skills/process/read-only-ops/SKILL.md
Read-only exploration, inspection, and reporting without modifications. Explore and report on code/config/state without writing or modifying anything.
npx skillsauth add notque/claude-code-toolkit read-only-opsInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
This skill operates as a safe exploration and reporting mechanism without ever modifying files or system state. Use it when you need to gather evidence, verify facts, or show current state to the user.
The core principle: Observation Only. Gather evidence. Report facts. Keep all state unchanged.
Goal: Understand exactly what the user wants to know before exploring.
Step 1: Parse the request
Determine:
Step 2: Confirm scope if ambiguous
If the request could match dozens of results or span the entire filesystem, clarify before proceeding. If the scope is clear, proceed directly. This prevents wasting tokens on over-broad searches.
Gate: Scope is understood. Target locations are identified. Proceed only when gate passes.
Goal: Collect evidence using read-only tools. Tools must preserve state.
Step 1: Execute read-only operations
Allowed commands (safe for read-only use):
ls, find, wc, du, df, file, stat
ps, top -bn1, uptime, free, pgrep
git status, git log, git diff, git show, git branch
sqlite3 ... "SELECT ..."
curl -s (GET only)
date, timedatectl, env
Out-of-scope commands (are outside the read-only boundary):
mkdir, rm, mv, cp, touch, chmod, chown
git add, git commit, git push, git checkout, git reset
echo >, cat >, tee (file writes)
INSERT, UPDATE, DELETE, DROP, ALTER SQL
npm install, pip install, apt install
pkill, kill, systemctl restart/stop
Rationale: Even "harmless" state changes violate the read-only boundary. Use the read-only equivalent instead (e.g., ls -la instead of mkdir -p, git status instead of git add, SELECT instead of INSERT).
Step 2: Record raw output
Show complete command output. Show complete output, truncating only unless output exceeds reasonable display length, in which case show representative samples with counts. The user must be able to verify your claims from the evidence shown.
Gate: All requested data has been gathered with read-only commands. No state was modified. Proceed only when gate passes.
Goal: Present findings in a structured, verifiable format.
Step 1: Summarize key findings at the top
Lead with what the user asked about. Answer the question first, then provide supporting details. This prevents burying the answer in verbose output.
Step 2: Show evidence
Include command output, file contents, or search results that support the summary. The user must be able to verify claims from the evidence shown. Show the raw data — show the raw data.
Step 3: List files examined
Document which files were read for transparency:
### Files Examined
- `/path/to/file1` - why it was read
- `/path/to/file2` - why it was read
Gate: Report answers the user's question with verifiable evidence. All claims are supported by shown output.
Cause: Skill boundary violation — tried to modify a file. Solution: This skill only permits Read, Grep, Glob, and read-only Bash. Report findings verbally; write them to files only with explicit user permission. Crossing the read-only boundary defeats the purpose of the skill.
Cause: Attempted destructive or state-changing command. Solution: Use the read-only equivalent. For example:
ls -la instead of mkdir -pgit status instead of git addSELECT instead of INSERTstat or [ -d /path ] && echo exists instead of mkdir -p /tmp/testCause: Search returned hundreds of matches without filtering.
Solution: Return to Phase 1. Narrow scope by file type, directory, or pattern before re-executing. For example, instead of searching the entire filesystem for "config", search ~/.config/ or ./etc/ with a specific file extension.
Investigating Everything: User asks about API server status; you audit all services, configs, logs, and dependencies. Why wrong: Wastes tokens, buries the answer. The scope extends beyond the specific question. Do instead: Answer the specific question. Offer to investigate further if needed.
Summarizing Away Evidence: "The repository has 3 modified files and is clean" instead of showing git status output. Why wrong: User cannot verify the claim. Missing details (which files? staged or unstaged?) prevent verification. Do instead: Show complete command output. Let the user draw conclusions.
Exploring Before Scoping: User says "find config files"; you immediately search entire filesystem. Why wrong: May return hundreds of irrelevant results. Wastes time without direction. Do instead: Confirm scope (which config? where? what format?) then search targeted locations.
This skill enforces the Observation Only architectural pattern to enable safe, passive exploration without side effects. The constraint is absolute: tools must preserve state, even to "verify" something. Verification that requires modification (e.g., "is this directory writable?") should use read-only checks (stat, ls -la, test operators).
This skill follows the CLAUDE.md principle of verification over assumption and artifacts over memory. All claims are backed by shown evidence. No paraphrasing. No hidden state changes.
documentation
Document translation: quick/normal/refined modes with chunked parallel subagents and glossary support.
development
AI image generation: Gemini and Nano Banana backends; single/series/batch workflows with prompt-to-disk.
testing
Unified voice content generation pipeline with mandatory validation and joy-check. 13-phase pipeline: LOAD, GROUND, STATS-CHECKPOINT, GENERATE, HOOK-GATE, VALIDATE, REFINE, VARIETY-GATE, JOY-CHECK, ANTI-AI, CLOSE-GATE, OUTPUT, CLEANUP. Use when writing articles, blog posts, or any content that uses a voice profile. Use for "write article", "blog post", "write in voice", "generate content", "draft article", "write about".
documentation
Critique-and-rewrite loop for voice fidelity validation.