  sources:\r\n    - focused-fix (alirezarezvani/claude-skills)\r\n    - pr-review-expert (alirezarezvani/claude-skills)\r\n    - spec-driven-workflow (alirezarezvani/claude-skills)\r\n    - api-design-reviewer (alirezarezvani/claude-skills)\r\n    - api-test-suite-builder (alirezarezvani/claude-skills)\r\n    - self-eval (alirezarezvani/claude-skills)\r\n    - skill-tester (alirezarezvani/claude-skills)\r\n    - mcp-server-builder (alirezarezvani/claude-skills)\r\n    - e2e-skills (voidmatcha/e2e-skills)\r\n    - avoid-ai-writing (conorbronsdon/avoid-ai-writing)\r\n    - cc-skills-golang (samber/cc-skills-golang)\r\n    - agentic-stack (codejunkie99/agentic-stack)\r\n    - antigravity-skills (krishnakanthb13)\r\n    - codebase-onboarding / migration-architect / ci-cd-pipeline-builder\r\n    - performance-profiler / database-designer / sql-database-assistant\r\n    - observability-designer / ship-gate / tech-debt-tracker\r\n    - changelog-generator / dependency-auditor / git-worktree-manager\r\n    - monorepo-navigator / rag-architect / agent-designer / agent-workflow-designer\r\n    - dawn-code-master v4.0 (local)\r\n    - agent-skills (addyosmani/agent-skills, 80k star)\r\n    - yao-meta-skill (yaojingang/yao-meta-skill, 2.1k star)\r\n    - ratel-ai/ratel (ratel-ai/ratel, 351 star)\r\n    - context-engineering-kit (NeoLabHQ/context-engineering-kit, 1.3k star)\r\n    - claude-skills (borghei/Claude-Skills, 411 star)\r\n  dawn:\r\n    requires:\r\n      bins: [python, node, pwsh, git]\r\n    permissions:\r\n      - exec: [python, node, ruff, black, pytest, pwsh, git]\r\n      - filesystem: [read/write workspace]\r\n---\r\n\r\n# Dawn Code Master v6.0\r\n\r\n**50+ 顶级编码技能集成 + 全生命周期工作流 + 反合理化验证门禁。** 写代码、修bug、审PR、做设计，按这个来。\r\n\r\n---\r\n\r\n## 0. Skill Router\r\n\r\n### Core Operating Behaviors\r\n\r\n1. Surface Assumptions - Before implementing, explicitly state assumptions\r\n2. Manage Confusion - Stop, name confusion, present tradeoff, wait for resolution\r\n3. Push Back - Point out problems directly, quantify downsides, propose alternatives\r\n\r\n### When to Use What\r\n\r\n| Phase | Task | Skill |\r\n|-------|------|-------|\r\n| Define | Dont know what you want | interview-me |\r\n| Define | Rough concept needs refining | [s2] Spec-Driven Dev |\r\n| Plan | Have spec, need tasks | [s3] Planning |\r\n| Build | Implementing code | [s4] Incremental Impl |\r\n| Build | UI work | Frontend principles |\r\n| Build | API work | [s16] API Design |\r\n| Build | Need better context | [s6] Context Eng |\r\n| Build | High stakes / unfamiliar code | [s7] Doubt-Driven |\r\n| Verify | Writing/running tests | [s5] TDD |\r\n| Verify | Bug fixing | [s8] Focused-Fix |\r\n| Review | Reviewing code | [s9] PR Review |\r\n| Review | Too complex | [s10] Code Simplification |\r\n| Review | Security concerns | [s11] Security |\r\n| Review | Performance concerns | [s12] Performance |\r\n| Ship | Committing/branching | [s14] Git Workflow |\r\n| Ship | CI/CD pipeline | [s15] CI/CD |\r\n| Ship | Deploying/launching | [s13] Ship Gate |\r\n| Maintain | Migration/deprecation | [s19] Migration |\r\n| Maintain | Tech debt | [s20] Tech Debt |\r\n| Docs | Writing docs/ADRs | Doc standards |\r\n| Ops | Logs/metrics/alerts | [s18] Observability |\r\n\r\n---\r\n\r\n## 1. Coding Laws\r\n\r\n**Pre-Commit Checklist:** syntax clean, tests pass, type hints, no bare except, no hardcoded secrets, f-string (not format()), pathlib (not os.path), docstrings, functions <= 30 lines.\r\n\r\n**File Structure:** <= 300 lines per file, <= 30 lines per function, one thing per function.\r\n\r\n**Error Handling:** async ops must have error handling, network requests must timeout, user input must be validated, external deps assumed to fail.\r\n\r\n**Anti-Rationalization:**\r\n\r\n| Rationalization | Reality |\r\n|----------------|---------|\r\n| \"Write now, refactor later\" | Later never comes. |\r\n| \"Just one line, no need to check\" | Small diffs push files past boundaries. |\r\n| \"AI-generated code is probably fine\" | AI code needs more scrutiny. |\r\n| \"Tests pass, it is good\" | Tests dont catch architecture or security issues. |\r\n\r\n---\r\n\r\n## 2. Spec-Driven Development\r\n\r\n**Law: NO CODE WITHOUT AN APPROVED SPEC.**\r\n\r\n**9 Mandatory Sections:** Title/Metadata, Context, Functional Requirements (RFC 2119), Non-Functional Requirements, Acceptance Criteria, Edge Cases, API Contract, Data Model, Out of Scope.\r\n\r\n**4-Phase Gated Workflow:** SPECIFY -> PLAN -> TASKS -> IMPLEMENT (each reviewed by human)\r\n\r\n**Stop-and-Ask Rules:** Scope creep, >30% ambiguity, breaking changes, security implications, unknown performance.\r\n\r\n**Anti-Rationalization:**\r\n| Rationalization | Reality |\r\n| \"Clear requirements, no spec needed\" | Clear reqs take 5 min. Unclear ones need it. |\r\n| \"Quick prototype first\" | The prototype is the final product. |\r\n| \"Specs are too slow\" | Specs save 10x refactoring time. |\r\n| \"I will document later\" | Later never comes. |\r\n\r\n---\r\n\r\n## 3. Planning and Task Breakdown\r\n\r\nEach task <= 30 min, independently testable, with clear AC. Slicing strategies: Vertical (preferred), Contract-First, Risk-First.\r\n\r\n---\r\n\r\n## 4. Incremental Implementation\r\n\r\n**Cycle:** Implement -> Test -> Verify -> Commit -> Next slice\r\n\r\n**Anti-Rationalization:** \"Writing everything at once is faster\" -> 500 lines untested = 10x debugging. \"Just a few lines, no need to commit separately\" -> atomic commits make rollback/review clean. \"I will test later\" -> never happens.\r\n\r\n---\r\n\r\n## 5. Test-Driven Development + E2E\r\n\r\n**TDD Cycle:** RED (write failing test) -> GREEN (min code to pass) -> REFACTOR (clean up)\r\n\r\n**Prove-It Pattern:** Write test reproducing bug (RED) -> Fix bug (GREEN) -> Write regression test -> Refactor\r\n\r\n**E2E Silent-Pass Detection:** toBeDefined()/not.toBeNull() on Locator always passes. Use toBeVisible()/toHaveText().\r\n\r\n**P0 Anti-patterns:** toBeDefined() on Locator, forgotten it.only, empty catch blocks, un-awaited async.\r\n\r\n**Anti-Rationalization:** \"Tests pass, it is good\" -> tests dont catch architecture/security. \"AI-generated code is fine\" -> needs more scrutiny. \"Write code first, add tests later\" -> tests what code does, not what it should do.\r\n\r\n---\r\n\r\n## 6. Context Engineering\r\n\r\n**From: ratel-ai/ratel (351 star) + NeoLabHQ/context-engineering-kit (1.3k star)**\r\n\r\n**Core Principle: Progressive Disclosure** - Load only what each turn needs.\r\n\r\n**Context Hierarchy:** 1. Rules Files (persistent) -> 2. Spec/Arch (per feature) -> 3. Source Files (per task) -> 4. Error Output (per iteration) -> 5. History (accumulates, compacts)\r\n\r\n**Ratel-Style Catalog:** All skills in SkillCatalog, tools in ToolCatalog. Each turn loads only matching ones.\r\n\r\n**Anti-Rationalization:** \"All rules in system prompt\" -> noise reduces accuracy. \"Same project, no need to separate\" -> different modules need different context. \"Write rules once\" -> projects evolve.\r\n\r\n---\r\n\r\n## 7. Doubt-Driven Development\r\n\r\n**From: addyosmani/agent-skills -- doubt-driven-development**\r\n\r\nA confident answer is not a correct one. For non-trivial decisions (branching logic, crossing boundaries, unverifiable assertions, irreversible blast radius).\r\n\r\n**Doubt Cycle:** 1. CLAIM (write claim + why matters) -> 2. EXTRACT (isolate artifact) -> 3. DOUBT (fresh-context adversarial review) -> 4. RECONCILE (classify findings) -> 5. STOP (trivial findings, 3 cycles, or user override)\r\n\r\n**Anti-Rationalization:** \"This is obviously correct\" -> hides most dangerous assumptions. \"Tests pass\" -> only cover known scenarios. \"No time\" -> doubt cycle is faster than debugging.\r\n\r\n---\r\n\r\n## 8. Bug Fixing (Focused-Fix)\r\n\r\n**Law: NO FIXES WITHOUT SCOPE -> TRACE -> DIAGNOSE FIRST.**\r\n\r\n**Phase 1: SCOPE** - Identify feature, find files, understand purpose.\r\n**Phase 2: TRACE** - Map inbound dependencies (imports) and outbound (who imports this).\r\n**Phase 3: DIAGNOSE** - Risk tags: HIGH (public API/DB schema/security), MED (internal module), LOW (isolated file).\r\n**Phase 4: FIX** - Dependencies -> Types -> Logic -> Tests -> Integration. Fix one at a time, run tests after each.\r\n**Phase 5: VERIFY** - Feature tests -> referencing tests -> full suite.\r\n\r\n---\r\n\r\n## 9. PR Review (5-Axis + Anti-Rationalization)\r\n\r\n**From: addyosmani/agent-skills -- code-review-and-quality**\r\n\r\n**Axis 1: Correctness** - Matches spec? Edge cases? Error paths? Tests pass?\r\n**Axis 2: Readability & Simplicity** - Descriptive names? Straightforward flow? Logical organization? No clever tricks? Lines can be reduced? Abstractions earning complexity?\r\n**Axis 3: Architecture** - Fits system design? Clean boundaries? No circular deps? Appropriate abstraction?\r\n**Axis 4: Security** - Input validated? Secrets safe? Auth checked? SQL parameterized? XSS prevented?\r\n**Axis 5: Performance** - N+1 queries? Large object allocations? Uncached hot paths?\r\n\r\n**Output Format:** Blast radius, per-axis assessment, severity labels (CRITICAL/REQUIRED/NIT), verdict (Approve/Request changes).\r\n\r\n**Anti-Rationalization:** 9-item table covering \"It works, good enough\", \"I wrote it, I know it is correct\", \"Clean up later\", \"AI-generated code is fine\", \"Tests pass\", \"Refactor makes it cleaner\", \"Just a small addition\", \"Just a version bump\".\r\n\r\n---\r\n\r\n## 10. Code Simplification\r\n\r\n**From: addyosmani/agent-skills -- code-simplification**\r\n\r\n**Principles:** Chestertons Fence, Rule of 500 (>500 lines = decompose), reduce complexity not relocate it.\r\n\r\n**Checklist:** Dead code? Conditionals can be simplified? Duplicate code? Complex expressions named? Nesting flattened? Single responsibility? Abstraction worth it? More code deleted than added?\r\n\r\n---\r\n\r\n## 11. Security Hardening\r\n\r\n**From: addyosmani/agent-skills -- security-and-hardening**\r\n\r\n**OWASP Top 10 Prevention:** SQL injection, XSS, auth, authorization, sensitive data, config security, dependency scanning, logging.\r\n\r\n**3-Tier Boundary:** External (untrusted, validate all) -> Service (semi-trusted, auth) -> Internal (trusted, business logic).\r\n\r\n---\r\n\r\n## 12. Performance Optimization\r\n\r\n**From: addyosmani/agent-skills -- performance-optimization**\r\n\r\n**Measure First, Optimize Second:** Baseline -> Hypothesize -> Validate -> Optimize -> Verify -> Repeat.\r\n\r\n**Checklist:** N+1 queries? Repeated computation? Large objects? Sync blocking? Caching? Lazy loading? Bundle size? Indexes? Connection pool?\r\n\r\n---\r\n\r\n## 13. Ship Gate and Deployment\r\n\r\n**From: addyosmani/agent-skills -- shipping-and-launch**\r\n\r\n**Pre-Launch Checklist:** All tests pass, code review approved, no P0/P1 vulns, CHANGELOG updated, version bumped, DB migrations forward-compatible, rollback plan, monitoring configured, docs updated, performance baseline, feature flags, staged rollout plan.\r\n\r\n---\r\n\r\n## 14. Git Workflow and Versioning\r\n\r\n**From: addyosmani/agent-skills -- git-workflow-and-versioning**\r\n\r\n**Principles:** Trunk-based development, atomic commits, ~100 lines per PR, commit as save point.\r\n\r\n**Convention:** <type>: <description> (feat/fix/refactor/chore/docs/test/ci)\r\n\r\n**Anti-Rationalization:** \"Commit first, organize later\" -> commit history IS code history. \"One PR for everything\" -> no one reviews large PRs. \"Long feature branch is fine\" -> merge hell.\r\n\r\n---\r\n\r\n## 15. CI/CD Pipeline and Automation\r\n\r\n**From: addyosmani/agent-skills -- ci-cd-and-automation**\r\n\r\n**Stages:** Lint -> Type check -> Unit test -> Integration test -> Build -> Security scan -> Deploy\r\n\r\n**Gates:** Lint 0 errors (block), Unit test 100% (block), Coverage >=80% (block), Security scan 0 critical (block), Build success (block).\r\n\r\n---\r\n\r\n## 16. API Design Review\r\n\r\n**REST:** kebab-case plural nouns (/api/v1/users). HTTP methods: GET (retrieve), POST (create), PUT (replace), PATCH (partial), DELETE (remove).\r\n\r\n**5-Dimension Score:** Consistency (30%), Documentation (20%), Security (20%), Usability (15%), Performance (15%).\r\n\r\n---\r\n\r\n## 17. Database Design\r\n\r\n**Principles:** Plural table names, UUID PK, created_at/updated_at, soft delete optional, indexes on query conditions, explicit FKs, forward-compatible migrations.\r\n\r\n**Performance Checklist:** Indexes used? N+1 queries? Reasonable joins? Cursor pagination? Correct transaction scope?\r\n\r\n---\r\n\r\n## 18. Observability Design\r\n\r\n**Three Pillars:** Structured logging, business metrics (latency/error rate/throughput), distributed tracing.\r\n\r\n**Health Endpoints:** GET /health (liveness), GET /health/ready (readiness), GET /health/debug (internal only).\r\n\r\n---\r\n\r\n## 19. Code Migration\r\n\r\n**Strategies:** Direct replacement (high risk, small module), Parallel run (medium, need rollback), Gradual (low, large system), Abstraction layer (low, dual maintenance).\r\n\r\n**Flow:** Inventory -> Impact analysis -> Compatibility layer -> Execute -> Verify -> Cleanup\r\n\r\n---\r\n\r\n## 20. Tech Debt Tracking\r\n\r\n**Classification:** Architecture (HIGH), Code quality (MED), Testing (HIGH), Documentation (LOW), Infrastructure (MED).\r\n\r\n**Entry Format:** Type, Location, Description, Impact, Estimate, Created.\r\n\r\n---\r\n\r\n## 21. De-AI-Writing Check\r\n\r\n**Tier 1 (Always Flag):** leverage/use, utilize/utilize, implement/build, nevertheless/but, furthermore/and, commence/start, endeavor/try.\r\n\r\n**Tier 2 (Cluster Flag):** robust/reliable, seamless/smooth, facilitate/help, granular/detailed, holistic/complete, ecosystem/system.\r\n\r\n**Tier 3 (High Density):** cutting-edge/modern, state-of-the-art/best available, game-changer/big change.\r\n\r\n**Detection Flow:** First pass (flag all Tier 1) -> Structure check -> Rhythm check -> Second pass -> Output\r\n\r\n---\r\n\r\n## 22. Self Evaluation\r\n\r\n**Two-Axis:** Task Difficulty (Low/Medium/High) x Execution Quality (Poor/Adequate/Strong) -> Score 1-5.\r\n\r\n**Forced Counter-Argument:** Before final score, write reasons for lower, reasons for higher, then resolve.\r\n\r\n**Inflation Detection:** 4+ of last 5 same score -> flag inflation. 3 consecutive 4s -> stricter evaluation.\r\n\r\n---\r\n\r\n## 23. Language Quick Reference\r\n\r\n**Python:** snake_case, type hints, pathlib, f-strings, try/except/raise.\r\n**TypeScript:** camelCase, PascalCase for types, interfaces, async/await with try/catch.\r\n**Go:** camelCase, capitalized exports, error wrapping with fmt.Errorf.%w.\r\n**PowerShell:** Verb-Noun naming, CmdletBinding, ErrorAction Stop.\r\n\r\n---\r\n\r\n## Appendix: Quick Reference\r\n\r\n### When to Use What\r\n\r\n| Scenario | Use |\r\n|----------|-----|\r\n| Write new code | Spec-Driven -> Plan -> TDD -> Incremental Impl |\r\n| Fix bugs | Focused-Fix 5-phase |\r\n| Review PR | 5-Axis PR Review |\r\n| Design API | API Design + Score |\r\n| Write tests | TDD + E2E silent-pass detection |\r\n| Migration | Migration flow |\r\n| CI/CD | Pipeline stages |\r\n| Database | Design principles |\r\n| Release | Ship gate checklist |\r\n| Tech debt | Debt tracking format |\r\n| Self-eval | 2-axis scoring |\r\n| De-AI-fy | Writing check |\r\n\r\n### Never Do\r\n\r\n1. Fix bugs without scoping first\r\n2. Write code without spec\r\n3. Merge without review\r\n4. Commit without tests\r\n5. Release without CHANGELOG\r\n6. Change API without impact assessment\r\n7. Dishonest self-eval\r\n8. Ship without de-AI-fying\n\nFile v2.0.2:_meta.json\n\n{\n  \"ownerId\": \"kn71mxvdsyxaq6jpehtw8pc8t183hwzn\",\n  \"slug\": \"dawn-code-master\",\n  \"version\": \"2.0.2\",\n  \"publishedAt\": 1785120799414\n}\n\nFile v2.0.2:skill-card.md\n\n## Description: <br>\nDawn Code Master is a broad coding workflow skill that combines coding, bug fixing, PR review, design, testing, security, performance, release, and maintenance guidance. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[chen6896qqwee](https://clawhub.ai/user/chen6896qqwee) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and engineering agents use this skill as an opinionated workflow guide for writing code, fixing bugs, reviewing pull requests, designing APIs, testing, security checks, performance work, CI/CD, release readiness, migration, and technical debt management. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill is broad and opinionated, so it may strongly shape how an agent plans, tests, reviews, and discusses code. <br>\nMitigation: Review the Chinese description and strict process rules before use, and apply the workflow only where it fits the project. <br>\nRisk: The artifact requests normal workspace coding authority, including read/write filesystem access and execution of common development tools. <br>\nMitigation: Use it in trusted workspaces and review proposed commands and file changes before allowing execution. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/chen6896qqwee/skills/dawn-code-master) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Guidance, Markdown, Code, Shell commands, Configuration] <br>\n**Output Format:** [Markdown guidance with checklists, tables, code-oriented instructions, and command suggestions] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May guide workspace file edits and execution of development tools such as python, node, pwsh, git, ruff, black, and pytest.] <br>\n\n## Skill Version(s): <br>\n2.0.2 (source: server release metadata; artifact frontmatter lists 6.0.0) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v2.0.1: 3 files, 11554 bytes\n\nFiles: skill-card.md (2053b), SKILL.md (21738b), _meta.json (135b)\n\nFile v2.0.1:SKILL.md\n\n---\r\nname: dawn-code-master\r\ndescription: >\r\n  Dawn Code Master v5.0 — 综合编码技能，整合了focused-fix、PR review、规格驱动开发、API设计审查、\r\n  E2E测试、去AI味写作、自评系统等30+ GitHub顶级编码技能的最佳实践。\r\n  写代码、修bug、审PR、做设计，按这个来。\r\nmetadata:\r\n  version: 5.0.0\r\n  sources:\r\n    - focused-fix (alirezarezvani/claude-skills)\r\n    - pr-review-expert (alirezarezvani/claude-skills)\r\n    - spec-driven-workflow (alirezarezvani/claude-skills)\r\n    - api-design-reviewer (alirezarezvani/claude-skills)\r\n    - api-test-suite-builder (alirezarezvani/claude-skills)\r\n    - self-eval (alirezarezvani/claude-skills)\r\n    - skill-tester (alirezarezvani/claude-skills)\r\n    - mcp-server-builder (alirezarezvani/claude-skills)\r\n    - e2e-skills (voidmatcha/e2e-skills)\r\n    - avoid-ai-writing (conorbronsdon/avoid-ai-writing)\r\n    - cc-skills-golang (samber/cc-skills-golang)\r\n    - agentic-stack (codejunkie99/agentic-stack)\r\n    - antigravity-skills (krishnakanthb13)\r\n    - codebase-onboarding / migration-architect / ci-cd-pipeline-builder\r\n    - performance-profiler / database-designer / sql-database-assistant\r\n    - observability-designer / ship-gate / tech-debt-tracker\r\n    - changelog-generator / dependency-auditor / git-worktree-manager\r\n    - monorepo-navigator / rag-architect / agent-designer / agent-workflow-designer\r\n    - dawn-code-master v4.0 (本地)\r\n  dawn:\r\n    requires:\r\n      bins: [python, node, pwsh, git]\r\n    permissions:\r\n      - exec: [python, node, ruff, black, pytest, pwsh, git]\r\n      - filesystem: [read/write workspace]\r\n---\r\n\r\n# Dawn Code Master v5.0\r\n\r\n**30+ GitHub顶级编码技能 → 1个综合技能。** 写代码、修bug、审PR、做设计，按这个来。\r\n\r\n---\r\n\r\n## 目录\r\n\r\n1. [写代码铁律](#1-写代码铁律)\r\n2. [修复Bug流程（focused-fix）](#2-修复bug流程focused-fix)\r\n3. [PR审查清单（pr-review-expert）](#3-pr审查清单pr-review-expert)\r\n4. [规格驱动开发（spec-driven-workflow）](#4-规格驱动开发spec-driven-workflow)\r\n5. [API设计审查](#5-api设计审查)\r\n6. [E2E测试暗坑检测](#6-e2e测试暗坑检测)\r\n7. [去AI味写作检查（avoid-ai-writing）](#7-去ai味写作检查avoid-ai-writing)\r\n8. [自评系统（self-eval）](#8-自评系统self-eval)\r\n9. [代码迁移指南（migration-architect）](#9-代码迁移指南migration-architect)\r\n10. [CI/CD流水线构建](#10-cicd流水线构建)\r\n11. [数据库设计](#11-数据库设计)\r\n12. [MCP服务器构建](#12-mcp服务器构建)\r\n13. [可观测性设计](#13-可观测性设计)\r\n14. [发布门禁](#14-发布门禁)\r\n15. [技术债务追踪](#15-技术债务追踪)\r\n16. [每种语言速查](#16-每种语言速查)\r\n\r\n---\r\n\r\n## 1. 写代码铁律\r\n\r\n### 提交前必查清单\r\n\r\n```\r\n[ ] py_compile / tsc / go build — 语法干净\r\n[ ] pytest / npm test / go test — 全绿\r\n[ ] 所有公开函数有类型提示\r\n[ ] 没有裸 except / 没有 any\r\n[ ] 没有硬编码密钥\r\n[ ] f-string / 模板字面量 — 不用 format() 或 %\r\n[ ] pathlib / fs 路径 — 不用 os.path\r\n[ ] 所有公开API有文档字符串\r\n[ ] 没有函数超过30行\r\n[ ] PowerShell: 完整路径用于 cron argv\r\n```\r\n\r\n### 文件结构铁律\r\n\r\n```\r\n每个文件不超过300行。\r\n每个函数不超过30行。\r\n每个函数只做一件事。\r\n```\r\n\r\n### 错误处理铁律\r\n\r\n```\r\n所有异步操作必须有错误处理。\r\n所有网络请求必须超时。\r\n所有用户输入必须验证。\r\n所有外部依赖必须假设会失败。\r\n```\r\n\r\n### 命名铁律\r\n\r\n```\r\nPython: snake_case, 类用 PascalCase\r\nTypeScript: camelCase, 类/类型用 PascalCase\r\nGo: camelCase, 导出用大写开头\r\nPowerShell: 动-名 格式，如 Get-Item\r\n```\r\n\r\n---\r\n\r\n## 2. 修复Bug流程（focused-fix）\r\n\r\n**铁律：** 不跑完前三阶段，不给修。\r\n\r\n```\r\nNO FIXES WITHOUT COMPLETING SCOPE → TRACE → DIAGNOSE FIRST\r\n```\r\n\r\n### Phase 1: SCOPE — 划定范围\r\n\r\n1. 确认哪个功能/模块需要修\r\n2. 找出主文件夹和所有文件\r\n3. 读每个文件，理解用途\r\n4. 输出功能清单\r\n\r\n```\r\nFEATURE SCOPE:\r\n  主路径: src/features/auth/\r\n  入口文件: [被其他地方引用的文件]\r\n  内部文件: [仅本功能使用的文件]\r\n  总文件数: N\r\n  总行数: N\r\n```\r\n\r\n### Phase 2: TRACE — 映射依赖\r\n\r\n**入向（本功能引用了什么）：**\r\n- 每个import追溯到源文件\r\n- 验证源文件存在\r\n- 验证导出的实体存在\r\n- 检查环境变量、配置文件、数据库模型、API端点\r\n\r\n**出向（谁引用了本功能）：**\r\n- 搜索整个代码库中引用本功能的文件\r\n- 验证它们引用的实体确实存在\r\n- 检查是否使用了正确的API\r\n\r\n```\r\nDEPENDENCY MAP:\r\n  入向依赖:\r\n    src/lib/db.ts → auth/repository.ts (getUserById)\r\n    src/lib/jwt.ts → auth/service.ts (signToken)\r\n    process.env.JWT_SECRET → auth/service.ts\r\n  出向依赖:\r\n    src/app/api/login/route.ts → import { login } from auth/service\r\n    src/middleware.ts → import { verifyToken } from auth/service\r\n```\r\n\r\n### Phase 3: DIAGNOSE — 全面诊断\r\n\r\n**代码质量检查：**\r\n- [ ] 每个import能解析到真实文件\r\n- [ ] 没有循环依赖\r\n- [ ] 类型在边界处一致（没有 any）\r\n- [ ] 函数复杂度合理（< 10 McCabe）\r\n- [ ] 没有 TODO/FIXME/HACK 注释\r\n\r\n**运行时检查：**\r\n- [ ] 环境变量已设置\r\n- [ ] 数据库迁移已更新\r\n- [ ] API端点返回预期的形状\r\n\r\n**测试检查：**\r\n- [ ] 运行所有相关测试\r\n- [ ] 记录每个失败及其完整输出\r\n- [ ] 检查测试覆盖率缺口\r\n\r\n**风险标签：**\r\n| 风险 | 标准 |\r\n|------|------|\r\n| HIGH | 公开API/中断接口契约/DB schema/安全逻辑/3+调用者 |\r\n| MED | 内部模块有测试/共享工具/配置 |\r\n| LOW | 隔离文件/测试/单用途辅助函数 |\r\n\r\n### Phase 4: FIX — 系统修复\r\n\r\n按顺序修复：\r\n1. **依赖先修** — 修复损坏的import、缺失包、版本错误\r\n2. **类型次修** — 修复功能边界处的类型不匹配\r\n3. **逻辑三修** — 修复实际业务逻辑bug\r\n4. **测试四修** — 为每个修复创建或修复测试\r\n5. **集成最后** — 验证功能端到端\r\n\r\n**规则：**\r\n- 一次只修一个\r\n- 每个修复后运行相关测试\r\n- 如果修复破坏了其他东西，停下来\r\n- 修复3个以上创建新问题 → 停！架构问题，不是bug集合\r\n\r\n### Phase 5: VERIFY — 验证\r\n\r\n1. 运行功能目录下所有测试\r\n2. 运行引用本功能的文件中的所有测试\r\n3. 运行完整测试套件\r\n4. 总结所有变更\r\n\r\n```\r\nFOCUSED FIX COMPLETE:\r\n  功能: auth\r\n  修改文件: 4\r\n  修复总数: 7\r\n  测试: 23/23 通过\r\n  回归: 0\r\n\r\n  变更:\r\n    1. auth/service.ts — 修复token签名参数顺序\r\n    2. auth/repository.ts — 添加用户查询空值检查\r\n    3. auth/middleware.ts — 修复async错误处理\r\n    4. auth/types.ts — 对齐UserResponse与DB schema\r\n```\r\n\r\n---\r\n\r\n## 3. PR审查清单（pr-review-expert）\r\n\r\n### 30+项检查清单\r\n\r\n**第一步：获取上下文**\r\n```bash\r\ngh pr diff <PR_NUMBER> --name-only\r\ngh pr view <PR_NUMBER> --json title,body,labels,assignees,milestone\r\ngh pr diff <PR_NUMBER> > /tmp/pr.diff\r\n```\r\n\r\n**第二步：爆炸半径分析**\r\n- [ ] 哪些文件导入/依赖变更的文件？\r\n- [ ] 变更跨越了服务边界吗？\r\n- [ ] 共享契约（类型、接口、schema）被修改了吗？\r\n\r\n**爆炸半径严重程度：**\r\n| 级别 | 标准 |\r\n|------|------|\r\n| CRITICAL | 共享库、DB模型、auth中间件、API契约 |\r\n| HIGH | 被3+项目使用的服务、共享配置、环境变量 |\r\n| MEDIUM | 单个服务内部变更、工具函数 |\r\n| LOW | UI组件、测试文件、文档 |\r\n\r\n**第三步：安全扫描**\r\n- [ ] SQL注入（原始SQL字符串拼接）\r\n- [ ] 硬编码密钥（password/secret/api_key/token）\r\n- [ ] XSS向量（dangerouslySetInnerHTML/innerHTML）\r\n- [ ] 认证绕过（bypass/skip auth/noauth）\r\n- [ ] 不安全哈希算法（md5/sha1）\r\n- [ ] eval/exec 调用\r\n- [ ] 原型污染（__proto__/constructor）\r\n- [ ] 路径遍历风险\r\n\r\n**第四步：测试覆盖率delta**\r\n- [ ] 新功能没有测试 → 标记\r\n- [ ] 删了测试没删代码 → 标记\r\n- [ ] 覆盖率下降 >5% → 阻止合并\r\n- [ ] 认证/支付路径要求100%覆盖率\r\n\r\n**第五步：破坏性变更检测**\r\n- [ ] API端点被移除或重命名\r\n- [ ] 响应结构变化\r\n- [ ] 字段被移除或重命名\r\n- [ ] 字段类型变更\r\n- [ ] 新增必填字段\r\n- [ ] DB schema迁移\r\n\r\n**第六步：性能影响**\r\n- [ ] N+1查询\r\n- [ ] 包体积回归\r\n- [ ] 内存分配变化\r\n\r\n---\r\n\r\n## 4. 规格驱动开发（spec-driven-workflow）\r\n\r\n**铁律：**\r\n```\r\nNO CODE WITHOUT AN APPROVED SPEC.\r\nNO EXCEPTIONS. NO \"QUICK PROTOTYPES.\" NO \"I'LL DOCUMENT IT LATER.\"\r\n```\r\n\r\n### 规格格式（9个强制章节）\r\n\r\n| # | 章节 | 关键规则 |\r\n|---|------|----------|\r\n| 1 | 标题和元数据 | 作者、日期、状态（草稿/审查中/已批准/已替代）、审查者 |\r\n| 2 | 上下文 | 为什么这个功能存在。2-4段，有证据（指标、工单） |\r\n| 3 | 功能需求 | RFC 2119关键词（MUST/SHOULD/MAY）。编号FR-N。每个原子化可测试 |\r\n| 4 | 非功能需求 | 性能、安全、可访问性、可扩展性、可靠性 — 都有可测量阈值 |\r\n| 5 | 验收标准 | Given/When/Then格式。每个AC引用至少一个FR-*或NFR-* |\r\n| 6 | 边界情况 | 编号EC-N。覆盖每个外部依赖的故障模式 |\r\n| 7 | API契约 | TypeScript风格接口。覆盖成功和错误响应 |\r\n| 8 | 数据模型 | 表格格式：字段、类型、约束。需求中的每个实体必须有模型 |\r\n| 9 | 超出范围 | 明确排除的内容及原因。防止范围蔓延 |\r\n\r\n### 6阶段工作流\r\n\r\n**Phase 1:** 收集需求 → 能2分钟解释清楚\r\n**Phase 2:** 写规格 → 9个章节全部填满\r\n**Phase 3:** 验证规格 → 80+分，自查清单全过\r\n**Phase 4:** 生成测试 → 每个AC变成测试用例，初始全红\r\n**Phase 5:** 实现 → 一次一个AC，确保无回归\r\n**Phase 6:** 自审 → 自己审查自己的实现\r\n\r\n### 停止自主执行的规则\r\n\r\n遇到以下情况必须停并问：\r\n1. 范围蔓延 — 实现需要规格里没有的东西\r\n2. 歧义 >30% — 无法从规格确定正确行为\r\n3. 破坏性变更 — 改变API契约/DB schema/公开接口\r\n4. 安全隐患 — 影响认证/授权/加密/PII\r\n5. 性能未知 — 无法测量或保证性能阈值\r\n\r\n---\r\n\r\n## 5. API设计审查\r\n\r\n### REST命名规范\r\n\r\n```\r\n✓ 好例子:\r\n  /api/v1/users\r\n  /api/v1/user-profiles\r\n  /api/v1/orders/123/line-items\r\n\r\n✗ 坏例子:\r\n  /api/v1/getUsers\r\n  /api/v1/user_profiles\r\n  /api/v1/orders/123/lineItems\r\n```\r\n\r\n### HTTP方法使用\r\n\r\n| 方法 | 用途 | 幂等 |\r\n|------|------|------|\r\n| GET | 获取资源 | 是 |\r\n| POST | 创建资源 | 否 |\r\n| PUT | 替换资源 | 是 |\r\n| PATCH | 部分更新 | 否 |\r\n| DELETE | 删除资源 | 是 |\r\n\r\n### 设计评分（5维度）\r\n\r\n| 维度 | 权重 | 检查内容 |\r\n|------|------|----------|\r\n| 一致性 | 30% | 命名、响应模式、结构一致性 |\r\n| 文档质量 | 20% | 文档完整性和清晰度 |\r\n| 安全性 | 20% | 认证、授权、安全头 |\r\n| 可用性 | 15% | 易用性、可发现性、开发者体验 |\r\n| 性能 | 15% | 缓存、分页、效率模式 |\r\n\r\n---\r\n\r\n## 6. E2E测试暗坑检测\r\n\r\n### 常见silent-pass模式\r\n\r\n```\r\n// ❌ 总是通过的假断言\r\nexpect(page.getByText('Welcome')).toBeDefined();    // Locator 永远不为 undefined\r\nexpect(page.locator('.badge')).not.toBeNull();        // Locator 永远不为 null\r\n\r\n// ✅ 正确的断言\r\nawait expect(page.getByText('Welcome')).toBeVisible();\r\nawait expect(page.locator('.badge')).toHaveText('New');\r\n```\r\n\r\n### 24个反模式检测（P0/P1/P2）\r\n\r\n**P0（立即修复）：**\r\n- `toBeDefined()` / `not.toBeNull()` 用于 Locator\r\n- 遗忘的 `it.only` / `test.only`\r\n- 空catch块：`try {} catch(e) {}`\r\n- 未await的异步操作\r\n\r\n**P1（应该修复）：**\r\n- 固定时间 `page.waitForTimeout(3000)`\r\n- 快照测试无阈值\r\n- `page.waitFor()` 无超时参数\r\n- 测试间共享可变状态\r\n\r\n**P2（建议修复）：**\r\n- 过长的测试（>50行）\r\n- 硬编码URL\r\n- 重复的setup代码\r\n- 无error场景测试\r\n\r\n---\r\n\r\n## 7. 去AI味写作检查（avoid-ai-writing）\r\n\r\n### 57种AI写作模式检测\r\n\r\n**Tier 1（永远标记）：**\r\n| 词 | 替换 |\r\n|----|------|\r\n| leverage | use |\r\n| utilize | use |\r\n| implement | build / add / create |\r\n| nevertheless | but / yet |\r\n| furthermore | and / also |\r\n| commence | start |\r\n| endeavor | try |\r\n| notwithstanding | despite |\r\n| subsequently | then / later |\r\n| moreover | also / and |\r\n\r\n**Tier 2（聚类时标记）：**\r\n| 词 | 替换 |\r\n|----|------|\r\n| robust | reliable / solid |\r\n| seamless | smooth / clean |\r\n| optimize | speed up / improve |\r\n| facilitate | help / enable |\r\n| leverage | use |\r\n| granular | detailed / fine |\r\n| holistic | complete / full |\r\n| ecosystem | system / platform |\r\n| paradigm | model / approach |\r\n| actionable | useful / practical |\r\n\r\n**Tier 3（高密度时标记）：**\r\n| 词/短语 | 替换 |\r\n|---------|------|\r\n| cutting-edge | modern / recent |\r\n| state-of-the-art | best available |\r\n| game-changer | big change |\r\n| best-in-class | good / top |\r\n| the integration of | [直接说] |\r\n| a deep dive into | [直接说] |\r\n| in the realm of | in |\r\n| a wealth of | many / plenty |\r\n| decentralized compute | [直接说] |\r\n| leverage best practices | [直接说] |\r\n\r\n### 三模式检测\r\n\r\n- **重写模式** — 标记并重写，两遍检测\r\n- **检测模式** — 只标记不改\r\n- **编辑模式** — 在文件中有针对性地修改\r\n\r\n### 检测流程\r\n\r\n```\r\n1. 第一遍：标记所有Tier 1词汇 + 聚类Tier 2 + 高密度Tier 3\r\n2. 结构检测：检查hashtag、空泛名词列表、预测性结论\r\n3. 节奏检查：检查句子长度均匀性\r\n4. 第二遍：重读重写结果，捕获漏网之鱼\r\n5. 输出：标记问题 + 原文引用 + 修改建议 + 变更摘要\r\n```\r\n\r\n---\r\n\r\n## 8. 自评系统（self-eval）\r\n\r\n### 两轴评分\r\n\r\n**轴1：任务难度（Low/Medium/High）**\r\n- Low — 安全、熟悉、常规。没有真正的失败风险\r\n- Medium — 有意义的工作，有新颖性或挑战性\r\n- High — 有野心、不熟悉或高风险\r\n\r\n**轴2：执行质量（Poor/Adequate/Strong）**\r\n- Poor — 重大失败、不完整、错误输出\r\n- Adequate — 完成但有缺口、走捷径\r\n- Strong — 执行得当、彻底、高质量输出\r\n\r\n### 评分矩阵\r\n\r\n| | Poor Exec | Adequate Exec | Strong Exec |\r\n|---|:---:|:---:|:---:|\r\n| **Low Ambition** | 1 | 2 | 2 |\r\n| **Medium Ambition** | 2 | 3 | 4 |\r\n| **High Ambition** | 2 | 4 | 5 |\r\n\r\n### 强制反方论证\r\n\r\n在写最终评分前，必须写：\r\n1. **更低分的理由** — 为什么可能更低？\r\n2. **更高分的理由** — 为什么可能更高？\r\n3. **解决** — 重新评估，给出最终评分\r\n\r\n### 防通胀检测\r\n\r\n检查 `.self-eval-scores.jsonl` 历史记录：\r\n- 最近5次中4+次相同 → 标记通胀\r\n- 连续3次4分 → 要求更严格的评估\r\n\r\n---\r\n\r\n## 9. 代码迁移指南（migration-architect）\r\n\r\n### 迁移策略\r\n\r\n| 策略 | 风险 | 适用场景 |\r\n|------|------|----------|\r\n| 直接替换 | 高 | 小模块，有完整测试覆盖 |\r\n| 并行运行 | 中 | 核心功能，需要回滚能力 |\r\n| 逐步迁移 | 低 | 大型系统，逐模块切换 |\r\n| 抽象层 | 低 | 需要长期同时维护两个版本 |\r\n\r\n### 迁移流程\r\n\r\n1. **盘点** — 扫描所有使用旧代码的地方\r\n2. **影响分析** — 每个使用点的影响修正\r\n3. **兼容层** — 需要时提供向后兼容\r\n4. **迁移执行** — 按依赖关系排序\r\n5. **验证** — 每个迁移点独立验证\r\n6. **清理** — 删除旧代码和兼容层\r\n\r\n---\r\n\r\n## 10. CI/CD流水线构建\r\n\r\n### 流水线阶段\r\n\r\n```\r\n1. Lint → 代码风格检查\r\n2. Type check → 类型检查（tsc / mypy / go vet）\r\n3. Unit test → 单元测试\r\n4. Integration test → 集成测试\r\n5. Build → 构建\r\n6. Security scan → 安全扫描（SAST / dependency check）\r\n7. Deploy → 部署（staging → production）\r\n```\r\n\r\n### 门禁规则\r\n\r\n| 阶段 | 门禁 | 操作 |\r\n|------|------|------|\r\n| Lint | 0 errors | 阻塞 |\r\n| Unit test | 100% pass | 阻塞 |\r\n| Coverage | ≥80% | 阻塞 |\r\n| Security scan | 0 critical/high | 阻塞 |\r\n| Build | 成功 | 阻塞 |\r\n\r\n---\r\n\r\n## 11. 数据库设计\r\n\r\n### 设计原则\r\n\r\n```\r\n1. 表名：复数名词（users, orders, products）\r\n2. 主键：id（UUID或自增）\r\n3. 时间戳：created_at, updated_at\r\n4. 软删除：deleted_at（可选）\r\n5. 索引：覆盖所有查询条件\r\n6. 外键：显式定义，有ON DELETE策略\r\n7. 迁移：始终向前兼容\r\n```\r\n\r\n### 性能检查清单\r\n\r\n- [ ] 查询使用了索引吗？\r\n- [ ] N+1查询问题？\r\n- [ ] 连接数量合理？\r\n- [ ] 分页正确（游标 > OFFSET）？\r\n- [ ] 事务范围正确？\r\n\r\n---\r\n\r\n## 12. MCP服务器构建\r\n\r\n### OpenAPI → MCP 映射\r\n\r\n```bash\r\npython3 scripts/openapi_to_mcp.py \\\r\n  --input openapi.json \\\r\n  --server-name my-service \\\r\n  --language python \\\r\n  --output-dir ./out\r\n```\r\n\r\n### MCP设计原则\r\n\r\n```\r\n1. 工具名 = 动+名（getUser, createOrder）\r\n2. 每个工具一个明确职责\r\n3. Schema即文档（描述字段必填）\r\n4. 错误响应标准化\r\n5. 版本管理，向后兼容\r\n```\r\n\r\n---\r\n\r\n## 13. 可观测性设计\r\n\r\n### 三大支柱\r\n\r\n| 支柱 | 工具 | 检查内容 |\r\n|------|------|----------|\r\n| 日志 | 结构化日志 | 关键路径有日志，日志级别正确 |\r\n| 指标 | 业务指标 | 延迟、错误率、吞吐量 |\r\n| 追踪 | 分布式追踪 | 跨服务调用链完整 |\r\n\r\n### 健康检查端点\r\n\r\n```\r\nGET /health — 基础存活检查\r\nGET /health/ready — 就绪检查（依赖都可用）\r\nGET /health/debug — 调试信息（仅内部）\r\n```\r\n\r\n---\r\n\r\n## 14. 发布门禁（ship-gate）\r\n\r\n### 发布前检查清单\r\n\r\n```\r\n[ ] 所有测试通过\r\n[ ] 代码审查完成并批准\r\n[ ] 没有P0/P1安全漏洞\r\n[ ] CHANGELOG已更新\r\n[ ] 版本号已更新（semver）\r\n[ ] 数据库迁移向前兼容\r\n[ ] 回滚计划已制定\r\n[ ] 监控告警已配置\r\n[ ] 文档已更新\r\n[ ] 性能基准已检查\r\n```\r\n\r\n---\r\n\r\n## 15. 技术债务追踪\r\n\r\n### 债务分类\r\n\r\n| 类型 | 示例 | 优先级 |\r\n|------|------|--------|\r\n| 架构 | 循环依赖、上帝类 | HIGH |\r\n| 代码质量 | 长函数、重复代码 | MED |\r\n| 测试 | 低覆盖率、无集成测试 | HIGH |\r\n| 文档 | 过期文档、无API文档 | LOW |\r\n| 基础设施 | 陈旧依赖、手动部署 | MED |\r\n\r\n### 债务条目标准格式\r\n\r\n```\r\n- [ ] 类型: [架构/代码/测试/文档/基础设施]\r\n      位置: [文件路径:行号]\r\n      描述: [一句话描述问题]\r\n      影响: [为什么需要修复]\r\n      预估: [修复时间估计]\r\n      创建: [日期]\r\n```\r\n\r\n---\r\n\r\n## 16. 每种语言速查\r\n\r\n### Python\r\n```python\r\n# 类型提示\r\ndef greet(name: str) -> str:\r\n    return f\"Hello, {name}\"\r\n\r\n# 错误处理\r\ntry:\r\n    result = await async_func()\r\nexcept TimeoutError:\r\n    logger.error(\"timeout\")\r\n    raise\r\nexcept Exception as e:\r\n    logger.exception(\"unexpected error\", exc_info=e)\r\n    raise\r\n\r\n# 路径处理\r\nfrom pathlib import Path\r\nconfig = Path(\"config.yaml\")\r\nif not config.exists():\r\n    raise FileNotFoundError(f\"config not found: {config}\")\r\n```\r\n\r\n### TypeScript\r\n```typescript\r\n// 类型定义\r\ninterface User {\r\n  id: string;\r\n  name: string;\r\n  email: string;\r\n  createdAt: Date;\r\n}\r\n\r\n// 错误处理\r\nasync function fetchUser(id: string): Promise<User> {\r\n  const response = await fetch(`/api/users/${id}`);\r\n  if (!response.ok) {\r\n    throw new Error(`HTTP ${response.status}: ${response.statusText}`);\r\n  }\r\n  return response.json();\r\n}\r\n\r\n// 路径处理\r\nimport path from 'node:path';\r\nconst configPath = path.resolve(process.cwd(), 'config.yaml');\r\n```\r\n\r\n### Go\r\n```go\r\n// 接口定义\r\ntype UserService interface {\r\n    GetUser(ctx context.Context, id string) (*User, error)\r\n    CreateUser(ctx context.Context, user *User) error\r\n}\r\n\r\n// 错误处理\r\nfunc (s *Service) GetUser(ctx context.Context, id string) (*User, error) {\r\n    user, err := s.repo.FindByID(ctx, id)\r\n    if err != nil {\r\n        return nil, fmt.Errorf(\"get user %s: %w\", id, err)\r\n    }\r\n    return user, nil\r\n}\r\n```\r\n\r\n### PowerShell\r\n```powershell\r\n# 函数定义\r\nfunction Get-User {\r\n    [CmdletBinding()]\r\n    param(\r\n        [Parameter(Mandatory)]\r\n        [string]$UserId\r\n    )\r\n    # 实现\r\n}\r\n\r\n# 错误处理\r\ntry {\r\n    $result = Invoke-RestMethod -Uri $url -ErrorAction Stop\r\n} catch {\r\n    Write-Error \"Failed to fetch: $_\"\r\n    throw\r\n}\r\n```\r\n\r\n---\r\n\r\n## 附录：快速参考\r\n\r\n### 什么时候用什么\r\n\r\n| 场景 | 使用 |\r\n|------|------|\r\n| 写新代码 | 规格驱动开发 → 写规格 → 生成测试 → 实现 |\r\n| 修bug | focused-fix 5阶段流程 |\r\n| 审PR | PR审查清单（30+项） |\r\n| 设计API | API设计审查 + 评分 |\r\n| 写测试 | E2E暗坑检测 + 测试覆盖率 |\r\n| 做迁移 | 迁移架构流程 |\r\n| 设CI/CD | CI/CD流水线构建 |\r\n| 设数据库 | 数据库设计原则 |\r\n| 建MCP | MCP服务器构建 |\r\n| 发版本 | 发布门禁检查清单 |\r\n| 修技术债 | 债务追踪格式 |\r\n| 自评 | 两轴自评系统 |\r\n| 去AI味 | 去AI写作检查 |\r\n\r\n### 永远不要做\r\n\r\n1. 不划范围就修bug\r\n2. 不写规格就写代码\r\n3. 不审PR就合并\r\n4. 不跑测试就提交\r\n5. 不写CHANGELOG就发版\r\n6. 不评估影响就改API\r\n7. 不诚实地自评\r\n8. 不检查AI味就发出去\n\nFile v2.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn71mxvdsyxaq6jpehtw8pc8t183hwzn\",\n  \"slug\": \"dawn-code-master\",\n  \"version\": \"2.0.1\",\n  \"publishedAt\": 1785080140976\n}\n\nFile v2.0.1:skill-card.md\n\n## Description: <br>\nDawn Code Master is a broad coding-workflow skill that guides agents through code implementation, bug fixing, PR review, spec-driven development, API review, E2E testing, writing review, self-evaluation, and release checks. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[chen6896qqwee](https://clawhub.ai/user/chen6896qqwee) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and software-engineering agents use this skill as a consolidated coding process guide for implementation, debugging, reviews, testing, API and database design, CI/CD, observability, and release readiness. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill covers many coding workflows and may shape a wide range of development tasks. <br>\nMitigation: Review its workflow preferences and apply only the sections relevant to the current task. <br>\nRisk: The skill encourages workspace edits and running local development tools. <br>\nMitigation: Review proposed file changes and commands before execution, and run them in an appropriate workspace. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/chen6896qqwee/skills/dawn-code-master) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, code, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown guidance with checklists, tables, and code or shell-command snippets.] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May propose workspace edits and local development commands; users should review before execution.] <br>\n\n## Skill Version(s): <br>\n2.0.1 (source: server release; artifact metadata reports 5.0.0) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v2.0.0: 3 files, 5974 bytes\n\nFiles: _meta.json (135b), skill-card.md (2256b), SKILL.md (9309b)\n\nFile v2.0.0:SKILL.md\n\n---\r\nname: dawn-code-master\r\ndescription: >\r\n  Dawn Code Master — hardened coding standards distilled from code-quality,\r\n  python, typescript, python-testing, and code-smell-analyzer.\r\n  Write, review, and refactor code with consistent quality across Python and\r\n  TypeScript. Follow this skill for every new file, every review, every PR.\r\nmetadata:\r\n  version: 2.0.0\r\n  sources:\r\n    - code-quality (4.285)\r\n    - python (3.690)\r\n    - typescript (3.690)\r\n    - python-testing (2.877)\r\n    - code-smell-analyzer (2.477)\r\n  openclaw:\r\n    requires:\r\n      bins: [python, node]\r\n    permissions:\r\n      - exec: [python, node, ruff, black, pytest]\r\n      - filesystem: [read/write workspace]\r\n---\r\n\r\n# Dawn Code Master\r\n\r\n**5 skills → 1**. Integrated coding standards for Python & TypeScript.\r\n\r\n## Pocket Checklist (every commit)\r\n\r\n```\r\n[ ] py_compile / tsc — syntax clean\r\n[ ] pytest pass\r\n[ ] Type hints on all public functions\r\n[ ] No bare except / no `any`\r\n[ ] No hardcoded secrets\r\n[ ] f-strings / template literals — never format() or %\r\n[ ] pathlib / fs paths — never os.path\r\n[ ] Docstrings on all public APIs\r\n[ ] No function > 30 lines\r\n```\r\n\r\n---\r\n\r\n## 1. Universal Principles (all languages)\r\n\r\n### Naming\r\n\r\n| Construct | Convention | Example |\r\n|-----------|-----------|---------|\r\n| variables / functions | snake_case / camelCase⁽¹⁾ | `etf_rotator()` / `getEtfData()` |\r\n| classes / types | PascalCase | `class EtfPortfolio` |\r\n| constants | UPPER_CASE | `MAX_WEIGHT = 0.40` |\r\n| private | `_` prefix | `_validate()` |\r\n\r\n⁽¹⁾ Python → snake_case, TypeScript → camelCase.\r\n\r\n### Comment & Docstring Standard\r\n\r\n```python\r\n# Python docstring (Google-style)\r\ndef rebalance(code: str, target_pct: float) -> dict:\r\n    \"\"\"Rebalance ETF position to target weight.\r\n\r\n    Args:\r\n        code: ETF code, e.g. \"515790\".\r\n        target_pct: Target allocation as decimal 0-1.\r\n\r\n    Returns:\r\n        {order_id, filled_qty, avg_price}\r\n\r\n    Raises:\r\n        ValueError: If target_pct > max_single_weight.\r\n    \"\"\"\r\n```\r\n\r\n```typescript\r\n// TypeScript JSDoc\r\n/** Rebalance ETF position to target weight. */\r\nexport function rebalance(code: string, targetPct: number): OrderResult\r\n```\r\n\r\n### Error Handling\r\n\r\n✅ `except Exception:` — never bare `except:` (catches `SystemExit`, `KeyboardInterrupt`)\r\n✅ Always log or re-raise — never silent `except: pass`\r\n✅ Type-specific errors: `ValueError` / `TypeError` / custom exceptions\r\n```python\r\n# ❌ Bad\r\ntry:\r\n    result = api.buy(code, qty)\r\nexcept:\r\n    pass\r\n\r\n# ✅ Good\r\ntry:\r\n    result = api.buy(code, qty)\r\nexcept ApiError as e:\r\n    log(f\"Buy failed: {e}\")\r\n    raise\r\n```\r\n\r\n### Security Guardrails\r\n\r\n- **No secrets in code.** Use env vars or `.env` files.\r\n- **Validate inputs.** Never trust user/external data.\r\n- **Least privilege.** Only request permissions you actually use.\r\n- **No credentials in logs, screenshots, or test fixtures.**\r\n\r\n---\r\n\r\n## 2. Python (PEP 8 + Modern Patterns)\r\n\r\n### Style\r\n\r\n- 4-space indent, 88-char line limit (Black default)\r\n- Imports: stdlib → third-party → local, alphabetized\r\n- Two blank lines before top-level defs, one within class\r\n\r\n### Pythonic Patterns\r\n\r\n```python\r\n# ✅ Comprehensions over loops\r\nsquares = [x**2 for x in range(10)]\r\nlookup = {item.id: item for item in items}\r\n\r\n# ✅ Context managers for I/O\r\nwith open(path, encoding=\"utf-8\") as f:\r\n    data = f.read()\r\n\r\n# ✅ Unpacking & walrus\r\nfirst, *rest = items\r\nif match := re.search(pattern, text):\r\n    print(match.group())\r\n\r\n# ✅ EAFP (Easier to Ask Forgiveness than Permission)\r\ntry:\r\n    value = d[key]\r\nexcept KeyError:\r\n    value = default\r\n\r\n# ✅ f-strings\r\nmsg = f\"{name} has {count} items\"\r\n\r\n# ✅ pathlib\r\nfrom pathlib import Path\r\nconfig = Path.home() / \".config\" / \"app.json\"\r\n\r\n# ✅ dataclasses\r\n@dataclass\r\nclass Position:\r\n    code: str\r\n    qty: int\r\n    cost: float\r\n\r\n# ✅ enumerate, zip, itertools\r\nfor i, item in enumerate(items):\r\n    ...\r\nfor a, b in zip(xs, ys, strict=True):\r\n    ...\r\n```\r\n\r\n### Anti-patterns to Avoid\r\n\r\n```python\r\n# ❌ Mutable defaults\r\ndef bad(items=[]):      # Shared across calls!\r\n\r\ndef good(items=None):\r\n    items = items or []\r\n\r\n# ❌ Bare except\r\ntry:\r\n    ...\r\nexcept:  # Catches SystemExit, KeyboardInterrupt\r\n\r\n# ❌ from module import *\r\n# ❌ == None  (use `is None`)\r\n# ❌ len(x) == 0  (use `not x`)\r\n# ❌ String concat in loops  (use join)\r\n# ❌ Global mutable state\r\n```\r\n\r\n### Python Version\r\n\r\n- Minimum: Python 3.10+ (3.9 EOL Oct 2025)\r\n- Target: 3.11-3.13 for new code\r\n- Use modern features: `match` statements, `|` union syntax, type hints\r\n\r\n---\r\n\r\n## 3. TypeScript (Strict Mode)\r\n\r\n### Core Rules\r\n\r\n- **Stop using `any`** — `unknown` forces narrowing, `any` silently breaks safety\r\n- **Prefer `const`** over `let` — enables literal inference\r\n- **`as const`** on config objects / tuples to preserve literals\r\n- **`satisfies`** over type annotation when you need both checking + literal preservation\r\n\r\n### Narrowing\r\n\r\n```typescript\r\n// ❌ filter(Boolean) doesn't narrow type\r\nitems.filter(Boolean)\r\n\r\n// ✅ Use type predicate\r\nitems.filter((x): x is T => Boolean(x))\r\n\r\n// ❌ Object.keys returns string[]\r\nconst keys = Object.keys(obj)  // string[], not (keyof typeof obj)[]\r\n\r\n// ✅ Exhaustive discriminated union\r\nswitch (event.kind) {\r\n  case \"buy\": return handleBuy(event);\r\n  case \"sell\": return handleSell(event);\r\n  default: const _exhaustive: never = event;\r\n}\r\n```\r\n\r\n### Null Safety\r\n\r\n- `?.` returns `undefined` (not `null`) — matters for APIs\r\n- `??` catches `null`/`undefined` only — `||` catches all falsy\r\n- `!` non-null assertion is **last resort** — prefer narrowing / early return\r\n\r\n### Module Boundaries\r\n\r\n- `import type` for type-only imports — stripped at runtime\r\n- Re-export types: `export type { X }` — prevents accidental runtime dep\r\n- `.d.ts` augmentation: `declare module` with exact module path\r\n\r\n---\r\n\r\n## 4. Testing (pytest)\r\n\r\n### Quickstart\r\n\r\n```bash\r\npytest -v                                    # run all, verbose\r\npytest test_guardrails.py -k \"blacklist\"     # filter tests\r\npytest --cov=scripts --cov-report=term        # coverage\r\npytest -x --tb=short                          # stop on first fail\r\n```\r\n\r\n### Patterns\r\n\r\n```python\r\nimport pytest\r\nfrom unittest.mock import patch\r\n\r\n# Parametrize\r\n@pytest.mark.parametrize(\"code,expected\", [\r\n    (\"688001\", False), (\"600519\", True),\r\n])\r\ndef test_blacklist(code, expected):\r\n    assert check_blacklist(code)[0] == expected\r\n\r\n# Mock\r\n@patch(\"module.api_buy\")\r\ndef test_buy_fails_gracefully(mock_buy):\r\n    mock_buy.side_effect = ApiError(\"timeout\")\r\n    result = execute_trade(\"515790\", 100)\r\n    assert result[\"status\"] == \"error\"\r\n\r\n# Fixture\r\n@pytest.fixture\r\ndef sample_state():\r\n    return {\"holdings\": {}, \"cash\": 100000}\r\n\r\ndef test_empty_portfolio(sample_state):\r\n    assert total_weight(sample_state) == 0\r\n```\r\n\r\n### Coverage Targets\r\n\r\n- **Core logic**: 90%+ (guardrails, strategy decisions, scoring)\r\n- **I/O wrappers**: 70%+ (API calls, file I/O with mocking)\r\n- **UI / scripts**: 50%+ (integration-style)\r\n\r\n---\r\n\r\n## 5. Code Smell & Refactoring\r\n\r\n### Every PR Review: Smell Checklist\r\n\r\n| Smell | Fix |\r\n|-------|-----|\r\n| Function > 30 lines | Extract smaller functions |\r\n| Nested if > 3 deep | Early return / guard clauses |\r\n| Magic numbers | Named constants |\r\n| Duplicate code | Extract helper / DRY |\r\n| Long param list (>3) | Dataclass / config object |\r\n| Mixed error handling | Consistent try/except pattern |\r\n| No tests for new logic | Add pytest parametrize |\r\n| Hardcoded config | Move to config file / env var |\r\n\r\n### Refactoring Process\r\n\r\n1. **Read** the function — understand what it does\r\n2. **Write tests** to lock current behavior\r\n3. **Extract** coherent chunks into named functions\r\n4. **Rename** variables/helpers to be self-documenting\r\n5. **Verify** — tests still pass, output unchanged\r\n6. **Commit** — one atomic change per refactor\r\n\r\n### SOLID (Simple version)\r\n\r\n- **S** — One reason to change per module\r\n- **O** — Extend with new code, not by modifying working code\r\n- **L** — Subtypes must be substitutable for base types\r\n- **I** — Small, focused interfaces over one big one\r\n- **D** — Depend on abstractions, not concrete implementations\r\n\r\n---\r\n\r\n## Reference Files\r\n\r\n| File | Source Skill |\r\n|------|-------------|\r\n| `references/python-guide.md` | Full PEP 8 + Pythonic patterns reference |\r\n| `references/typescript-guide.md` | Generics, utility types, declaration files |\r\n| `references/pytest-guide.md` | Mocking, fixtures, async tests, coverage |\r\n| `references/security-checklist.md` | Security validation, threat modeling |\r\n\r\n---\r\n\r\n## Changelog\r\n### v2.0.0 (2026-07-11)\r\n\r\n- Added ``rules/`` directory — per-language rule files for automated linting and enforcement\r\n- Added ``templates/`` directory — reusable code templates for Python and TypeScript\r\n- Extended coverage: new file templates for CLI scripts, data pipelines, and API endpoints\r\n\r\n\r\n\r\n### v1.0.0 (2026-07-06)\r\n\r\n- Integrated 5 skills: code-quality + python + typescript + python-testing + code-smell-analyzer\r\n- Universal principles across Python and TypeScript\r\n- Pocket checklist for every commit\r\n- Refactoring process with smell checklist\n\nFile v2.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn71mxvdsyxaq6jpehtw8pc8t183hwzn\",\n  \"slug\": \"dawn-code-master\",\n  \"version\": \"2.0.0\",\n  \"publishedAt\": 1783787545580\n}\n\nFile v2.0.0:skill-card.md\n\n## Description: <br>\nDawn Code Master provides coding standards for writing, reviewing, and refactoring Python and TypeScript with consistent quality, testing, and security practices. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[chen6896qqwee](https://clawhub.ai/user/chen6896qqwee) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and engineers use this skill to apply consistent Python and TypeScript coding standards during implementation, review, refactoring, and pull request preparation. It emphasizes syntax checks, tests, type safety, security guardrails, and code smell reduction. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The security scan notes an invisible leading character in SKILL.md that may interfere with parsing or review. <br>\nMitigation: Ask the publisher to remove the invisible leading character and republish before installation when strict parser hygiene is required. <br>\nRisk: The skill declares workspace read/write access and execution of Python, Node, ruff, black, and pytest commands. <br>\nMitigation: Review proposed edits and commands before execution, and apply the skill in a version-controlled workspace where changes can be inspected. <br>\n\n\n## Reference(s): <br>\n- [Dawn Code Master on ClawHub](https://clawhub.ai/chen6896qqwee/skills/dawn-code-master) <br>\n- [Publisher profile](https://clawhub.ai/user/chen6896qqwee) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [guidance, markdown, code, shell commands, configuration] <br>\n**Output Format:** [Markdown guidance with inline code blocks, checklists, command examples, and configuration recommendations.] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Requires Python and Node tooling when applying the recommended checks.] <br>\n\n## Skill Version(s): <br>\n2.0.0 (source: evidence.release.version and artifact metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.0: 3 files, 5647 bytes\n\nFiles: skill-card.md (1977b), SKILL.md (8659b), _meta.json (135b)\n\nFile v1.0.0:SKILL.md\n\n---\nname: dawn-code-master\ndescription: >\n  Dawn Code Master — hardened coding standards distilled from code-quality,\n  python, typescript, python-testing, and code-smell-analyzer.\n  Write, review, and refactor code with consistent quality across Python and\n  TypeScript. Follow this skill for every new file, every review, every PR.\nmetadata:\n  version: 1.0.0\n  sources:\n    - code-quality (4.285)\n    - python (3.690)\n    - typescript (3.690)\n    - python-testing (2.877)\n    - code-smell-analyzer (2.477)\n  openclaw:\n    requires:\n      bins: [python, node]\n    permissions:\n      - exec: [python, node, ruff, black, pytest]\n      - filesystem: [read/write workspace]\n---\n\n# Dawn Code Master\n\n**5 skills → 1**. Integrated coding standards for Python & TypeScript.\n\n## Pocket Checklist (every commit)\n\n```\n[ ] py_compile / tsc — syntax clean\n[ ] pytest pass\n[ ] Type hints on all public functions\n[ ] No bare except / no `any`\n[ ] No hardcoded secrets\n[ ] f-strings / template literals — never format() or %\n[ ] pathlib / fs paths — never os.path\n[ ] Docstrings on all public APIs\n[ ] No function > 30 lines\n```\n\n---\n\n## 1. Universal Principles (all languages)\n\n### Naming\n\n| Construct | Convention | Example |\n|-----------|-----------|---------|\n| variables / functions | snake_case / camelCase⁽¹⁾ | `etf_rotator()` / `getEtfData()` |\n| classes / types | PascalCase | `class EtfPortfolio` |\n| constants | UPPER_CASE | `MAX_WEIGHT = 0.40` |\n| private | `_` prefix | `_validate()` |\n\n⁽¹⁾ Python → snake_case, TypeScript → camelCase.\n\n### Comment & Docstring Standard\n\n```python\n# Python docstring (Google-style)\ndef rebalance(code: str, target_pct: float) -> dict:\n    \"\"\"Rebalance ETF position to target weight.\n\n    Args:\n        code: ETF code, e.g. \"515790\".\n        target_pct: Target allocation as decimal 0-1.\n\n    Returns:\n        {order_id, filled_qty, avg_price}\n\n    Raises:\n        ValueError: If target_pct > max_single_weight.\n    \"\"\"\n```\n\n```typescript\n// TypeScript JSDoc\n/** Rebalance ETF position to target weight. */\nexport function rebalance(code: string, targetPct: number): OrderResult\n```\n\n### Error Handling\n\n✅ `except Exception:` — never bare `except:` (catches `SystemExit`, `KeyboardInterrupt`)\n✅ Always log or re-raise — never silent `except: pass`\n✅ Type-specific errors: `ValueError` / `TypeError` / custom exceptions\n```python\n# ❌ Bad\ntry:\n    result = api.buy(code, qty)\nexcept:\n    pass\n\n# ✅ Good\ntry:\n    result = api.buy(code, qty)\nexcept ApiError as e:\n    log(f\"Buy failed: {e}\")\n    raise\n```\n\n### Security Guardrails\n\n- **No secrets in code.** Use env vars or `.env` files.\n- **Validate inputs.** Never trust user/external data.\n- **Least privilege.** Only request permissions you actually use.\n- **No credentials in logs, screenshots, or test fixtures.**\n\n---\n\n## 2. Python (PEP 8 + Modern Patterns)\n\n### Style\n\n- 4-space indent, 88-char line limit (Black default)\n- Imports: stdlib → third-party → local, alphabetized\n- Two blank lines before top-level defs, one within class\n\n### Pythonic Patterns\n\n```python\n# ✅ Comprehensions over loops\nsquares = [x**2 for x in range(10)]\nlookup = {item.id: item for item in items}\n\n# ✅ Context managers for I/O\nwith open(path, encoding=\"utf-8\") as f:\n    data = f.read()\n\n# ✅ Unpacking & walrus\nfirst, *rest = items\nif match := re.search(pattern, text):\n    print(match.group())\n\n# ✅ EAFP (Easier to Ask Forgiveness than Permission)\ntry:\n    value = d[key]\nexcept KeyError:\n    value = default\n\n# ✅ f-strings\nmsg = f\"{name} has {count} items\"\n\n# ✅ pathlib\nfrom pathlib import Path\nconfig = Path.home() / \".config\" / \"app.json\"\n\n# ✅ dataclasses\n@dataclass\nclass Position:\n    code: str\n    qty: int\n    cost: float\n\n# ✅ enumerate, zip, itertools\nfor i, item in enumerate(items):\n    ...\nfor a, b in zip(xs, ys, strict=True):\n    ...\n```\n\n### Anti-patterns to Avoid\n\n```python\n# ❌ Mutable defaults\ndef bad(items=[]):      # Shared across calls!\n\ndef good(items=None):\n    items = items or []\n\n# ❌ Bare except\ntry:\n    ...\nexcept:  # Catches SystemExit, KeyboardInterrupt\n\n# ❌ from module import *\n# ❌ == None  (use `is None`)\n# ❌ len(x) == 0  (use `not x`)\n# ❌ String concat in loops  (use join)\n# ❌ Global mutable state\n```\n\n### Python Version\n\n- Minimum: Python 3.10+ (3.9 EOL Oct 2025)\n- Target: 3.11-3.13 for new code\n- Use modern features: `match` statements, `|` union syntax, type hints\n\n---\n\n## 3. TypeScript (Strict Mode)\n\n### Core Rules\n\n- **Stop using `any`** — `unknown` forces narrowing, `any` silently breaks safety\n- **Prefer `const`** over `let` — enables literal inference\n- **`as const`** on config objects / tuples to preserve literals\n- **`satisfies`** over type annotation when you need both checking + literal preservation\n\n### Narrowing\n\n```typescript\n// ❌ filter(Boolean) doesn't narrow type\nitems.filter(Boolean)\n\n// ✅ Use type predicate\nitems.filter((x): x is T => Boolean(x))\n\n// ❌ Object.keys returns string[]\nconst keys = Object.keys(obj)  // string[], not (keyof typeof obj)[]\n\n// ✅ Exhaustive discriminated union\nswitch (event.kind) {\n  case \"buy\": return handleBuy(event);\n  case \"sell\": return handleSell(event);\n  default: const _exhaustive: never = event;\n}\n```\n\n### Null Safety\n\n- `?.` returns `undefined` (not `null`) — matters for APIs\n- `??` catches `null`/`undefined` only — `||` catches all falsy\n- `!` non-null assertion is **last resort** — prefer narrowing / early return\n\n### Module Boundaries\n\n- `import type` for type-only imports — stripped at runtime\n- Re-export types: `export type { X }` — prevents accidental runtime dep\n- `.d.ts` augmentation: `declare module` with exact module path\n\n---\n\n## 4. Testing (pytest)\n\n### Quickstart\n\n```bash\npytest -v                                    # run all, verbose\npytest test_guardrails.py -k \"blacklist\"     # filter tests\npytest --cov=scripts --cov-report=term        # coverage\npytest -x --tb=short                          # stop on first fail\n```\n\n### Patterns\n\n```python\nimport pytest\nfrom unittest.mock import patch\n\n# Parametrize\n@pytest.mark.parametrize(\"code,expected\", [\n    (\"688001\", False), (\"600519\", True),\n])\ndef test_blacklist(code, expected):\n    assert check_blacklist(code)[0] == expected\n\n# Mock\n@patch(\"module.api_buy\")\ndef test_buy_fails_gracefully(mock_buy):\n    mock_buy.side_effect = ApiError(\"timeout\")\n    result = execute_trade(\"515790\", 100)\n    assert result[\"status\"] == \"error\"\n\n# Fixture\n@pytest.fixture\ndef sample_state():\n    return {\"holdings\": {}, \"cash\": 100000}\n\ndef test_empty_portfolio(sample_state):\n    assert total_weight(sample_state) == 0\n```\n\n### Coverage Targets\n\n- **Core logic**: 90%+ (guardrails, strategy decisions, scoring)\n- **I/O wrappers**: 70%+ (API calls, file I/O with mocking)\n- **UI / scripts**: 50%+ (integration-style)\n\n---\n\n## 5. Code Smell & Refactoring\n\n### Every PR Review: Smell Checklist\n\n| Smell | Fix |\n|-------|-----|\n| Function > 30 lines | Extract smaller functions |\n| Nested if > 3 deep | Early return / guard clauses |\n| Magic numbers | Named constants |\n| Duplicate code | Extract helper / DRY |\n| Long param list (>3) | Dataclass / config object |\n| Mixed error handling | Consistent try/except pattern |\n| No tests for new logic | Add pytest parametrize |\n| Hardcoded config | Move to config file / env var |\n\n### Refactoring Process\n\n1. **Read** the function — understand what it does\n2. **Write tests** to lock current behavior\n3. **Extract** coherent chunks into named functions\n4. **Rename** variables/helpers to be self-documenting\n5. **Verify** — tests still pass, output unchanged\n6. **Commit** — one atomic change per refactor\n\n### SOLID (Simple version)\n\n- **S** — One reason to change per module\n- **O** — Extend with new code, not by modifying working code\n- **L** — Subtypes must be substitutable for base types\n- **I** — Small, focused interfaces over one big one\n- **D** — Depend on abstractions, not concrete implementations\n\n---\n\n## Reference Files\n\n| File | Source Skill |\n|------|-------------|\n| `references/python-guide.md` | Full PEP 8 + Pythonic patterns reference |\n| `references/typescript-guide.md` | Generics, utility types, declaration files |\n| `references/pytest-guide.md` | Mocking, fixtures, async tests, coverage |\n| `references/security-checklist.md` | Security validation, threat modeling |\n\n---\n\n## Changelog\n\n### v1.0.0 (2026-07-06)\n\n- Integrated 5 skills: code-quality + python + typescript + python-testing + code-smell-analyzer\n- Universal principles across Python and TypeScript\n- Pocket checklist for every commit\n- Refactoring process with smell checklist\n\nFile v1.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn71mxvdsyxaq6jpehtw8pc8t183hwzn\",\n  \"slug\": \"dawn-code-master\",\n  \"version\": \"1.0.0\",\n  \"publishedAt\": 1783324240745\n}\n\nFile v1.0.0:skill-card.md\n\n## Description: <br>\nDawn Code Master provides hardened coding standards for writing, reviewing, testing, and refactoring Python and TypeScript code with consistent quality. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[chen6896qqwee](https://clawhub.ai/user/chen6896qqwee) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and engineers use this skill to guide coding agents through Python and TypeScript implementation, review, testing, security checks, and refactoring workflows. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill can guide edits and standard development checks in a workspace, including repositories with sensitive code or configuration. <br>\nMitigation: Review proposed code changes, shell commands, and test or formatting actions before accepting them. <br>\nRisk: Coding guidance can be incomplete or inappropriate for a repository's local standards. <br>\nMitigation: Apply the skill alongside project-specific tests, linters, security review, and existing contribution rules. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/chen6896qqwee/skills/dawn-code-master) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, code, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown guidance with code snippets, checklists, and shell commands] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May recommend local formatting, linting, test, and workspace review actions.] <br>\n\n## Skill Version(s): <br>\n1.0.0 (source: server release metadata and skill metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>","readmeExcerpt":"Skill: 代码大师｜编程铁律 Owner: chen6896qqwee Summary: AI 写的代码一上生产就崩——不是它不会写，是没人给它立规矩。 代码大师把「写、审、测、重构」的标准炼成一条硬规矩，整合 80k★ agent-skills、23k★ claude-skills 等顶级技能集，让每一行 AI 代码都过验收。 触发词：写代码、修bug、代码审查、PR review、重构、设计评审、API设计、测试用例、spec 驱动开发。 Tags: code-review:6.1.1, coding:6.1.1, latest:6.1.1, python:6.1.1, typescript:6.1.1 Version history: v6.1.1 | 2026-10-09T02:47:37.361Z | user 技能页文案升级：痛点钩子前置 + 保留触发词 v6.1.0 | 2026-07-27T02:55:37.","codeSnippets":[],"executableExamples":[{"language":"text","snippet":"[ ] py_compile / tsc — syntax clean\n[ ] pytest pass\n[ ] Type hints on all public functions\n[ ] No bare except / no `any`\n[ ] No hardcoded secrets\n[ ] f-strings / template literals — never format() or %\n[ ] pathlib / fs paths — never os.path\n[ ] Docstrings on all public APIs\n[ ] No function > 30 lines"},{"language":"python","snippet":"# Python docstring (Google-style)\ndef rebalance(code: str, target_pct: float) -> dict:\n    \"\"\"Rebalance ETF position to target weight.\n\n    Args:\n        code: ETF code, e.g. \"515790\".\n        target_pct: Target allocation as decimal 0-1.\n\n    Returns:\n        {order_id, filled_qty, avg_price}\n\n    Raises:\n        ValueError: If target_pct > max_single_weight.\n    \"\"\""},{"language":"typescript","snippet":"// TypeScript JSDoc\n/** Rebalance ETF position to target weight. */\nexport function rebalance(code: string, targetPct: number): OrderResult"},{"language":"python","snippet":"# ❌ Bad\ntry:\n    result = api.buy(code, qty)\nexcept:\n    pass\n\n# ✅ Good\ntry:\n    result = api.buy(code, qty)\nexcept ApiError as e:\n    log(f\"Buy failed: {e}\")\n    raise"},{"language":"python","snippet":"# ✅ Comprehensions over loops\nsquares = [x**2 for x in range(10)]\nlookup = {item.id: item for item in items}\n\n# ✅ Context managers for I/O\nwith open(path, encoding=\"utf-8\") as f:\n    data = f.read()\n\n# ✅ Unpacking & walrus\nfirst, *rest = items\nif match := re.search(pattern, text):\n    print(match.group())\n\n# ✅ EAFP (Easier to Ask Forgiveness than Permission)\ntry:\n    value = d[key]\nexcept KeyError:\n    value = default\n\n# ✅ f-strings\nmsg = f\"{name} has {count} items\"\n\n# ✅ pathlib\nfrom pathlib import Path\nconfig = Path.home() / \".config\" / \"app.json\"\n\n# ✅ dataclasses\n@dataclass\nclass Position:\n    code: str\n    qty: int\n    cost: float\n\n# ✅ enumerate, zip, itertools\nfor i, item in enumerate(items):\n    ...\nfor a, b in zip(xs, ys, strict=True):\n    ..."},{"language":"python","snippet":"# ❌ Mutable defaults\ndef bad(items=[]):      # Shared across calls!\n\ndef good(items=None):\n    items = items or []\n\n# ❌ Bare except\ntry:\n    ...\nexcept:  # Catches SystemExit, KeyboardInterrupt\n\n# ❌ from module import *\n# ❌ == None  (use `is None`)\n# ❌ len(x) == 0  (use `not x`)\n# ❌ String concat in loops  (use join)\n# ❌ Global mutable state"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\r\nname: dawn-code-master\r\ndescription: >\r\n  AI 写的代码一上生产就崩——不是它不会写，是没人给它立规矩。\r\n  代码大师把「写、审、测、重构」的标准炼成一条硬规矩，整合 80k★ agent-skills、23k★ claude-skills 等顶级技能集，让每一行 AI 代码都过验收。\r\n  触发词：写代码、修bug、代码审查、PR review、重构、设计评审、API设计、测试用例、spec 驱动开发。\r\nmetadata:\r\n  version: 6.1.0\r\n  sources:\r\n    - focused-fix (alirezarezvani/claude-skills)\r\n    - pr-review-expert (alirezarezvani/claude-skills)\r\n    - spec-driven-workflow (alirezarezvani/claude-skills)\r\n    - api-design-reviewer (alirezarezvani/claude-skills)\r\n    - api-test-suite-builder (alirezarezvani/claude-skills)\r\n    - self-eval — alirezarezvani/claude-skills\r\n    - skill-tester (alirezarezvani/claude-skills)\r\n    - mcp-server-builder (alirezarezvani/claude-skills)\r\n    - e2e-skills (voidmatcha/e2e-skills)\r\n    - avoid-ai-writing (conorbronsdon/avoid-ai-writing)\r\n    - cc-skills-golang (samber/cc-skills-golang)\r\n    - agentic-stack (codejunkie99/agentic-stack)\r\n    - antigravity-skills (krishnakanthb13)\r\n    - codebase-onboarding / migration-architect / ci-cd-pipeline-builder\r\n    - performance-profiler / database-designer / sql-database-assistant\r\n    - observability-designer / ship-gate / tech-debt-tracker\r\n    - changelog-generator / dependency-auditor / git-worktree-manager\r\n    - monorepo-navigator / rag-architect / agent-designer / agent-workflow-designer\r\n    - dawn-code-master v4.0 (local)\r\n    - agent-skills (addyosmani/agent-skills, 80k star)\r\n    - yao-meta-skill (yaojingang/yao-meta-skill, 2.1k star)\r\n    - ratel-ai/ratel (ratel-ai/ratel, 351 star)\r\n    - context-engineering-kit (NeoLabHQ/context-engineering-kit, 1.3k star)\r\n    - claude-skills (borghei/Claude-Skills, 411 star)\r\n  dawn:\r\n    requires:\r\n      bins: [python, node, pwsh, git]\r\n    permissions:\r\n      - exec: [python, node, ruff, black, pytest, pwsh, git]\r\n      - filesystem: [read/write workspace]\r\n---\r\n\r\n# Dawn Code Master v6.0\r\n\r\n**50+ 顶级编码技能集成 + 全生命周期工作流 + 反合理化验证门禁。** 写代码、修bug、审PR、做设计，按这个来。\r\n\r\n---\r\n\r\n## 0. Skill Router\r\n\r\n### Core Operating Behaviors\r\n\r\n1. Surface Assumptions - Before implementing, explicitly state assumptions\r\n2. Manage Confusion - Stop, name confusion, present tradeoff, wait for resolution\r\n3. Push Back - Point out problems directly, quantify downsides, propose alternatives\r\n\r\n### When to Use What\r\n\r\n| Phase | Task | Skill |\r\n|-------|------|-------|\r\n| Define | Dont know what you want | interview-me |\r\n| Define | Rough concept needs refining | [s2] Spec-Driven Dev |\r\n| Plan | Have spec, need tasks | [s3] Planning |\r\n| Build | Implementing code | [s4] Incremental Impl |\r\n| Build | UI work | Frontend principles |\r\n| Build | API work | [s16] API Design |\r\n| Build | Need better context | [s6] Context Eng |\r\n| Build | High stakes / unfamiliar code | [s7] Doubt-Driven |\r\n| Verify | Writing/running tests | [s5] TDD |\r\n| Verify | Bug fixing | [s8] Focused-Fix |\r\n| Review | Reviewing code | [s9] PR Review |\r\n| Review | Too complex | [s10] Code Simplification |\r\n| Review | Security concerns | [s11] Security |\r\n| Review |"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn71mxvdsyxaq6jpehtw8pc8t183hwzn\",\n  \"slug\": \"dawn-code-master\",\n  \"version\": \"6.1.1\",\n  \"publishedAt\": 1791514057361\n}"},{"path":"skill-card.md","content":"## Description:\n\nGuides coding agents through specification, implementation, testing, review, and release with structured quality checks.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[chen6896qqwee](https://clawhub.ai/user/chen6896qqwee)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers use this skill to guide coding agents through scoped fixes, feature development, API design, testing, code review, and release preparation.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Broad coding workflows can change project files or run commands beyond the intended task.\n\nMitigation: Use a bounded workspace and review proposed commands, file changes, and commits before execution.\n\n## Reference(s):\n\n- [代码大师｜编程铁律 on ClawHub](https://clawhub.ai/chen6896qqwee/skills/dawn-code-master)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Code, Markdown, Shell commands, Configuration instructions]\n\n**Output Format:** [Text and Markdown, with code or commands as needed]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May guide workspace file changes, tests, reviews, and release checks.]\n\n## Skill Version(s):\n\n6.1.1 (source: ClawHub release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"AI 写的代码一上生产就崩——不是它不会写，是没人给它立规矩。 代码大师把「写、审、测、重构」的标准炼成一条硬规矩，整合 80k★ agent-skills、23k★ claude-skills 等顶级技能集，让每一行 AI 代码都过验收。 触发词：写代码、修bug、代码审查、PR review、重构、设计评审、API设计、测试用例、spec 驱动开发。 Skill: 代码大师｜编程铁律 Owner: chen6896qqwee Summary: AI 写的代码一上生产就崩——不是它不会写，是没人给它立规矩。 代码大师把「写、审、测、重构」的标准炼成一条硬规矩，整合 80k★ agent-skills、23k★ claude-skills 等顶级技能集，让每一行 AI 代码都过验收。 触发词：写代码、修bug、代码审查、PR review、重构、设计评审、API设计、测试用例、spec 驱动开发。 Tags: code-review:6.1.1, coding:6.1.1, latest:6.1.1, python:6.1.1, typescript:6.1.1 Version history: v6.1.1 | 2026-10-09T02:47:37.361Z | user 技能页文案升级：痛点钩子前置 + 保留触发词 v6.1.0 | 2026-07-27T02:55:37.","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1149,"uniquenessScore":59,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-11T03:44:49.131Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-11T03:44:49.131Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-11T07:39:20.764Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}