agentsclimarketplace

Rot canary

Skill HetCreep/CoalMine/plugin/skills/rot-canary

Code-health scan — dead code, bug-prone logic, resource leaks, concurrency bugs, silent failures, input-boundary issues, doc rot. Triggers on: "/rot-canary", "rot-canary", "code-health" (legacy aliases: "/rotcanary", "rotcanary"). Auto-runs at session end on touched files (QUICK, report only) via platform hooks — auto-wired by the Claude Code plugin, manual elsewhere. Run manually for fix mode. Reports; fixes on request via choice-gated menu.From its SKILL.md

Install
npx -y skills add HetCreep/CoalMine --skill rot-canary

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

3 things to look at

  • skips confirmationTells the agent to proceed without asking first, 2 times: "honor .coalmine.json autoFixMode as the pre-chosen option" and 1 more.
  • 11 stars11 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
  • runs commandsInstructs the agent to run 2 commands, including `git stash/commit (checkpoint before applying safe fixes)` and 1 more.

SKILL.md

7.4 KB, ~1.7k tokens by cl100k_base, as published. Nobody here has run it

Rot-Canary

Language: Generate EVERYTHING at runtime in the user's language — questions, answer options, menu labels, recommendations, report narrative. Detect from their messages; never default to English just because this file is English. English is allowed only for technical terms: commands, paths, code identifiers, severity labels (CRITICAL/HIGH/MEDIUM/LOW), and tier names (Light/Standard/Heavy).

Scan code for rot. Report CONFIRMED findings. Fix on request.

Parameters

  • SCOPE: touched files (default) | diff | named files | whole repo. Touched-files scan is hybrid-capped: all if ≤ autoScanFileCap, else the autoScanFileCapSlice most-recently-modified files (warn the user). A touched file matching scanExcludePaths (lab/throwaway tooling only — never shipped/tracked source) is dropped before the cap; the nudge notes the skip count.
  • DEPTH: QUICK (default) | DEEP

Categories

  1. Bug-risk — null deref, wrong operator, off-by-one, missing return
  2. Dead / unreachable — zero-ref symbols, code after return/throw, always-true guards
  3. Disconnected — exists but never wired to entry point, half-done refactor
  4. Duplication — copy-paste diverged, two sources of truth for one constant
  5. Resource leak — undisposed handle/stream/COM, subscription never removed
  6. Async — unawaited task, .Result/.Wait() deadlock, blocking on UI thread
  7. Silent failure — empty catch, success on partial completion, ignored return code
  8. Input security — unvalidated input, injection, path traversal, secret in code/log
  9. Performance — O(n²) in hot path, N+1, unbounded growth, work on UI thread
  10. Doc rot — comment contradicts code, stale TODO, wrong param in docstring

Discipline

  • Report only CONFIRMED. Unverifiable → separate "SUSPECTED" list.
  • Cite evidence (file:line, call-site count, the absent catch).
  • "Dead" = zero-reference reachability (the static heuristic): zero references across ALL entry routes — reflection, DI, events, public API, tests — not a single-file grep.

Fix mode (choice-gated)

Standing consent: honor .coalmine.json autoFixMode as the pre-chosen option (the config IS the chosen option) — off = report only, no menu · safe = apply safe/reversible fixes automatically (still checkpoint → build/test → revert if red) · interactive (default) = present the menu below.

After any scan report in an interactive session — manual run OR hook-nudged auto-scan — you MUST present this menu via ask_question (skip only when findings are zero, no user is present, or autoFixMode pre-decided above):

  • Apply safe fixes: mechanical, fully reversible edits only (dead imports, commented-out blocks, formatting). Each fix: checkpoint (git stash/commit in a git repo; else copy the file aside — never assume git exists) → apply → build + tests → auto-revert if newly red.
  • Let me pick: list findings; user selects.
  • Report only: exit unchanged.

NEVER auto-fix: live/reachable path · logic change · "API looks wrong" (ground via source-grounding first) · framework-wired code that only looks dead · SUSPECTED findings.

Output

| # | path:line | category | severity | finding | evidence | fix |

Then: SUSPECTED list · coverage gaps · counts + top 3 to fix.

Severity: CRITICAL (data loss/security/crash on normal path) · HIGH (real bug/leak on reachable path) · MEDIUM (dead/dup/unwired) · LOW (style/doc rot)

Cadence

Stop hook → auto QUICK on the session's touched files (report only), hybrid-capped per .coalmine.json (see Parameters). Manual whole-repo DEEP sweep when needed. Auto-wiring is platform-dependent — read references/cadence.md before claiming auto-scan works on the current platform.

Tooling

Per-stack build/dead-code/lint commands: read references/tooling.md when selecting scan tools.

Escalation — Scope & Model Quality

Tiers are capability targets, not platform commands — resolve each to your host's nearest lever. No lever for one? Degrade gracefully — never fake parallelism you can't do; escalate via model tier + reasoning depth instead.

LevelIntentCapability targetCost
LightFast scan, minimal coverageCheapest model · single agent, no sub-agents.Low
StandardBalanced scan, module-level coverageBalanced model · raised reasoning · sub-agents per category only if your platform runs concurrent workers (else single-agent).Balanced
HeavyFull scan, maximum coverageMost capable model + largest context · deepest reasoning · max sub-agent fan-out if supported · adversarial cross-check where available.High

Per-platform Heavy levers + Heavy-run durability: read references/escalation.md before a Heavy run. No concurrent fan-out on your host → escalate by model + reasoning only.

Agent Context (interactive): score the tier rubric, then call ask_question once with the 3 tiers — the pick marked , score shown, labels localized — and wait for the choice before starting. ask_question = your platform's question tool: Claude Code AskUserQuestion · Cline ask_question · Copilot askQuestions · Gemini CLI ask_user (business-tier product; individual tiers ended 2026-06-18 → Antigravity CLI) · Codex request_user_input · Cursor/Devin Desktop (ex-Windsurf)/Antigravity built-in prompts; none → numbered text menu.

Tier rubric (deterministic): +1 each — ① >20 files or whole-repo/cross-module reach ② >2 of this skill's categories relevant ③ release/security/pre-ship context ④ findings will drive code changes. 0–1 Light · 2–3 Standard · 4 Heavy. Freshness cap: scope already audited ≥Standard this session → cap at Light (re-auditing fresh ground wastes tokens; scope to what changed). Default tier: honor .coalmine.json defaultTier unless the user requests a tier for that run — an explicit request overrides everything.

Hook Context (auto-triggered): auto-Light, no tier question, no sub-agents — report first. Interactive session (a user is present) → offer the fix menu after the report; non-interactive → report-only. Never fix without a chosen option.

Entanglement: after the report, if confirmed findings fall in another canary's domain, offer it once via ask_question (one line, max one offer): perf/N+1 → scale-canary · contract/serialization/config → drift-canary · failure-path/retry → resilience-audit · logging/metrics → telemetry-canary · coupling/DI → testability-canary · dependency/CVE → supply-chain-audit · unverified version-sensitive claim → source-grounding · missing/stale rule → gold-standard.

Self error-report: if this skill misbehaves (contradictory instruction, broken procedure, wrong finding class), OFFER to file it at https://github.com/HetCreep/CoalMine/issues/new/choose with a user-reviewed summary — never auto-submit, never include unapproved code or paths.

What ships with it: 4 files

5.3 KB alongside SKILL.md

references/

Keep looking

Skills are one crate of 325,949. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.