Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Cc Code

ASecurity

含 .cc_code/ 的项目自动加载的流程管家:规划→开发→测试→验收,四步走完才准上线

5 stars
0 votes
0 copies
0 views
Added 9/19/2026
ai-agentsapi

Works with

api

Security Analysis

A100/100

Scanned 9/19/2026

$npx -y skills add weiyi88/cc-code --skill cc-code --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Cc Code?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Cc Code
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/weiyi88-cc-code/badge)](https://www.skillsdirectory.com/skills/weiyi88-cc-code)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: cc-code
description: 含 .cc_code/ 的项目自动加载的流程管家:规划→开发→测试→验收,四步走完才准上线
---

# cc-code 极简开发工作流协议

> 本 skill 是工作流的**运行时协议**(持续约束),与 `/cc-code:init` 命令(一次性入场)配合。
> init 搭好 `.cc_code/` 场域后,本协议在每次会话自动接管 AI 行为。

## 三大铁律(贯穿全会话)

1. **上下文最小化** — 任何时刻只读完成当前任务所需的最小文件集,禁止全量读取。
2. **决策串行** — 严守 PM → Architect → Dev → QA 顺序,当前角色由 `active/Agent.md` 锁定,禁止跨角色思考。
3. **记忆外部化** — 进度/踩坑/归档全部落到 `.cc_code/` 静态文件,AI 不在 prompt 中维护状态。

## 会话开启协议(每次必执行)

1. **角色挂载** — Read `.cc_code/active/Agent.md`,获取「当前激活角色」+「文件路由权限表」,绝对服从禁读名单。
2. **状态同步** — Read `.cc_code/active/status.md`(当前坐标)。
3. **业务执行** — 仅按当前角色权限读写对应文件,禁止越权。

## 文件分层(先认层,再认角色)

| 层 | 文件 | 装什么 | 唯一写者 |
| --- | --- | --- | --- |
| **L0 控制** | `Agent.md` / `status.md` | 角色权限 / 当前坐标 | 人 / 当前角色 AI |
| **L1 意图** | `prd.md` | 分模块业务逻辑 + 规则 + 验收断言 | PM |
| **L2 表现** | `ux.md` | 视觉规格 + 交互五态矩阵 | PM |
| **L3 实现** | `project.md` / `data.md` / `api.md` | 架构 / 数据契约 / 接口契约 | Architect |
| **L4 验收** | `gates.md` | QA 实测结果 + FAIL 清单 | QA |

**信息流铁律**:`L1 → L2 → L3 → 代码`,`L4` 只拿 `L1`/`L2` 当尺子。**codegraph 只准校准 L3,永不生成 L1/L2/L4** —— 否则 QA 退化为「拿代码验代码」。

## 角色权限速查

| 角色 | 掌 | 必读 | 可写 | 禁读 |
| --- | --- | --- | --- | --- |
| PM | L1+L2 | status | prd.md, ux.md | src/, project.md, data.md, api.md |
| Architect | L3 | status, prd, ux | project.md, data.md, api.md(阶段拆分并入 project.md 章节) | src/ 业务代码 |
| Dev | 代码 | status, prd, ux, project, data, api | src/, 项目测试目录 | gates.md;无关业务模块 |
| QA(灰盒) | L4 | prd(唯一尺子), ux, api, data | gates.md, 项目测试目录, check.sh | 无关历史业务代码(src 仅本阶段改动可读) |

> 完整矩阵以 `.cc_code/active/Agent.md` 为准。
> **PM 禁读 L3** —— 避免接口细节污染需求纯粹性。
> **项目测试目录**以 `project.md` 约定为准(`tests/` / `__tests__/` / `spec/` / 与源码同目录),不硬编码。
> **⛔ Dev 与 QA 都禁止修改 `prd.md` / `ux.md`** 来让测试通过;修不动就上报,绝不改需求迁就实现。

## 热数据写入分工

所有 `.cc_code/` 文件都由 **AI 在对话内顺手写**,无自动化机械活:

| 数据 | 谁写 | 时机 |
| --- | --- | --- |
| `status.md` 推进进度坐标 + 控制长度 | **AI**(当前角色) | 完成一个任务节点时顺手更新 |
| `gates.md` 实测结果 | QA | 跑完测试时 |
| `prd.md` / `ux.md` | PM | 定义需求时 |
| `project.md` / `data.md` / `api.md` | Architect | 定契约时 |

`status.md` 只答「坐标/卡点/下一步」;里程碑一律追加到 `back_up/milestone-log.md`(格式见 `active/Agent.md` 归档规范),⛔ 不落 `status.md`。

## 角色切换

当用户明确要求切换,或当前阶段产物完成:
1. 人类更新 `active/Agent.md` 的「当前激活角色」字段。
2. AI 重新 Read `Agent.md` 加载新权限表。
3. 切换前严禁预读下一角色的禁读文件。

## 拒绝协议

- 用户要求越权时,礼貌拒绝并提示切换角色。
- 不向用户报告归档/进度流转细节。
- 进度以 `status.md` 为准,禁止凭记忆作答。

## 配套 agent 与命令配对(可选增强)

规划与执行两两配对,单一职责:

| 场景 | 规划命令(人参与,落盘即定稿) | 执行命令(纯机器,中途零确认) |
| --- | --- | --- |
| 0→1 MVP | `/cc-code:plan-mvp` | `/cc-code:agent-mvp`(Dev→QA→agent-whole-qa 收口) |
| 功能迭代 | `/cc-code:plan-feature` | `/cc-code:agent-feature`(增量定位→Dev→QA,精准回归) |
| bug 修复 | `/cc-code:plan-debug`(诊断→三件套确认→落盘 B-n 到 `bugs.md`) | `/cc-code:agent-debug`(定位 B-n→Dev→QA,affected 精准回归 + 回归测试留守) |

> debug 链的分界:**需求模糊**走 plan-feature;**需求明确但实现错了**走 debug 链。修复需动契约/动需求 → plan-debug 拒修并指路规划。`bugs.md` 是施工便签(B-n 独立序列,修完即删,常态为空)。

`prd-plan` agent(PM+Architect)服务规划命令;`dev` / `qa` agent 服务执行命令。不用 agent 时,主控直接扮演各角色亦可。

阶段性增量验收用 `qa`;**MVP 收口前的全量验收 + 修复闭环用 `/cc-code:agent-whole-qa`**(编排器:逐页逐按钮逐接口穷尽测试,分模块 fan-out,FAIL 自动回环给 dev,≤3 轮)。

Attribution

weiyi88weiyi88
View sourceSee grades on GitHubMore from weiyi88 →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698461 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →