skill-candidates/repo-d-mass-index-ops/SKILL.md
Run UI-and-packaging mass-index operations for <PRIVATE_REPO_D> workspace trees. Use when scanning renderer components, Electron startup files, workspace packages, and packaging scripts while aggressively excluding generated build artifacts.
npx skillsauth add grtninja/skill-arbiter repo-d-mass-index-opsInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use this wrapper for desktop UI and packaging lanes in <PRIVATE_REPO_D>.
safe-mass-index-core only for non-desktop discovery lanes.Use these anchors to keep the query lane tied to desktop packaging behavior:
rendererpreloadwindowBoundswindowManagerelectron/mainpackages/desktop-shellstorybook-staticapp.asarUse this skill when the task is primarily about:
Do not use this skill for:
Run from <PRIVATE_REPO_D> root:
Use the standard safe-mass-index-core build command with the repo-d exclusion profile in references/presets.md.
Keep frontend/Electron artifacts excluded by default.
Renderer and component sweep:
python3 "$CODEX_HOME/skills/safe-mass-index-core/scripts/index_query.py" \
--index-dir .codex-index \
--path-contains renderer \
--path-contains ui \
--ext tsx \
--limit 180 \
--format table
Packaging workspace sweep:
python3 "$CODEX_HOME/skills/safe-mass-index-core/scripts/index_query.py" \
--index-dir .codex-index \
--path-contains packages \
--path-contains build \
--lang typescript \
--limit 180 \
--format table
references/presets.mdIf results stay ambiguous, send filter args plus .codex-index/run.json to $skill-hub for deterministic rerouting.
tools
Run a defender-first security sweep on code, configs, prompts, model/tooling surfaces, or third-party contribution lanes. Use when a request involves safe bug, leak, zero-day-class, exploit, or hack hunting for protection, when contributing to outside repositories and you want a focused security pass, or when touching auth, secrets, permissions, network exposure, prompt/tool boundaries, data flow, or update/build surfaces. This skill is defensive only and must never be used for weaponization or unauthorized access.
development
Validate and repair VRM Sandbox startup acceptance with shim-first local model authority, frontend/backend bring-up, and avatar-runtime launch proof. Use when launch behavior, chat handoff, voice fallback, or runtime bridge acceptance must be verified end to end.
documentation
Align documented voice-command catalogs, endpoint action allowances, and live runtime handlers so operator-visible voice surfaces match what the stack can actually execute. Use when voice command docs, parser matrices, endpoint permissions, or runtime action routing drift apart.
development
Track SkillHub trend and topic drift, maintain a bounded rewrite watchlist, and surface emerging gaps worth turning into repo-owned skills. Use when the marketplace query set shows new families or when the current shortlist has gone stale.