ipollowork-maintainable-code
Mandatory iPolloWork code-change gate for modern, minimal, performant, reuse-first implementation and clean repository ownership. Use whenever AI creates, edits, deletes, or refactors application code, server code, packages, scripts, tests, dependencies, schemas, routes, UI, or g
Supply asset profile
Coding and developer agents
Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.
Scenario
GitHub automation
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Agent fit
Claude Code + OpenAI Agents + Browser agents
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add Devin-AXIS/iPolloWork --skill ipollowork-maintainable-code
Maintenance
fresh
Pushed today
Risk
Needs review
Dependency or permission surface needs review
GitHub quality
4.5K
83/100 Quality · 71/100 Trust
Coverage tags
Review notes
Dependency or permission surface needs review · Permission surface may require sandboxing
Agent adoption scorecard
Trust, audit, and install readiness at a glance
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
StrongSolid option that is likely worth shortlisting for production workflows.
Trust
Sandbox onlyUseful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Human review before install
Run only in a sandbox and compare close alternatives before using it for real work.
Stars
4.5K GitHub stars
Repo activity
4.5K stars, 878 forks
Maintenance
Pushed today
License
NOASSERTION
Install
npx skills add Devin-AXIS/iPolloWork --skill ipollowork-maintainable-code
Install safety
standard package or runtime install path
Permission surface
shell or command execution, filesystem or document access
Agent outcomes
No agent outcome data yet
Docs
Usable metadata, review docs
Risk summary
Review before production
- Repository license is NOASSERTION; the skill itself does not include a license or attribution, which may create compliance ambiguity.
- Financial research output is not financial advice; require human review before any live investment decision.
- Quality score needs review
- Permission surface needs review: shell or command execution, filesystem or document access
Install readiness
Install path available
- Install path is available
- Repository evidence is available
- License is declared
- No Agent Proven outcome evidence yet
Agent-readable metadata
Machine-readable decision data for this skill.
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
- Local desktop workflows
- Claude Code teams
- teams that value GitHub adoption signals
- Navigate local resources
Suited agents
Install decision
- Command
- npx skills add Devin-AXIS/iPolloWork --skill ipollowork-maintainable-code
- Policy
- review
- Human review
- yes
Trust and risk
- Trust
- 63/100
- Audit
- 81/100
- Risk level
- Needs review
Outcome loop
- Endpoint
- /api/agent/outcome
- Event ID
- resolve
- Outcomes
- 5
Install command
npx skills add Devin-AXIS/iPolloWork --skill ipollowork-maintainable-codeDo not use when
- teams that need a vendor-supported SLA
- production agents without a repository review
- Repository license is NOASSERTION; the skill itself does not include a license or attribution, which may create compliance ambiguity.
- High-risk permission hints: Shell or command execution
- Dependency or permission surface needs review
Agent safety v2
45/100 · Avoid automatic install
Sparse or mixed signals. Useful for discovery, but not for autonomous installation.
Test manually in an isolated workspace and compare against safer alternatives.
high
Shell or command execution
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Browser automation
Skill may drive a browser or interact with web pages.
medium
Network access
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Filesystem access
Skill may read or write project files, documents, generated artifacts, or local workspace state.
- High-risk permission hints: Shell or command execution
- Dependency or permission surface needs review
Install targets
Install this skill in your agent workflow
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
OpenAgentSkill CLI
Resolve policy, run the source installer safely, and report a verified install receipt.
$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install devin-axis-ipollowork-maintainable-codeAgent resolve plan
Let an agent verify fit before installing.
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20ipollowork-maintainable-code%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20ipollowork-maintainable-code%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/devin-axis-ipollowork-maintainable-code/install
Agent should check
- Task fit and alternatives from Resolve API.
- Audit score, trust score, and safety policy warnings.
- Install target compatibility for Codex, Claude Code, Cursor, or CLI.
Copy prompt
Task: Use ipollowork-maintainable-code in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20ipollowork-maintainable-code%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/devin-axis-ipollowork-maintainable-code/install
Install command: npx skills add Devin-AXIS/iPolloWork --skill ipollowork-maintainable-code
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Give an agent the install path, not another directory page.
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/devin-axis-ipollowork-maintainable-code/install
LLM text format
/api/skills/devin-axis-ipollowork-maintainable-code/install?format=text
Find alternatives
/api/skills/search?q=ipollowork-maintainable-code&limit=3
Agent prompt
Use ipollowork-maintainable-code for this task. Review https://www.openagentskill.com/api/skills/devin-axis-ipollowork-maintainable-code/install, then install with: npx skills add Devin-AXIS/iPolloWork --skill ipollowork-maintainable-codeRegistry metadata
Agent-readable profile for automatic skill selection.
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/devin-axis-ipollowork-maintainable-code
LLM text
/api/registry/manifest/devin-axis-ipollowork-maintainable-code?format=text
Install alias
/api/registry/install/devin-axis-ipollowork-maintainable-code
Recommend
/api/registry/recommend?task=Use%20ipollowork-maintainable-code%20in%20an%20agent%20workflow&limit=3
Agent fit
Local desktop
Use-case tags
Platforms
Claude Code, OpenAI Agents, Browser agents
Audit report
Needs review · 81/100
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Primary pick for Local desktop
Use this as a leading candidate, then validate the README and install path in your own agent stack.
Role in stack
Primary pick
Primary fit
Local desktop
Trust label
Production-ready
Install path
Command ready
Use when
- Local desktop workflows
- Claude Code teams
- teams that value GitHub adoption signals
Evidence
- 4,479 GitHub stars
- recent repository activity
- install command or GitHub repo available
- 83/100 quality profile
- 1 OpenAgentSkill engagement events
review first
- Repository license is NOASSERTION; the skill itself does not include a license or attribution, which may create compliance ambiguity.
Implementation path
- 1Install it in a sandbox agent and run one Local desktop task end to end.
- 2Compare output quality, latency, and failure behavior against at least one alternative.
- 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.
Trust profile
Sandbox only
Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
GitHub adoption
PASS4.5K GitHub stars
Stars/forks activity
PASS4.5K stars, 878 forks; issue activity unavailable in current metadata
Recent maintenance
PASSPushed today
License clarity
PASSNOASSERTION
Good signals
- AI review approved
- Install path is available
- Repository evidence is available
- Recently maintained repository
- Meaningful GitHub adoption signal
- Install command has no obvious high-risk pattern
- Outcome loop is ready but needs first real agent run
Review before install
- Repository license is NOASSERTION; the skill itself does not include a license or attribution, which may create compliance ambiguity.
- Financial research output is not financial advice; require human review before any live investment decision.
- Quality score needs review
- Permission surface needs review: shell or command execution, filesystem or document access
- Dependency/runtime risk: command execution surface, network or browser surface
- Permission surface: shell or command execution, filesystem or document access
- No real agent outcome reports yet
- Human review required before unattended installation
Recommended action
Run only in a sandbox and compare close alternatives before using it for real work.
Quality profile
Strong candidate for agent workflows
Solid option that is likely worth shortlisting for production workflows.
Workflow fit
Use this skill in these scenarios
Operate local tools
Local desktop
I need my agent to operate local files and desktop apps in a repeatable workflow.
Operate web apps
Browser automation
I need my agent to control a browser, fill forms, and verify web app workflows.
Investigate faster
Research agents
I need my agent to research a topic, compare sources, and produce a concise report.
Workflow fit
Add it to a complete workflow
Scrape, clean, and reuse web data
Web data pipeline
A practical workflow for agents that crawl public pages, extract clean content, normalize data, and hand it to downstream research or RAG workflows.
Operate and verify web apps
Browser QA agent
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Design, build, test, and ship interfaces
Frontend and UI
A practical workflow for agents that turn product briefs or Figma designs into polished frontend code, review the result, test it in a browser, and prepare a safe deployment.
Alternative shortlist
Compare before you install
Similar skills that may fit this task.
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
Maigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
Nuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
Infisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
Overview
--- name: ipollowork-maintainable-code description: Mandatory iPolloWork code-change gate for modern, minimal, performant, reuse-first implementation and clean repository ownership. Use whenever AI creates, edits, deletes, or refactors application code, server code, packages, scripts, tests, dependencies, schemas, routes, UI, or generated-file workflows. Reuse existing code before creating files, keep one source of truth, prevent parallel implementations and junk directories, justify every new file or dependency, and audit the current change before completion. ---
# iPolloWork Maintainable Code
Treat this as the repository's single code-quality Skill. Implement changes with the smallest coherent diff, modern platform patterns, bounded runtime cost, and one clear owner. Search and reuse before creating anything.
## Non-Negotiable Outcomes
- **Modern:** use the current repository stack and supported platform APIs; do not add legacy wrappers or compatibility layers without a real supported consumer. - **Minimal:** solve the requested job with the fewest concepts, files, dependencies, states, and routes that remain clear. - **Performant:** keep network, database, filesystem, bundle, render, and memory work bounded; optimize measured or structurally obvious hot paths. - **Reusable:** extend compatible components, hooks, services, schemas, types, and utilities before creating parallel versions. - **Owned:** keep one source of truth and place behavior in the narrowest existing owner. - **Clean:** do not create convenience directories, one-off design notes, duplicate implementations, generated source artifacts, or abandoned replacement files.
## Required Workflow
1. Find the repository root. Read `AGENTS.md`, the owning package manifest, the real entrypoint, and nearby implementations. 2. Read `references/repository-boundaries.md` before adding a file, directory, dependency, API, table, or cross-package import. 3. Define a change budget before editing: intended behavior, owning module, expected files touched, and whether any new file, directory, dependency, route, table, or persistent state is truly required. Default every category to zero. 4. Search before creating anything: - Search component names, visible labels, route names, event names, type names, and distinctive behavior with `rg`. - Search `apps/app/src/components/ui`, `apps/app/src/components`, the target domain, `apps/server/src`, `packages/types`, and `packages/ui` as relevant. - Inspect exports and call sites, not just filenames. 5. State the reuse decision: reuse unchanged, extend compatibly, extract for real multiple consumers, or create as the last choice. For each new file or dependency, record why no existing owner can absorb the change. 6. Implement locally. Remove the replaced path in the same change; do not leave `old`, `new`, `v2`, fallback, or dead compatibility copies behind. 7. Add focused tests at the owning layer. Do not duplicate server business logic, contracts, state, or validation in the desktop app. 8. Run the narrow package checks, inspect the complete diff, then run:
```powershell node .codex/skills/ipollowork-maintainable-code/scripts/audit-changes.mjs ```
9. Resolve every error. Fix warnings or give a concrete ownership/performance reason for keeping the exception.
## Creation Gate
- Add a file only when it has a distinct owner and responsibility that would make an existing file less coherent. A long file alone is not a reason to split it. - Add a directory only for a real subsystem or package with multiple cohesive files and a stable owner. Never create a directory to hold one small feature, one handoff, one report, or one Markdown note. - Do not add a new top-level directory without explicit user approval and a repository-level architectural reason. - Do not create `new`, `old`, `v2`, `copy`, `backup`, `temp`, `tmp`, `misc`, `notes`, `drafts`, `handoff`, or `tdd-summary` paths to avoid integrating with the current owner. - Do not create a design, plan, QA, summary, or TODO Markdown file for each small feature. Update an existing durable document only when future maintainers need information that code, tests, types, or comments cannot express. - Add a dependency only when the platform, current dependency graph, and local utilities cannot meet the requirement cleanly. Account for bundle/runtime cost, maintenance, license, and existing transitive capability. - Do not create a generic abstraction for one caller. Extract only after two real consumers need meaningful shared behavior or centralization prevents contract/security drift.
## Reuse Decision
| Situation | Action | | --- | --- | | Existing API/component/helper meets the need | Import and reuse it | | Existing implementation differs only by presentation or configuration | Add typed props/options without changing existing defaults | | Two real call sites need the same non-trivial behavior | Extract to the nearest shared owner | | Similar-looking code has different domain rules or is unlikely to be reused | Keep it local; do not force an abstraction | | No compatible implementation exists after searching | Create one in the narrowest correct owner |
Do not copy a component and rename it, create `*V2`, `*New`, `*Copy`, or duplicate a helper to avoid understanding its API. Do not add a generic abstraction for a single trivial use.
## Modernity And Simplicity
- Use typed boundaries, functional React, explicit async/error states, semantic controls, and current repository primitives. - Avoid `any`, broad type assertions, duplicated derived state, prop-to-state mirroring, hidden global state, and fallback branches that types or control flow make impossible. - Prefer composition and typed options over copied components or mode-heavy forks. Preserve existing defaults when extending shared code. - Delete obsolete code, exports, dependencies, flags, tests, and documentation when their supported path is removed. - Keep compatibility only for a named active format, client, or migration window. Document the removal condition beside the boundary.
## Performance Gate
- Keep lists and APIs paginated and bounded. Select only needed fields and avoid N+1 queries, request loops, and repeated filesystem scans. - Keep React subscriptions narrow. Derive values instead of synchronizing copies, avoid effects for pure computation, and lazy-load genuinely heavy optional surfaces. - Do not add caching or memoization without a clear owner, invalidation rule, and demonstrated reuse or cost. - Do not move server-owned data or heavy processing into the browser. Keep network and filesystem work out of render paths and short transactions free of network calls. - For a hot or high-volume path, record the relevant measurement, query plan, bundle effect, or complexity argument. Do not claim a performance improvement from code shape alone.
## Frontend Rules
- Reuse primitive controls from `apps/app/src/components/ui`. - Put app-wide composed UI in `apps/app/src/components`. - Put feature-specific UI, hooks, state, and behavior in `apps/app/src/react-app/domains/<domain>`. - Move UI to `packages/ui` only when more than one application genuinely consumes it. - Keep domain internals private. Share a stable public API or move truly cross-domain logic to a neutral owner instead of deep-importing another domain. - Use server APIs for server-owned behavior. Never reproduce filesystem, persistence, authorization, or orchestration logic in the client. - Put cross-process request/response contracts in `packages/types`; do not maintain separate client and server copies.
## Server And Generated Files
- Add thin HTTP handlers to `apps/server/src/routes`; put reusable business behavior in the existing owning service/extension module. - Reuse path guards from `apps/server/src/paths.ts`, including safe workspace-relative normalization and root containment helpers. - Never construct user-controlled filesystem paths with unchecked `path.join` or string concatenation. - Runtime exports, uploads, captures, renders, audio, images, and generated HTML must not be written under `apps/server/src` or another source directory. - Preserve the current session layout: `<workspace>/design/<session-id>/...` for design/PPT/web sessions and `<workspace>/video/<session-id>/...` for video sessions. - Put artifact kinds such as assets, renders, audio, captures, and exports below the owning session directory when appropriate. - Centralize directory creation and path resolution in one owning service. Routes and UI should pass identifiers, not invent disk paths.
## Platform And Repository Safety
- Keep Electron lifecycle and native integration in `apps/desktop`; do not leak shell-specific behavior into app domains. - Keep headless runtime orchestration in `apps/orchestrator`; do not create a second orchestration path in the UI or server. - Keep OpenCode external. Use its supported API, SDK, CLI, plugin, and configuration surfaces; do not fork or silently modify its internals. - Keep names consistently `iPolloWork` and `ipollowork`; do not introduce alternate product spellings in code, paths, docs, or user-facing text. - Do not commit secrets, credentials, local caches, build output, generated runtime artifacts, or commercial-only code.
## Verification By Risk
- TypeScript or UI: run the owning package typecheck and focused tests. - Server or plugin: run focused unit tests and the relevant package test. - Build or runtime boundary: build the affected package and start the real development entrypoint. - Observable UI: verify the actual browser/Electron flow using the repository experience-proof rules in `AGENTS.md`. - Dependency or OpenCode change: record old/new versions and verify startup, configuration, and the affected loading path. - Database or high-volume query: verify migrations, constraints, rollback/rejection behavior, bounded results, and the relevant query plan when representative data exists.
## Completion Standard
- No existing reusable implementation was missed. - No unjustified file, directory, dependency, route, table, state store, or abstraction was added. - No client/server contract was duplicated. - No runtime artifact was added to a source tree. - New files have one clear owner and do not create a parallel architecture. - Runtime work is bounded and no obvious N+1, request loop, broad subscription, or heavy eager import was introduced. - Existing behavior remains the default when extending shared code. - Replaced code and stale documentation were removed instead of retained as alternate versions. - Focused tests, package checks, `git diff --check`, and the maintainability audit pass; any unverified runtime surface is stated explicitly.
Technical details
- Version
- 1.0.0
- License
- NOASSERTION
- Last updated
- Aug 22, 2026
- Published
- Aug 22, 2026
Decision snapshot
Primary pick
4,479 GitHub stars
Audit
Install review
Install and adoption review
- Security
- 74/100
- Maintenance
- 100/100
- Install
- 92/100
Agent-proven evidence
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
- Success rate
- —
- Recent failure
- —
- Outcomes
- 0
- Output quality
- —
- Failed
- 0
- Not relevant
- 0
- Installs
- 0
- Risk blocked
- 0
- Setup needed
- 0
- Production
- 0
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Add to agent workflow
Free and open source. Review the report before installing into production agents.
Growth loop
Share kit
Scenario-led draft for ipollowork-maintainable-code, ready for a manual X post.
ipollowork-maintainable-code: Mandatory iPolloWork code-change gate for modern, minimal, performant, reuse-first implementa... 4.5K stars https://www.openagentskill.com/skills/devin-axis-ipollowork-maintainable-code?ref=x
Optional reply with install command
Listing + install path for ipollowork-maintainable-code: https://www.openagentskill.com/skills/devin-axis-ipollowork-maintainable-code?ref=x Install: npx skills add Devin-AXIS/iPolloWork --skill ipollowork-maintainable-code
Listing source
Registry indexed
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
- Creator
- Devin-AXIS
- Source
- Devin-AXIS/iPolloWork
- Indexed by
- OpenAgentSkill community index
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
Claim this skill listing
This Registry indexed listing is attributed to Devin-AXIS but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Add the evidence badges to your README
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/devin-axis-ipollowork-maintainable-code)
[](https://www.openagentskill.com/skills/devin-axis-ipollowork-maintainable-code)
[](https://www.openagentskill.com/skills/devin-axis-ipollowork-maintainable-code/audit)
[](https://www.openagentskill.com/skills/devin-axis-ipollowork-maintainable-code)Author
Devin-AXIS
@devin-axis
Tags
Platform fit
Health signals
- GitHub stars
- 4.5K
- Quality score
- 49/100
- Last GitHub push
- Aug 22, 2026
- Framework hints
- Unknown
- OpenAgentSkill views
- 1
- Install copies
- 0
- Outbound clicks
- 0
Community signal
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Trust & safety
Sandbox only
- GitHub adoption4.5K GitHub starsPASS
- Stars/forks activity4.5K stars, 878 forks; issue activity unavailable in current metadataPASS
- Recent maintenancePushed todayPASS
- License clarityNOASSERTIONPASS
- README/SKILL.md completenessPublic metadata needs stronger README/SKILL.md contextINFO
- Dependency/runtime riskcommand execution surface, network or browser surfaceCHECK
Related skills
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16.3K StarsMaigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
32.9K StarsNuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29.2K StarsInfisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
27.4K Stars