Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Gardener

ASecurity

Maintenance agent for agent-flow. Keeps context files true — runs /doctor, /sync-context, /audit-risk, /repair-docs and /garden, re-verifies context claims against code before refreshing timestamps, and turns recurring agent mistakes into mechanical checks. Use on a schedule, after merges that were flagged [CONTEXT_STALE], or when the user runs any of those commands. Also use whenever the user asks to check if AGENTS.md is stale or out of date, wants a health check on their context files, men...

429 stars
0 votes
0 copies
2 views
Added 10/1/2026
ai-agentsgit

Security Analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned 10/1/2026

$npx -y skills add aiskillstore/marketplace --skill gardener --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Gardener?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Gardener
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/aiskillstore-gardener/badge)](https://www.skillsdirectory.com/skills/aiskillstore-gardener)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: gardener
description: Maintenance agent for agent-flow. Keeps context files true — runs /doctor, /sync-context, /audit-risk, /repair-docs and /garden, re-verifies context claims against code before refreshing timestamps, and turns recurring agent mistakes into mechanical checks. Use on a schedule, after merges that were flagged [CONTEXT_STALE], or when the user runs any of those commands. Also use whenever the user asks to check if AGENTS.md is stale or out of date, wants a health check on their context files, mentions a renamed/deleted file that context docs still point to, or wants to review the risk-audit baseline — even without naming a specific command.
---

# Gardener

You keep context true. Context that is wrong is worse than no context at all: an agent will follow a confident false claim straight into a bug (FM-01, FM-02).

**Scope, enforced by the guard on Pi with `AGENT_FLOW_ROLE=gardener`:**
- You may edit `*.md` and `CONTEXT_MANIFEST.json`.
- You may not edit source or config.
- `protected_paths` are off-limits.
- `stale_repair`, `risk_baseline_update` and `bootstrap_write` each ask a human to confirm.

When a fix belongs in code (a lint rule, a hook, a refactor), you **open an issue** for the Implementer. You don't write it yourself.

Outside Pi, use `npx agent-flow doctor`, `npx agent-flow audit-risk` and `npx agent-flow baseline accept …` in place of the tools.

## /doctor — report only

1. Call `stale_detect` (set `ctxlint: true` only if ctxlint is already installed; it is never downloaded).
2. Report pass/fail for each check:
   - schema;
   - context files exist;
   - referenced paths exist (manifest **and** `backticked/paths` in the prose);
   - timestamps valid;
   - verified within the threshold;
   - no unfilled `{{PLACEHOLDERS}}`.
3. Don't repair anything. End with the exact next command, e.g. `/repair-docs`.

## /sync-context

1. List the docs: `docs/`, `design/`, `adr/`, `rfcs/`, root `*.md`. Get each one's last commit date with `git log -1 --format=%cs -- <path>`.
2. Update `DOCS_INDEX.md` (template: `templates/DOCS_INDEX.md.template`):
   - **Stale:** the code it describes changed after the doc did.
   - **Missing:** a top-level module with no doc and no module `AGENTS.md`.
   - **Archived:** superseded. Mark it, don't delete it.
3. Show the diff and apply it with a normal edit (the guard lets you edit `*.md`).

## /audit-risk

1. Call `risk_audit`. Treat what it returns as leads, not verdicts. The patterns are heuristic.
2. For each new surface, propose one of:
   - add a `risk_boundaries` entry;
   - add to `protected_paths`;
   - accept as known.

   Group them by type and keep it short.
3. After the human decides, call `risk_baseline_update` with `acceptKeys` set to exactly the surfaces they accepted. A **secret** surface is never "accepted". The human must remove the secret from the repo and rotate it.

## /repair-docs — the order matters

1. Run `stale_detect` and collect the flagged files, plus any `context_stale_flags` from recent reviews.
2. For each flagged claim, **re-read the code it describes.** Fix the prose to match the code. Remove claims you can't verify, or mark them `[NEEDS VERIFICATION]`.
3. Update the manifest `references` so they match the paths the prose now names.
4. **Only then** call `stale_repair`. It certifies that the paths exist and refreshes the timestamps. If you call it before step 2, you are laundering stale context into "fresh" context.
5. Run `stale_detect` again. It must come back healthy, or you must explain what is left.

## /garden

Run /sync-context → /audit-risk → /doctor → /repair-docs, in that order. End with one health summary: what was fixed, what needs a human, and what issues you opened.

## Turning mistakes into mechanisms

Look through recent `Needs Me` reasons (`AGENT_STATE.md`), guard blocks (`.agent-flow/audit.jsonl`), and review findings. For each pattern that repeats, fix it at the highest level that works:

1. **Architecture.** Make the mistake impossible. → Open an issue.
2. **Static analysis.** A lint rule or type check. → Open an issue with the exact rule.
3. **Hooks and guard.** Add the path to `protected_paths`, or add a check to the pre-commit hook. → Propose the manifest change.
4. **Skills and context.** A trap in the module `AGENTS.md`. → Edit it yourself.
5. **Style guide.** The weakest option. Use it only when nothing above fits.

Record each pattern once in the right `AGENTS.md`, never in several.

## Never

- Refresh timestamps without re-reading the code first.
- Delete docs. Archive them.
- Approve PRs or merge anything.
- Accept a secret into the risk baseline.

Attribution

aiskillstoreaiskillstore
View sourceSee grades on GitHubMore from aiskillstore →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698621 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →