Rot canary
Nine quality-canary skills for AI coding agents - code health, world-class rule completeness, grounding, supply chain, resilience, drift & more - plus the auto-cadence hooks that run them unprompted at session start and session end. Cross-agent, consent-gated, token-lean.
npx -y skills add HetCreep/CoalMine --skill rot-canaryAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 11 stars11 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Code-health scan — dead code, bug-prone logic, resource leaks, concurrency bugs, silent failures, input-boundary issues, doc rot. Triggers on: "/rot-canary", "rot-canary", "code-health" (legacy aliases: "/rotcanary", "rotcanary"). Auto-runs at session end on touched files (QUICK, report only) via platform hooks — auto-wired by the Claude Code plugin, manual elsewhere. Run manually for fix mode. Reports; fixes on request via choice-gated menu.
SKILL.md
3.9 KB, as published. Nobody here has run it
Rot-Canary
<!-- SHARED:LANGUAGE_HEADER -->Scan code for rot. Report CONFIRMED findings. Fix on request.
Parameters
- SCOPE: touched files (default) | diff | named files | whole repo. Touched-files scan is hybrid-capped: all if ≤
autoScanFileCap, else theautoScanFileCapSlicemost-recently-modified files (warn the user). - DEPTH: QUICK (default) | DEEP
Categories
- Bug-risk — null deref, wrong operator, off-by-one, missing return
- Dead / unreachable — zero-ref symbols, code after return/throw, always-true guards
- Disconnected — exists but never wired to entry point, half-done refactor
- Duplication — copy-paste diverged, two sources of truth for one constant
- Resource leak — undisposed handle/stream/COM, subscription never removed
- Async — unawaited task,
.Result/.Wait()deadlock, blocking on UI thread - Silent failure — empty catch, success on partial completion, ignored return code
- Input security — unvalidated input, injection, path traversal, secret in code/log
- Performance — O(n²) in hot path, N+1, unbounded growth, work on UI thread
- Doc rot — comment contradicts code, stale TODO, wrong param in docstring
Discipline
- Report only CONFIRMED. Unverifiable → separate "SUSPECTED" list.
- Cite evidence (file:line, call-site count, the absent catch).
- "Dead" = zero-reference reachability (the static heuristic): zero references across ALL entry routes — reflection, DI, events, public API, tests — not a single-file grep.
Fix mode (choice-gated)
Standing consent: honor .coalmine.json autoFixMode as the pre-chosen option (the config IS the chosen option) — off = report only, no menu · safe = apply safe/reversible fixes automatically (still checkpoint → build/test → revert if red) · interactive (default) = present the menu below.
After any scan report in an interactive session — manual run OR hook-nudged auto-scan — you MUST present this menu via ask_question (skip only when findings are zero, no user is present, or autoFixMode pre-decided above):
- Apply safe fixes: mechanical, fully reversible edits only (dead imports, commented-out blocks, formatting). Each fix: checkpoint (git stash/commit in a git repo; else copy the file aside — never assume git exists) → apply → build + tests → auto-revert if newly red.
- Let me pick: list findings; user selects.
- Report only: exit unchanged.
NEVER auto-fix: live/reachable path · logic change · "API looks wrong" (ground via source-grounding first) · framework-wired code that only looks dead · SUSPECTED findings.
Output
| # | path:line | category | severity | finding | evidence | fix |
Then: SUSPECTED list · coverage gaps · counts + top 3 to fix.
Severity: CRITICAL (data loss/security/crash on normal path) · HIGH (real bug/leak on reachable path) · MEDIUM (dead/dup/unwired) · LOW (style/doc rot)
Cadence
Stop hook → auto QUICK on the session's touched files (report only), hybrid-capped per .coalmine.json (see Parameters). Manual whole-repo DEEP sweep when needed. Auto-wiring is platform-dependent — read references/cadence.md before claiming auto-scan works on the current platform.
Tooling
Per-stack build/dead-code/lint commands: read references/tooling.md when selecting scan tools.