iso-24495-code

审查 · 63
已收录

Plain language applied to source code (ISO 24495-1:2023 principles). Governs the parts of code a person reads: the order units appear in, their names, comments, and error messages. Applied when writing or restructuring code, not when explaining it.

Verified installs0
Stars89
版本1.0.0
质量67/100 · 有潜力
信任63/100 · 仅限沙盒
审计78/100 · 需审查

供给资产档案

研究与知识工作

Deep research, source comparison, literature review, RAG, knowledge search, and reports.

浏览赛道

场景

研究 Agent

I need my agent to research a topic, compare sources, and produce a concise report.

适配 Agent

Claude Code + CLI + Codex

适用于 Codex、Claude Code、Cursor、CLI 或自定义 Agent。

安装

就绪

npx skills add GaZmagik/iso-24495 --skill iso-24495-code

维护状态

新鲜

距上次推送 1 天

风险

需审查

Dependency or permission surface needs review

GitHub 质量

89

67/100 质量 · 71/100 信任

覆盖标签

研究研究 Agentagent-skill

审查说明

Dependency or permission surface needs review · Permission surface may require sandboxing

Agent 采用评分卡

一眼查看信任、审计与安装准备度

这些分数综合公开仓库元数据、OpenAgentSkill 审查信号、维护新鲜度与安装准备度。它用于候选筛选,不替代人工审查。

质量

有潜力
67

有用的候选项,但采用前应与替代方案比较。

信任

仅限沙盒
63

有用但信任信号不足或混杂的候选项。在结果闭环证明任务匹配前,请保持在隔离工作区内使用。

审计

需审查
78

对安装准备度、安全元数据、维护情况与采用风险的机器可读审查。

OpenAgentSkill 信任评分 v5

安装前需人工审查

仅在沙盒中运行,并在用于真实工作前比较接近的替代方案。

CodexClaude CodeCursorOpenAgentSkill CLI

Stars

89 个 GitHub Stars

仓库活跃度

89 个 Star,4 个 Fork

维护状态

距上次推送 1 天

许可证

MIT

安装

npx skills add GaZmagik/iso-24495 --skill iso-24495-code

安装安全性

标准软件包或运行时安装路径

权限范围

secrets or environment access, filesystem or document access

Agent 结果

暂未有 Agent 结果数据

文档

Usable metadata, review docs

风险摘要

生产前审查

  • Quality score needs review
  • Permission surface needs review: secrets or environment access, filesystem or document access
  • GitHub adoption: 89 GitHub stars
  • Stars/forks activity: 89 stars, 4 forks; issue activity unavailable in current metadata

安装准备度

安装路径可用

  • 安装路径可用
  • 仓库证据可用
  • 已声明许可证
  • 暂无 Agent 验证结果证据

Agent 可读元数据

这个 Skill 的机器可读决策数据。

使用此区块或内嵌 JSON 判断 Agent 是否应安装该 Skill、选择替代方案,或先请求人工审查。

打开 JSON

适用任务

  • 研究 Agent 工作流
  • Claude Code 团队
  • builders willing to evaluate younger projects
  • 检索来源

适用 Agent

CodexClaude CodeCursorOpenAgentSkill CLICLI

安装决策

命令
npx skills add GaZmagik/iso-24495 --skill iso-24495-code
策略
审查
人工审查

信任与风险

信任
63/100
审计
78/100
风险级别
需审查

结果闭环

端点
/api/agent/outcome
事件 ID
resolve
结果
5

安装命令

npx skills add GaZmagik/iso-24495 --skill iso-24495-code

不适用场景

  • 需要厂商支持 SLA 的团队
  • 没有内部安全审查的高合规环境
  • 暂未有 OpenAgentSkill 使用反馈数据
  • 高风险权限提示:Secrets or environment access
  • Dependency or permission surface needs review

Agent 安全 v2

46/100 · 避免自动安装

实验性审查

Sparse or mixed signals. Useful for discovery, but not for autonomous installation.

Test manually in an isolated workspace and compare against safer alternatives.

通过 API 解析

Browser automation

Skill may drive a browser or interact with web pages.

网络访问

Skill 可能访问远程页面、API、仓库或外部服务。

文件系统访问

Skill 可能读取或写入项目文件、文档、生成产物或本地工作区状态。

Secrets or environment access

Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.

  • 高风险权限提示:Secrets or environment access
  • Dependency or permission surface needs review

安装目标

在你的 Agent 工作流中安装此 Skill

通过公开安装端点获取命令、安全清单、目标提示词和该 Skill 的规范链接。

skill install

OpenAgentSkill CLI

Resolve policy, run the source installer safely, and report a verified install receipt.

$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install gazmagik-iso-24495-code

Agent 解析计划

让 Agent 在安装前验证匹配度。

Resolve API 返回首选 Skill、替代方案、安全策略、审计说明、安装目标和可直接执行的提示词,无需抓取此页面。

打开文本计划

Agent 应检查

  • 从 Resolve API 检查任务匹配与替代方案。
  • 检查审计评分、信任评分和安全策略警告。
  • 检查 Codex、Claude Code、Cursor 或 CLI 的安装目标兼容性。

复制提示词

Task: Use iso-24495-code in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20iso-24495-code%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/gazmagik-iso-24495-code/install
Install command: npx skills add GaZmagik/iso-24495 --skill iso-24495-code
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.

Agent 交接

把安装路径交给 Agent,而不是再给一个目录页。

通过公开安装端点获取命令、安全清单、目标提示词和该 Skill 的规范链接。

打开安装 API

Agent 提示词

Use iso-24495-code for this task. Review https://www.openagentskill.com/api/skills/gazmagik-iso-24495-code/install, then install with: npx skills add GaZmagik/iso-24495 --skill iso-24495-code

Registry 元数据

用于自动选择 Skill 的 Agent 可读档案。

本页通过 Registry API 提供相同的决策、信任、审计、场景和安装信号,让 Agent 无需抓取界面即可排序。

打开 Manifest

适配 Agent

66/100

研究 Agent

平台

Claude Code

审计报告

需审查 · 78/100

对安装准备度、安全元数据、维护情况与采用风险的机器可读审查。

查看审计报告查看评估报告

Agent 决策面板

Fallback candidate for Research agents

先用此 Skill 做原型验证,并保留备选方案。

66
就绪度
原型验证
阶段

栈中角色

备选候选

主要匹配

研究 Agent

信任标签

先做原型验证

安装路径

命令已就绪

适用场景

  • 研究 Agent 工作流
  • Claude Code 团队
  • builders willing to evaluate younger projects

证据

  • 仓库近期活跃
  • 已提供安装命令或 GitHub 仓库
  • 67/100 质量档案

先审查

  • 暂未有 OpenAgentSkill 使用反馈数据

实施路径

  1. 1在沙盒 Agent 中安装它,并端到端完成一次研究 Agent任务。
  2. 2Compare output quality, latency, and failure behavior against at least one alternative.
  3. 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.

信任档案

仅限沙盒

有用但信任信号不足或混杂的候选项。在结果闭环证明任务匹配前,请保持在隔离工作区内使用。

63
OpenAgentSkill 信任评分

GitHub 采用度

检查

89 个 GitHub Stars

Star/Fork 活跃度

检查

89 个 Star,4 个 Fork; 当前元数据中没有议题活跃度信息

近期维护

通过

距上次推送 1 天

许可证清晰度

通过

MIT

积极信号

  • AI 审查已通过
  • 安装路径可用
  • 仓库证据可用
  • 近期维护的仓库
  • 安装命令未发现明显高风险模式
  • 结果闭环已就绪,但需要首次真实 Agent 运行

安装前审查

  • Quality score needs review
  • Permission surface needs review: secrets or environment access, filesystem or document access
  • GitHub adoption: 89 GitHub stars
  • Stars/forks activity: 89 stars, 4 forks; issue activity unavailable in current metadata
  • Dependency/runtime risk: credential or environment access, external package install surface
  • Permission surface: secrets or environment access, filesystem or document access
  • 暂未有真实 Agent 结果报告
  • 无人值守安装前需要人工审查

建议操作

仅在沙盒中运行,并在用于真实工作前比较接近的替代方案。

质量档案

有潜力 适用于 Agent 工作流的候选

有用的候选项,但采用前应与替代方案比较。

67
GitHub Stars
89
新鲜度
1 天前
安装就绪
许可证
MIT

工作流匹配

在这些场景使用此 Skill

工作流匹配

加入完整工作流

替代方案短名单

安装前对比

可能适合该任务的相近 Skill。

对比全部

概览

--- name: iso-24495-code description: Plain language applied to source code (ISO 24495-1:2023 principles). Governs the parts of code a person reads: the order units appear in, their names, comments, and error messages. Applied when writing or restructuring code, not when explaining it. metadata: version: "0.6.0" iso-standard: "ISO 24495-1:2023" iso-status: "published, applied by analogy to source code" ---

# Plain language in code

Extends ISO 24495-1 to source code. Code is read far more often than it is written, so the person reading it is the reader the standard is about.

**Scope**. This skill governs what a reader reads: the order units appear in, what they are called, what the comments say, and what an error tells the person who hits it.

It does not govern correctness, performance, or system design. It does govern local organisation, in rules 1 and 2, because where a unit sits and how far it reaches decide what a reader must hold in their head. For maintainability weaknesses such as complexity and dead code, use a code quality skill built on ISO/IEC 5055.

**This is an interpretation of ISO 24495-1 applied by analogy, not a conformance claim.**

## The four principles, in code

| Principle | In prose | In code | |---|---|---| | Findable | The reader can find what they need | The public entry point appears first | | Understandable | The reader understands it | Names say what the thing is, in the reader's words | | Relevant | The reader gets what they need | A comment says why; interface documentation says what | | Usable | The reader can act on it | An error names the problem and shows a safe value |

## Rules

### 1. Front-load the main path

**Put the public entry point at the top of the file**, before the helpers it calls. A reader opening the file meets the thing it does, then the detail, in that order. This is the code form of leading with the outcome.

Where a language forces declarations before use, put a short delegating entry point first and the implementation below it.

> Measured on 30 generated implementations of one specification. Without this rule the public > function landed anywhere in the file, and in half the files it was the last thing in it. > With the rule it sat in the first fifth of the file every time. > > The measure was chosen after those runs rather than before them, and the effect appeared in > one model family but not in the two others tested. Treat it as a hypothesis with a clean > separation, not a settled result.

### 2. One job per unit

A function does one thing that its name describes. **A name needing "and" is a prompt to look, not an instruction to split.** Some operations are genuinely single and named for a pair, as `compareAndSwap` is, and splitting those breaks them.

Helpers belong at the top level or as members of a class, rather than buried as closures inside the function they serve. A reader cannot reach a closure without reading its container first.

### 3. Name for the reader

- A name says what the thing **is** or **does**, in the vocabulary of someone who knows the domain but not this file. - **Use one name for one concept throughout.** If it is a `token` here it is not a `lexeme` three functions later. Elegant variation confuses code exactly as it confuses prose. - Prefer a longer name that reads to a shorter one that must be decoded. `remainingBudget` beats `rb`.

### 4. A comment says why; interface documentation says what a caller needs

A comment earns its place when it records something a reader cannot recover from the code: a reason, a constraint, a rejected alternative, a bug it guards against.

**Delete a comment that merely restates the line beneath it**, and delete commented-out code.

This is not a rule against documentation. An interface comment tells a caller what a function returns, when it returns nothing, and what it throws. That is the reader's work being done for them, so it belongs there even when the body makes it obvious.

### 5. An error message serves the person who hits it

An error names the problem, shows a value it is safe to show, and where it helps, says what to do instead. Write it in the words its reader would use, so it can be acted on without opening the source.

**Never put a secret in an error.** A credential, token, key, password, session identifier or personal detail must not appear in a message, because messages reach logs, telemetry and screens. Name the field and describe the fault instead: `API token rejected: expected 32 characters, got 8`. Where you cannot show a value safely, show its shape.

**A value on this path has just failed validation, so its contents are unknown.** Naming the field does not make them safe: whatever the caller passed is what reaches the log. Report the format you expected and the shape of what arrived, never the value itself.

``` Bad: throw new Error("invalid input") Good: throw new TypeError( `Duration must be a number followed by ms, s, m, h or d; got ${duration.length} characters`) Good: throw new Error(`API token rejected: expected 32 characters, got ${token.length}`) ```

Quote a value only where you control it, such as one you have already matched against a fixed set. Then the set, not the caller, decides what can appear.

### 6. Prefer the plain construction

Where two constructions are equally correct, use the one a competent reader understands without pausing. Cleverness that needs a comment to explain it has already failed.

## What this skill does not do

- It does not require comments. A file with no comments and clear names is fine. - It does not set a line count for a function. Use `iso-5055-code-quality` for size and complexity thresholds, which are measurable. - It does not apply to generated code, vendored code, or code whose layout a formatter owns.

## Applying it to existing code

Change the reading order and the language. Do not restructure behaviour in the same pass, and never move code and change it at once, because the diff stops being reviewable.

技术详情

版本
1.0.0
许可证
MIT
最近更新
2026年8月21日
发布时间
2026年8月21日

决策摘要

备选候选

66
就绪
原型验证
阶段

仓库近期活跃

审计

安装审查

安装与采用审查

78
需审查
安全性
79/100
维护状态
100/100
安装
92/100
打开完整审计查看评估报告

Agent 验证证据

Agent 验证证据

来自解析、审查、安装和一次小范围运行后的结果报告。

0
已验证
Needs first agent run自动安装: 先审查最近: 未知
成功率
近期失败
结果
0
输出质量
失败
0
不相关
0
安装次数
0
风险拦截
0
需要配置
0
生产环境
0

暂时没有 Agent 结果数据。首次 Agent 执行可以通过 /api/agent/outcome 报告成功、需要设置、风险拦截、失败或不相关。

安装

加入 Agent 工作流

免费且开源. 在生产 Agent 中安装前请先审查报告。

增长闭环

分享工具包

X

为 iso-24495-code 准备的场景化草稿,可手动发布到 X。

策展说明
iso-24495-code: Plain language applied to source code (ISO 24495-1:2023 principles). Governs the parts of cod...

89 stars

https://www.openagentskill.com/skills/gazmagik-iso-24495-code?ref=x
打开 X 草稿
可选:带安装命令的回复
Listing + install path for iso-24495-code:
https://www.openagentskill.com/skills/gazmagik-iso-24495-code?ref=x

Install: npx skills add GaZmagik/iso-24495 --skill iso-24495-code
打开回复草稿

收录来源

Registry 收录

可认领

此列表来自公开来源,维护者认领获批前不会标记为官方。

创作者
GaZmagik
收录方
OpenAgentSkill 社区索引

归属链接指向公开仓库或创作者主页。创作者可认领列表以更新所有权信号。

认领此 Skill

所有者认领

认领此 Skill 页面

这条 Registry 收录 列表归属于 GaZmagik,但尚未标记为官方。认领后可增加已验证所有者信号,使后续发布、安装和审计更新更值得信赖。

创作者外链工具包

将证据徽章加入你的 README

在开发者评估仓库的位置展示规范页面、当前信任与审计信号,以及真实的 Agent 验证证据。

[![Listed on OpenAgentSkill](https://www.openagentskill.com/api/badge/gazmagik-iso-24495-code?metric=listed&label=Listed)](https://www.openagentskill.com/skills/gazmagik-iso-24495-code)
[![OpenAgentSkill Trust](https://www.openagentskill.com/api/badge/gazmagik-iso-24495-code?metric=trust&label=Trust)](https://www.openagentskill.com/skills/gazmagik-iso-24495-code)
[![OpenAgentSkill Audit](https://www.openagentskill.com/api/badge/gazmagik-iso-24495-code?metric=audit&label=Audit)](https://www.openagentskill.com/skills/gazmagik-iso-24495-code/audit)
[![Agent Proven](https://www.openagentskill.com/api/badge/gazmagik-iso-24495-code?metric=proven&label=Agent%20Proven)](https://www.openagentskill.com/skills/gazmagik-iso-24495-code)

作者

G

GaZmagik

@gazmagik

平台适配

健康信号

GitHub Stars
89
质量评分
37/100
最近 GitHub 推送
2026年8月21日
框架提示
未知
OpenAgentSkill 浏览量
0
复制安装命令
0
跳转点击
0

社区信号

告诉我们这个 Skill 是否对你的 Agent 工作流有帮助。汇总反馈会持续改善排序。

信任与安全

仅限沙盒

63
  • GitHub 采用度89 个 GitHub Stars检查
  • Star/Fork 活跃度89 个 Star,4 个 Fork; 当前元数据中没有议题活跃度信息检查
  • 近期维护距上次推送 1 天通过
  • 许可证清晰度MIT通过
  • README/SKILL.md 完整度公开元数据需要更完整的 README/SKILL.md 上下文信息
  • 依赖与运行时风险credential or environment access, external package install surface检查