Skip to content
Back to skills

Standup

ASecurity

Session-scoped triage: what did I leave open, what is rotting, and is the plan still right — answered in under a screen. Runs in seconds over the session, the working tree, open PRs, and the two ledgers (ROADMAP + RELEASES DB), then emits a ranked list capped at 7 items plus a capped strategic read. Use when the operator says "/standup", "what's open", "what did I leave hanging", "where are we", "what should I do next", or is closing out a long working session. Not for long-window defect anal...

  • 5 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 25, 2026
researchpythongobashgit

Security analysis

A100/100

Pro scans all 18 files and shows the line behind each finding

Scanned September 25, 2026

npx -y skills add HiQS-Labs/XYZ-forge --skill standup --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Standup?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Standup
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/hiqs-labs-standup/badge)](https://www.skillsdirectory.com/skills/hiqs-labs-standup)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: standup
description: >-
  Session-scoped triage: what did I leave open, what is rotting, and is the plan still right —
  answered in under a screen. Runs in seconds over the session, the working tree, open PRs, and the
  two ledgers (ROADMAP + RELEASES DB), then emits a ranked list capped at 7 items plus a capped
  strategic read. Use when the operator says "/standup", "what's open", "what did I leave hanging",
  "where are we", "what should I do next", or is closing out a long working session. Not for
  long-window defect analysis (that is /radar), not for closing one branch (/finish-line), not for
  cutting one task's drip (/rabbit-hole), and it never executes the work it recommends.
---

# /standup

Two failure modes make long agent sessions expensive: a wall of text, and a rabbit hole where the
original focus quietly got diverted six times. This skill answers one question in under a screen —
**what did I leave open, what is about to rot, and is the plan still right?**

**Status: partial. The deterministic half is built; the collector is partially built.** `triage.py` (ranking,
tiering, suppression, parking, rendering) is implemented and pinned by `test/gh77-standup-triage.sh`
(92 assertions). `collect.sh` — currently implements lenses 2, 3, and 7. The remaining offline lenses and network-dependent lenses are not yet written, so this
skill cannot run completely end-to-end today. `collect.sh` requires **`jq`** in addition to git and
python3; without it every lens degrades to `D5` and the collector exits 3 rather than emitting nothing. Design and remaining work:
[PROJECT/3-COMPLETED/GH-77-STANDUP-SESSION-TRIAGE.md](https://github.com/HiQS-Labs/XYZ-forge/blob/development/PROJECT/3-COMPLETED/GH-77-STANDUP-SESSION-TRIAGE.md)
· [#77](https://github.com/HiQS-Labs/XYZ-forge/issues/77).

## The division of labour, and why it is drawn here

Everything mechanical lives in `triage.py`. This file chooses **only** two things: the `what`
phrasing of each item, and one optional clause appended to a fixed verdict sentence. Nothing else is
model-authored.

That line is not stylistic. The PRD for this skill went four review rounds across two independent
models and escalated at the cap with a **flat** finding rate — 11 → 13 → 10 → 10. A converging review
goes 11 → 5 → 2. It stayed flat because a state machine was being specified in prose, where every gap
needs a human reader to find it. Four separate times, a fix faithful to a finding re-broke the same
property through a new route. `triage.py` exists so those properties are asserted by a test run
instead of argued in Markdown.

## Invariants — these are enforced in code, not by instruction

- **A tier-1–3 item is never silent.** It is rendered, or counted as `K critical beyond cap` with a
  `--page` escape hatch. Never suppressed, never parked, never merely absent.
- **Writes stay inside `PARKED/`.** Session state lives at `PARKED/.standup-session-<id>.json`, not
  under `.git/` — `.git` is a *file* in a linked worktree, and this repo uses them.
- **General PARKED notes remain human intake.** Lens 8 parses only lines with its explicit
  `— check:` machine field; Markdown checklists and other agent observations in root `PARKED/`
  do not become standup records. Triage may promote those notes under `PARKED/README.md`.
- **A park file is never itself emitted as an item.** Untracked paths under `PARKED/` are excluded;
  a *modified tracked* one still surfaces, because it cannot loop.
- **`close` is never executed.** Only a park record's read-only `check` probe runs during collection.
- **An unchanged rerun writes nothing** — no new park file, no touch.
- **Output is capped at 15 rendered lines**, enumerated: 1 opening + 1 heading + ≤7 items + ≤1
  notices + 1 heading + ≤4 body.

## Usage

```bash
skills/1-hourly/standup/collect.sh > /tmp/lenses.json   # Partially built (lenses 2, 3, 7 only)
python3 skills/1-hourly/standup/triage.py --lenses /tmp/lenses.json --dry-run
python3 skills/1-hourly/standup/triage.py --lenses /tmp/lenses.json --apply --session-state PARKED/.standup-session-$$.json
python3 skills/1-hourly/standup/triage.py --lenses /tmp/lenses.json --dry-run --page 2   # beyond the cap
```

Exit `0` clean · `2` usage or a contract violation · `3` one or more lenses degraded.

Verdict codes are a finite set — `no-contradiction`, `ledger-behind`, `release-overdue`,
`insufficient-evidence` — chosen with `--verdict`; `--verdict-clause` adds at most one newline-free
clause of ≤120 characters. An unbounded clause is a wall of text with extra steps, so it is refused.

## Reporting the result

Print `triage.py`'s output as-is. Do not summarise it, do not add a preamble, and do not narrate what
you did to produce it — narration of the agent's own recent work is the single most common
wall-of-text source and is the thing this skill exists to remove.

If a tier-1–3 item appears, say so in your first sentence. If `K` is non-zero, name the `--page`
command; the operator must be able to reach every critical item.

## Degrading

Say which lens was unavailable and what it costs the verdict. `gh` missing means the PR and
issue-state lenses did not run — report that, never an implied clean sweep. A skill that degrades
quietly reports a sweep it never performed, which is the defect class this repo has spent the month
removing.

Files in this skill

  • SKILL.md5.3 KB
  • collect.sh50.6 KB
  • fixtures/all-degraded/PARKED/bad.md63 B
  • fixtures/all-degraded/branch.txt5 B
  • fixtures/all-degraded/lens2.rc2 B
  • fixtures/all-degraded/lens3.rc2 B
  • fixtures/all-degraded/lens3_fallback.rc2 B
  • fixtures/all-degraded/lens4.rc2 B
  • fixtures/all-degraded/lens5_gh_check.rc2 B
  • fixtures/all-degraded/lens6_check.rc2 B
  • fixtures/all-degraded/lens7.rc2 B
  • fixtures/all-degraded/session.json12 B
  • fixtures/lens-1-bad-schema/lens4.rc2 B
  • fixtures/lens-1-bad-schema/lens4.txt3 B
  • fixtures/lens-1-bad-schema/lens5_gh_check.rc2 B
  • fixtures/lens-1-bad-schema/releases.db16 KB
  • fixtures/lens-1-bad-schema/session.json21 B
  • fixtures/lens-1-empty-session/lens4.rc2 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…