Devrites api interface
Skill ViktorsBaikers/DevRites/pack/generated/codex/skills/devrites-api-interface
Internal DevRites skill; DevRites agents invoke it explicitly, not by prompt match.From its SKILL.md
npx -y skills add ViktorsBaikers/DevRites --skill devrites-api-interfaceAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
2 things to look at
- no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
- 1 stars1 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
SKILL.md
7.0 KB, ~1.6k tokens by cl100k_base, as published. Nobody here has run it
Codex compatibility
This is the Codex mirror of a DevRites skill. In Codex:
- Load DevRites engineering standards from
.agents/skills/devrites-lib/reference/standards/. Read.agents/skills/devrites-lib/reference/standards/core.mdbefore workflow work, then load the other.agents/skills/devrites-lib/reference/standards/*.mdfiles exactly when this skill asks for them. - Installed
.agents/mirrors may be Git-ignored. If a repository-aware file tool refuses an ignored path, read it with a native filesystem command instead; a tool refusal is not a completed task. - For automatic Engram calls, omit optional
projectandsession_idunless an exact value came from Engram or repository configuration. Never derive either fromtask_name, a run ID, directory name, or normalized slug. Callmem_session_summarywithout them by default; onunknown_sessionorunknown_project, retry once with both optional fields omitted. If auto-detection is ambiguous, ask the user instead of guessing. - Use the installed
devrites-enginebinary as the canonical runtime helper surface for orientation, gates, and state mutation. - Invocation and dispatch are different: invoke means run a skill in this context; dispatch means start a fresh agent with
spawn_agent, await it, and reconcile its result. Never describe inline skill work as a dispatch. - On MultiAgent V2, call
spawn_agentwith the exact namedagent_type=devrites-<role>, a uniquetask_name, andfork_turns="none". A missing visibleagent_typefield is still V2—not capability loss, V1, or HITL—so send it anyway. If the named call rejects it, stop before any generic/default spawn. Codex loads the role TOML'sdeveloper_instructionsnatively; DevRites verifies the durable rollout, wait, completion, and delivered result. - Only after the runtime explicitly identifies MultiAgent V1, use generic
explorerfor a read-only role withfork_turns="none"and name exactly one.codex/agents/devrites-<role>.tomlcontract in the message. Trusted.codex/hooks.jsoninjects that contract's exactdeveloper_instructionsand binds the child to the fail-closed reviewer read-only guard. - On explicitly identified MultiAgent V1,
devrites-slice-wrightuses genericworkerwithfork_turns="none"and the exact role TOML named in the message. Trusted.codex/hooks.jsonbinds it to the active reconcile window and.wright-allowlist. - The invoked skill's
required-agent-rolesfrontmatter arms the fail-closed Stop receipt. Every listed role must have a confirmed start, wait, and non-empty result in this turn. - If the required dispatch for the explicitly identified runtime is unavailable or rejected, stop for HITL. Never switch runtime lanes. Never execute a DevRites specialist role in the root context.
- Wait for every required fresh-context dispatch before reconciling or advancing. A backgrounded or lost result is incomplete.
- Codex project hooks are installed in
.codex/hooks.json; declared-leaf hooks are scoped inside.codex/agents/devrites-*.toml. Review and trust them with/hooksbefore relying on hook enforcement. - When this skill asks a HITL question via
AskUserQuestion: Codex's equivalent (request_user_input) exists only in Plan mode. Outside Plan mode, render the option set as a plain numbered list in chat and end the turn so the human answers: NEVER silently pick an option yourself; auto-picking is AFK's contract, gated by the.devrites/AFKsentinel.
devrites-api-interface: contract before implementation
When a slice crosses a boundary (FE/BE, service/service, module/module) or exposes a public interface, define the contract first so both sides can proceed and the interface stays stable.
Define the contract first
- Shape: request/response or function signature; field names, types, optionality, units. Follow the project's existing naming and conventions.
- Status & errors: success codes, error codes, error body shape, validation messages. Errors are part of the contract, not an afterthought.
- Semantics: idempotency, pagination, ordering, nullability, side effects.
- Versioning/compat: is this new or a change to an existing contract? A breaking change to an existing consumer is a user decision (and a drift event if unplanned).
Stability principles
- Design for the caller. The interface should make the common case easy and the wrong call hard.
- Prefer addition over modification. A new field is additive and optional; changing a
field's type or removing one is a breaking change. You can add later. You can't un-ship a
shape consumers already read (observable behavior is the contract:
deprecation.mdHyrum's law). - One-Version Rule. Design as if only one version of this interface will ever exist: extend the single contract rather than fork a v2 you then maintain in parallel. Forking multiplies the surface and breeds diamond-dependency conflicts; bump a version only when an addition genuinely can't stay backward-compatible.
- Match existing endpoints/modules in style: don't introduce a competing convention.
- Validate at the boundary, and only there (untrusted → trusted); don't trust
caller-supplied trust signals (IDs, roles). Validation does not belong between two internal
typed functions, on your own database's data, or in a utility already called by validated code.
A check inside the trusted core hides the bug in the boundary that should have caught it. A
third-party API response is external input: always untrusted. (Three-tier boundary:
security.md; seerite-review/reference/security-review.md.)
Type craft: make the wrong call unrepresentable
- Brand your ids. A bare
string/numberid is assignable to any other id, so the compiler won't stop you passing auserIdwhere ataskIdis due. Give each a nominal brand (type TaskId = string & { readonly __brand: 'TaskId' }) and the mix-up becomes a type error, not a production incident. - Model variants as discriminated unions, each state carrying only its own fields, so an impossible combination can't be constructed in the first place.
Enables the split
A clear contract lets $rite-plan split proceed: the backend slice can land against the
contract with a stub consumer; the frontend slice can build against a mock or the real
contract. Neither side blocks on the other.
Doubt the contract
Before standing the interface, run devrites-doubt: boundary decisions are exactly the
non-trivial kind worth an adversarial check.
Done when
The contract is complete only when every field carries a type + optionality + unit,
every success and error status code is enumerated with its error-body shape, the
devrites-doubt verdict is accept, and the contract + rationale are recorded in
decisions.md. A contract that pins only the happy-path shape is not done.
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.