Summary
When a language has no lane, or a lane's tool is not installed, code-tidying:audit-dead-code
0.23.2 reports the lane as skipped and stops there. The owner's intent is that the skill covers
all source code accurately. So when it cannot cover some code, it should close the gap instead of
only labeling it.
Current limits, from the skill itself:
- "Never fetch": a lane with no local binary is
skipped, and no package runner is invoked
(SKILL.md "Hard rules").
- Rust and .NET are permanently out of scope because their detectors build or execute project code.
The same reason covers clangd and jdtls (context/lanes.md:124-130).
- Languages with no lane at all get no mention (see the sibling coverage-accounting issue).
Fix
When coverage is incomplete, the skill offers a path per gap. The default stays read-only, and
every action needs the user's consent:
- Name the gap: which files, which language, and why (no lane, tool not installed, excluded by
policy).
- Offer to file an issue against this plugin for a language or tool the skill does not
support, pre-filled with the file count and language.
- Offer to research and install: run
/discovery:research to pick a detector for the language,
show the choice and its install command, and install and run it only after the user approves.
Record the detector's precision as unmeasured until the trap fixtures cover it.
- Revisit the build-free rule as an opt-in, not a default. For Rust, .NET, C/C++, and Java,
offer a consent-gated lane that may build the project. The consent prompt states plainly that
this executes repo code (build.rs, proc macros, MSBuild targets). Keep it off for untrusted
repos.
This changes the "Never fetch" hard rule. The rule's safety property (no silent network or code
execution) is kept by the consent gate, not by refusing.
Verification
- Done when a run over a fixture with a language that has no lane prints the gap and offers both
paths, and no install or build happens without an explicit yes.
- The research-and-install path is exercised once end to end, for example on a repo with Java and
no detector, and the chosen tool's output is parsed into the existing record schema.
Related
Summary
When a language has no lane, or a lane's tool is not installed,
code-tidying:audit-dead-code0.23.2 reports the lane as
skippedand stops there. The owner's intent is that the skill coversall source code accurately. So when it cannot cover some code, it should close the gap instead of
only labeling it.
Current limits, from the skill itself:
skipped, and no package runner is invoked(SKILL.md "Hard rules").
The same reason covers clangd and jdtls (
context/lanes.md:124-130).Fix
When coverage is incomplete, the skill offers a path per gap. The default stays read-only, and
every action needs the user's consent:
policy).
support, pre-filled with the file count and language.
/discovery:researchto pick a detector for the language,show the choice and its install command, and install and run it only after the user approves.
Record the detector's precision as unmeasured until the trap fixtures cover it.
offer a consent-gated lane that may build the project. The consent prompt states plainly that
this executes repo code (
build.rs, proc macros, MSBuild targets). Keep it off for untrustedrepos.
This changes the "Never fetch" hard rule. The rule's safety property (no silent network or code
execution) is kept by the consent gate, not by refusing.
Verification
paths, and no install or build happens without an explicit yes.
no detector, and the chosen tool's output is parsed into the existing record schema.
Related
playbooks:repo-sweepsweep ofmelodic-software/.github(PR chore(skill-quality): harden static checker + record terminal retrofit scope #153).unreferenced-file detection.