01是什么What it is
一个 Codex Skill,把「可发布吗?」拆成可勾选、可验证的检查项,把「写 README」变成结构化、以证据驱动的文档。发布动作(git push、建仓库)不经用户显式授权绝不执行。
A Codex Skill that turns "is it publishable?" into a checklist of verifiable items, and "write a README" into an evidence-driven document. Publishing actions never run without explicit user authorization.
✓ Evidence-based checklist
逐项检查版本库、必备文件、README 质量、敏感信息、可验证性;每项都有命令输出/文件存在/git 状态作为证据。
Per-item checks of repo state, required files, README quality, sensitive info, and verifiability; every item backed by command output, file existence, or git state.
✓ Bilingual README
独立 README.md(英文)+ README.zh-CN.md(中文),切换链接互指、结构逐节镜像。
Standalone README.md (EN) + README.zh-CN.md (ZH), cross-linked switch, mirrored structure.
✓ Safety redline
API key / token / 私钥 / 个人数据 / 绝对路径一律禁止,命中即阻断发布。
API keys / tokens / private keys / personal data / absolute paths are hard-blocked; any hit halts release.
✓ Validatable
自带 scripts/validate_skill_package.py 与本包契约的单元测试。
Ships scripts/validate_skill_package.py plus a unit test for its own package contract.
02为什么需要Why
直觉式发布容易漏项、缺证据、埋敏感信息。本 skill 用固定清单与红线兜底。
Instinct-driven releases miss items, lack evidence, and leak secrets. This skill enforces a fixed checklist and a hard redline.
Instinct(反例)
"看起来差不多" / 一个 README 随便写 / 中英混排 / 想发就发
"Looks about right" / one sloppy README / mixed-language / publish on a whim
This skill(本方案)
每项有证据 / 固定结构 + 双语独立 / 敏感信息扫描 / 发布动作门禁
Every item evidenced / fixed structure + dual files / secret scan / gated publishing
03快速开始Quick Start
校验本包契约,并运行本地单元测试。
Validate this package's contract and run its local unit tests.
# 校验包契约 $ python3 scripts/validate_skill_package.py . → PASS: oss-release-prep package contract # 运行单元测试 $ python3 -m unittest discover -s tests → exit 0
04用法Usage
发布检查清单覆盖五个层面;敏感信息扫描是独立红线证据项。
The release checklist covers five layers; the secret scan is an independent redline evidence item.
| Layer | 覆盖 | Scope |
|---|---|---|
| A Repo state | git init / 默认分支 / 无敏感文件跟踪 | git init / default branch / no tracked secrets |
| B Required files | README.md / 中文版 / LICENSE / .gitignore / .gitattributes | README.md / ZH / LICENSE / .gitignore / .gitattributes |
| D Secret scan | API key / token / 私钥 / 个人数据 / 绝对路径 → 零命中才可发布 | API key / token / key / PII / absolute path → zero hits to publish |
| G Discoverability | About / topics(ai llm skill persona self-memory)/ Discussions / 主页 | About / topics (ai llm skill persona self-memory) / Discussions / homepage |
| K Review gate | 更新监管工具后做一次外部 reviewer 代码审查再发布 | external reviewer pass after updating guard tools before release |
05LicenseLicense
MIT License · 版权Copyright (c) 2026 xsoway