Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Doctrine Surfaces

ASecurity

Tier: opus (`loom-senior-software-engineer`). Starts after D1 returns. Read `../common.md` first.

61 stars
0 votes
0 copies
2 views
Added 9/21/2026
ai-agentsgo

Security Analysis

A100/100

Pro scans all 4 files and shows the line behind each finding

Scanned 9/21/2026

$npx -y skills add cosmix/loom --skill doctrine-surfaces --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Doctrine Surfaces?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Doctrine Surfaces
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/cosmix-doctrine-surfaces-loom/badge)](https://www.skillsdirectory.com/skills/cosmix-doctrine-surfaces-loom)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
d1-template-and-orchestration-skill.md
# D2 — plan-writer skill: template criteria, sizing rubric, split into references

Tier: opus (`loom-senior-software-engineer`). Starts after D1 returns. Read `../common.md` first.

## Goal

The skill authors copy from stops shipping defective criteria, teaches the sizing rule the
operator set, documents what `loom plan verify` now enforces, and costs less to load. Evidence:
report section 4.1 — the canonical knowledge-distill block (`SKILL.md:1081-1085`) carries two
criteria that cannot fail (`rg -q "## "` on a Markdown file; 119 slots in 38 plans, 17 of the 30
criteria proven green at base) and an unbounded `--strict` gate that produced 11 of 17 disputes.
The skill is one 111 KB file, about 30,000 tokens, read whole on every plan task.

## Files you own (write)

- `skills/loom-plan-writer/SKILL.md`
- `skills/loom-plan-writer/references/*.md` (new directory; no skill uses one yet, so you set the
  convention: SKILL.md links each reference with a one-line "read when" note)
- `loom/src/assets/tests/skill_references.rs` (new) and its `mod` line in the assets tests module

Read-only: `loom/src/orchestrator/signals/tests_doctrine_blocks.rs` (BLOCK-B as D1 left it),
the merged code of the plan-verification and knowledge stages for exact flag and field names
(`rg -n 'baseline' loom/src/commands/knowledge/check.rs`,
`rg -n 'skills' loom/src/plan/schema/types.rs`, `loom/src/plan/schema/validation/`).

## Steps

1. Canonical template, both bookends. Delete the four `rg -q "## " doc/loom/knowledge/...`
   lines. knowledge-bootstrap acceptance becomes
   `loom knowledge check --strict --baseline doc/loom/knowledge/check-baseline.txt`;
   knowledge-distill acceptance becomes that line plus `loom memory pending --strict`. Remove
   the tier-routing paragraph that defends the deleted criterion. Add the distill step
   `loom memory pending --group` as the stage's starting point, and
   `loom knowledge check --write-baseline doc/loom/knowledge/check-baseline.txt` as its last
   step when the stage removed issues.
2. Section 4 rubric. Replace "Size every worker task to finish inside about 40 requests and 120k
   of context" (`:478`) and the surrounding "120k worker budget" wording with the common.md
   numbers: typical completion under about 400,000 tokens, boot cost about 28,000 per spawn, so
   group small tasks and never split below what 400,000 needs. Keep the 500,000-token stage
   guidance (`:489`, `:533`, `:1160`). Replace BLOCK-B with D1's text byte-for-byte. Rewrite the
   sentences around it that say the main agent never implements, and the "a stage with no
   subagent assignments is a red flag" sentence, to the cost rule.
3. New stage field. Document `skills:` in the metadata skeleton (Section 7), the canonical
   template's feature stages, and the pre-STOP checklist: name the skills each stage's agents
   need; `loom plan verify` rejects unknown names.
4. Enforced rules become pointers. Where Sections 6 to 8 argue at length for something
   `loom plan verify` now checks (`|| true`, `HOME=` from a variable, bare `mktemp -d`, network
   binaries, `doc/plans/` paths, `vitest -t`, test runners in `wiring_tests`, criteria green at
   base), keep one line naming the check and the logged incident, and tell authors to run
   `loom plan verify --strict`. Add the three missing rules: a criterion whose paths are disjoint
   from the stage's `files:` is a repo-wide gate on a narrow stage; `wiring_tests` commands have
   a 30 s cap and acceptance 300 s; a merged plan's pinned criteria go red after later renames,
   so pin behaviour over paths where possible. Document the worker-table parser's rule that a
   Files-owned cell holds paths only.
5. Split. SKILL.md keeps Sections 2, 3, 5, 7, the canonical template and the pre-STOP checklist,
   plus a short form of Section 1's checklist. Move to `references/`: the Section 1 protocols
   (blast radius, reuse, wireability, destructive paths, new runtime, cross-plan), the codex
   implementer detail, the realizability and produced-artifact rules of Section 6, and Section 8
   sandbox detail. Target: SKILL.md at most 45,000 bytes. Every moved section keeps its text.

## Traps

- `tests_doctrine.rs:131-166` pins BLOCK-B in this file and asserts it contains the codex
  constants from `loom/src/codex.rs`. BLOCK-B stays in SKILL.md, not in a reference.
- The build embeds every file under a `loom-*` skill directory (`loom/build/assets.rs:170-191`,
  `walk_files`), so `references/` files are embedded. Add one test,
  `loom/src/assets/tests/skill_references.rs` (you own it and its `mod` line), asserting that the
  embedded asset table contains `loom-plan-writer/references/` entries and that the install
  path for one of them keeps the `references/` component.
- The plan-writer's own instructions forbid triple backticks inside YAML descriptions; keep the
  template valid by running nothing — the main agent runs `loom plan verify` on a plan rendered
  from your template.

## Proof

`cargo test --offline --locked --manifest-path loom/Cargo.toml --lib orchestrator::signals::tests_doctrine`
— run once.

Attribution

cosmixcosmix
View sourceSee grades on GitHubMore from cosmix →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698621 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →