Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Readonly

ASecurity

User-invoked modifier for evidence-first read-only investigation. Use when the user appends /readonly to a question or another skill request: answer by checking the codebase and available read-only sources, do not implement, do not open issues, do not mutate local or remote state, and do not guess with 'likely' or 'probably' when evidence can be gathered.

6 stars
0 votes
0 copies
1 views
Added 10/1/2026
ai-agentsgitapidatabasedocumentation

Works with

api

Security Analysis

A100/100

Scanned 10/1/2026

$npx -y skills add CheckPickerUpper/skills --skill readonly --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Readonly?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Readonly
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/checkpickerupper-readonly/badge)](https://www.skillsdirectory.com/skills/checkpickerupper-readonly)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: readonly
description: "User-invoked modifier for evidence-first read-only investigation. Use when the user appends /readonly to a question or another skill request: answer by checking the codebase and available read-only sources, do not implement, do not open issues, do not mutate local or remote state, and do not guess with 'likely' or 'probably' when evidence can be gathered."
disable-model-invocation: true
---

# /readonly

Prove, don't guess. Investigate with every read-only source that can answer the question, then stop before changing anything.

This is a user-invoked modifier. Use it when the user explicitly writes `/readonly`, including beside another skill name.

## Core rule

When `/readonly` is present, treat every other instruction or invoked skill as diagnostic only. Run its reading, tracing, classification, and reasoning steps, but skip any step that edits files, opens issues, changes configuration, creates branches, commits, pushes, posts comments, deploys, installs, regenerates, or otherwise mutates local or remote state.

## Procedure

1. **Freeze the state.** Record `git status --short` and the current branch before investigating. Existing dirty files are user state; do not normalize, revert, stage, or explain them away.
2. **Find the answer in the repo first.** Read code, docs, tests, scripts, generated descriptors, config, git history, issues, and PRs as needed. Use fast search before narrow reads.
3. **Trace to the owner.** If the question is about a bug, behavior, design, or class-level problem, keep following writers, callers, schemas, generators, or specs until the codebase proves where the answer lives.
4. **Plan from evidence.** If the question asks what to do next, read the repo state, active branch, recent commits, open PRs or issues when available, failing checks if readable, and local planning docs before recommending work.
5. **Avoid unsupported language.** Do not answer with `likely`, `probably`, `seems`, `I think`, or estimate language for a codebase-answerable fact. Use `proved`, `not found`, or `unknown after checking`.
6. **Ask only after legwork.** Do not ask clarifying questions until the available evidence cannot decide between materially different meanings. When asking, state what was checked and what exact missing fact blocks the answer.
7. **Stop before action.** Recommendations may be concrete, but do not implement them, create tracking issues, update docs, run generators, or perform cleanup.
8. **Prove no mutation.** Before the final answer, run `git status --short` again. If anything changed during investigation, identify it and do not hide it.

## Read-only sources

Allowed:

- Repository reads: `rg`, `find`, `ls`, `sed`, `nl`, `cat`, `git status`, `git diff`, `git show`, `git log`, `git blame`.
- Read-only project commands that do not write files, caches, snapshots, lockfiles, generated code, databases, or external state.
- Read-only remote queries such as `gh issue view`, `gh issue list`, `gh pr view`, documentation pages, package metadata, or API GET requests.
- Browser or web research when the answer depends on current external facts.

Banned:

- File edits, `apply_patch`, redirects that write files, formatters, generators, installers, migrations, cleanup scripts, and commands that update lockfiles or caches in the repo.
- `git add`, `git commit`, `git checkout`, `git switch`, `git reset`, `git rebase`, `git merge`, `git push`, branch creation, stash mutation, or tag mutation.
- Issue, PR, comment, label, project-board, reminder, deployment, secret, or environment changes.
- "Tiny" implementation, quick fixes, doc touch-ups, or drive-by cleanup.

If the only proof requires mutation, do not perform it. Say what command or change would prove the answer and why it is outside `/readonly`.

## Combined skills

When `/readonly` is combined with another skill, `/readonly` overrides its mutation steps:

- `/fix-the-class /readonly`: locate the writer, name the bad state, identify the invariant owner, reject lower patches, and propose the protective change. Do not make the owner protective or add tests.
- `/antimatter-code-quality-review /readonly`: perform the review and report findings. Do not patch findings.
- `/to-issues /readonly`: shape the issue plan if asked. Do not create issues.
- `/dog-food-it /readonly`: collect existing evidence only. Do not run proof commands that mutate state.

## Output

Answer in this shape:

1. **Answer:** the direct answer, decision, or recommendation.
2. **Evidence:** the files, commands, docs, issues, or history entries that prove it.
3. **Checked:** the search/read path, especially when the answer is negative.
4. **Unknowns:** only facts that remained unknowable after checking, plus the exact evidence that would settle them.
5. **No-mutation proof:** final `git status --short` result, summarized without dumping unrelated user changes.

If the answer is "we do not know," the report must make clear that the codebase was checked and the uncertainty is real, not a guess.

Attribution

CheckPickerUpperCheckPickerUpper
View sourceSee grades on GitHubMore from CheckPickerUpper →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698461 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →