skill-candidates/repo-b-starframe-ops/SKILL.md
Validate <PRIVATE_REPO_B> STARFRAME API, AvatarCore proxy, persona registry, heartbeat contract, and degraded-mode guardrails.
npx skillsauth add grtninja/skill-arbiter repo-b-starframe-opsInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use this skill for STARFRAME runtime contract and persona/runtime behavior changes in <PRIVATE_REPO_B>.
AGENTS.md, BOUNDARIES.md, HEARTBEAT.md, and INSTRUCTIONS.md before edits.starframe/ and starframe/proxy flowstests/proxy intent routing and fail-closed behaviortests/starframe persona/runtime policy and scoring surfacesHEARTBEAT_OK when no actionable issues).Run from <PRIVATE_REPO_B> root:
python -m pytest tests/proxy/test_avatar_proxy_core.py tests/starframe/test_persona_registry.py
python -m pytest tests/starframe/test_provider_score.py tests/starframe/test_degraded_mode_rules.py
python -m pytest tests/starframe/test_unified_api.py tests/api/test_starframe_service.py
# If heartbeat behavior changed, run heartbeat-listed checks only and verify exact success token:
# HEARTBEAT_OK
Optional strict lint/test lane:
ruff check starframe tests
pytest -q
python -m starframe --host 127.0.0.1 --port 9010 --no-start-services
curl -s http://127.0.0.1:9010/health
curl -s http://127.0.0.1:9010/v1/unified/status
curl -s http://127.0.0.1:9010/v1/shim/rag/status
starframe/proxy/avatar.py dispatch/heartbeat behavior fail-closed when intent payloads are invalid.AvatarProxyCore budget and penalty math unless migration is documented.Persona and telemetry payloads when scaling/energy logic changes.HEARTBEAT_OK when no actionable trust-layer issue exists.Use this skill only for STARFRAME/AvatarCore proxy and persona-runtime governance in <PRIVATE_REPO_B>.
Do not use this for unrelated lanes; route those through $skill-hub and the most specific matching skill.
references/starframe-checklist.mdIf the lane is unresolved, blocked, or ambiguous:
$skill-hub for chain recalculation.tools
Run a defender-first security sweep on code, configs, prompts, model/tooling surfaces, or third-party contribution lanes. Use when a request involves safe bug, leak, zero-day-class, exploit, or hack hunting for protection, when contributing to outside repositories and you want a focused security pass, or when touching auth, secrets, permissions, network exposure, prompt/tool boundaries, data flow, or update/build surfaces. This skill is defensive only and must never be used for weaponization or unauthorized access.
development
Validate and repair VRM Sandbox startup acceptance with shim-first local model authority, frontend/backend bring-up, and avatar-runtime launch proof. Use when launch behavior, chat handoff, voice fallback, or runtime bridge acceptance must be verified end to end.
documentation
Align documented voice-command catalogs, endpoint action allowances, and live runtime handlers so operator-visible voice surfaces match what the stack can actually execute. Use when voice command docs, parser matrices, endpoint permissions, or runtime action routing drift apart.
development
Track SkillHub trend and topic drift, maintain a bounded rewrite watchlist, and surface emerging gaps worth turning into repo-owned skills. Use when the marketplace query set shows new families or when the current shortlist has gone stale.