gza-code-review-full

レビュー · 50
Registry に収録

Comprehensive pre-release code review assessing test coverage, code duplication, and component interactions

Verified installs0
スター11
バージョン1.0.0
品質57/100 · 有望
信頼50/100 · Do not auto-install
監査69/100 · 要レビュー

供給アセットの概要

コーディングと開発 Agent

コードレビュー、リポジトリ分析、テスト、CI、GitHub、DevOps、開発ワークフロー向けのスキルです。

カテゴリを見る

シナリオ

GitHub automation

I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.

Agent 適合

Claude Code + Cursor + CLI

Codex、Claude Code、Cursor、CLI、またはカスタム Agent に対応します。

インストール

準備完了

npx skills add mhawthorne/gza --skill gza-code-review-full

メンテナンス

新しい

最終プッシュから 1 日

リスク

要レビュー

Dependency or permission surface needs review

GitHub 品質

11

57/100 品質 · 58/100 信頼

対象タグ

コーディングGitHub automationコーディング Agentagent-skill

レビュー注記

Dependency or permission surface needs review · Permission surface may require sandboxing

Agent 導入スコアカード

信頼、監査、インストール準備状況を一目で確認

公開リポジトリのメタデータ、OpenAgentSkill のレビューシグナル、保守の鮮度、インストール準備状況を組み合わせたスコアです。候補選定の目安であり、人によるレビューの代替ではありません。

品質

有望
57

有用な候補ですが、採用前に代替と比較してください。

信頼

Do not auto-install
50

Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.

監査

要レビュー
69

インストール準備、安全メタデータ、保守、採用リスクの機械可読なレビュー。

OpenAgentSkill Trust Score v5

サンドボックス限定

Choose a stronger alternative or inspect the source manually before any install attempt.

CodexClaude CodeCursorOpenAgentSkill CLI

スター

GitHub スター 11

リポジトリ活動

スター 11、フォーク 1

メンテナンス

最終プッシュから 1 日

ライセンス

MIT

インストール

npx skills add mhawthorne/gza --skill gza-code-review-full

インストール安全性

標準パッケージまたはランタイムのインストールパス

権限範囲

secrets or environment access, shell or command execution

Agent の成果

Agent の成果データはまだありません

ドキュメント

README/SKILL.md の文脈が十分です

リスク概要

本番前にレビュー

  • Skill is highly specific to the gza codebase, limiting reusability for other projects.
  • Low GitHub adoption signal
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution

インストール準備状況

インストールパスを利用可能

  • インストールパスを利用できます
  • リポジトリの根拠を利用できます
  • ライセンスが明示されています
  • Agent-Proven の成果エビデンスはまだありません

Agent 可読メタデータ

このスキルの機械可読な判断データ。

このブロックまたは埋め込み JSON を使い、Agent がこのスキルをインストールすべきか、代替を選ぶべきか、先に人のレビューを求めるべきかを判断できます。

JSON を開く

適したタスク

  • GitHub automation ワークフロー
  • Claude Code チーム
  • builders willing to evaluate younger projects
  • Inspect repository metadata

適した Agent

CodexClaude CodeCursorOpenAgentSkill CLICLI

インストール判断

コマンド
npx skills add mhawthorne/gza --skill gza-code-review-full
ポリシー
ブロック
人によるレビュー
はい

信頼とリスク

信頼
50/100
監査
69/100
リスクレベル
要レビュー

成果ループ

エンドポイント
/api/agent/outcome
イベント ID
resolve
成果
5

インストールコマンド

npx skills add mhawthorne/gza --skill gza-code-review-full

使わない場合

  • ベンダー提供の SLA が必要なチーム
  • production agents without a repository review
  • Low GitHub adoption signal
  • Skill is highly specific to the gza codebase, limiting reusability for other projects.
  • 高リスク権限のヒント: Shell or command execution, Secrets or environment access

Agent セーフティ v2

25/100 · 自動インストールを避ける

Blocked for auto-installブロック

This skill should not be selected by an agent without explicit human security review.

Do not auto-install. Inspect the source, dependencies, and permission surface first.

API で解決

Shell またはコマンド実行

Skill メタデータに端末、CLI、Shell、サブプロセス、またはコマンド実行のワークフローが含まれます。

ネットワークアクセス

Skill はリモートページ、API、リポジトリ、外部サービスにアクセスする可能性があります。

ファイルシステムアクセス

Skill はプロジェクトファイル、ドキュメント、生成物、ローカルワークスペース状態を読み書きする可能性があります。

Secrets or environment access

Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.

  • 高リスク権限のヒント: Shell or command execution, Secrets or environment access
  • Dependency or permission surface needs review

インストール先

Agent ワークフローにこのスキルをインストール

公開インストールエンドポイントからコマンド、安全チェックリスト、対象プロンプト、正規リンクを取得します。

skill install

OpenAgentSkill CLI

Resolve policy, run the source installer safely, and report a verified install receipt.

$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install mhawthorne-gza-code-review-full

Agent 解決プラン

インストール前に Agent に適合性を検証させます。

Resolve API は第一候補、代替、安全ポリシー、監査メモ、インストール先、Agent がそのまま使えるプロンプトを返します。

テキストプランを開く

Agent が確認すべきこと

  • Resolve API でタスク適合と代替を確認。
  • 監査・信頼スコアと安全ポリシーの警告を確認。
  • Codex、Claude Code、Cursor、CLI のインストール先互換性を確認。

プロンプトをコピー

Task: Use gza-code-review-full in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20gza-code-review-full%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/mhawthorne-gza-code-review-full/install
Install command: npx skills add mhawthorne/gza --skill gza-code-review-full
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.

Agent 引き継ぎ

別のディレクトリではなく、インストール経路を Agent に渡します。

公開インストールエンドポイントからコマンド、安全チェックリスト、対象プロンプト、正規リンクを取得します。

Install API を開く

Agent プロンプト

Use gza-code-review-full for this task. Review https://www.openagentskill.com/api/skills/mhawthorne-gza-code-review-full/install, then install with: npx skills add mhawthorne/gza --skill gza-code-review-full

Registry メタデータ

自動スキル選択用の Agent 可読プロファイル。

Registry API 経由で判断、信頼、監査、ユースケース、インストールのシグナルを提供し、UI をスクレイピングせずに Agent が順位付けできます。

Manifest を開く

Agent 適合

56/100

GitHub automation

プラットフォーム

Claude Code, Cursor

監査レポート

要レビュー · 69/100

インストール準備、安全メタデータ、保守、採用リスクの機械可読なレビュー。

監査レポートを見る評価レポートを見る

Agent 判断パネル

Needs validation for GitHub automation

Agent ワークフローに追加する前に手動でリポジトリをレビューしてください。

56
準備状況
レビュー
段階

スタック内の役割

検証が必要

主な適合

GitHub automation

信頼ラベル

手動レビューが必要

インストールパス

コマンド準備済み

使う場面

  • GitHub automation ワークフロー
  • Claude Code チーム
  • builders willing to evaluate younger projects

根拠

  • 最近のリポジトリ活動
  • インストールコマンドまたは GitHub リポジトリが利用可能
  • 品質プロファイル 57/100
  • OpenAgentSkill エンゲージメント 1 件

先にレビュー

  • Low GitHub adoption signal
  • Skill is highly specific to the gza codebase, limiting reusability for other projects.

実装パス

  1. 1サンドボックスの Agent にインストールし、GitHub automation タスクを一度最初から最後まで実行します。
  2. 2Compare output quality, latency, and failure behavior against at least one alternative.
  3. 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.

信頼プロファイル

Do not auto-install

Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.

50
OpenAgentSkill Trust Score

GitHub 採用度

修正

GitHub スター 11

スター/フォーク活動

修正

スター 11、フォーク 1; 現在のメタデータでは Issue 活動を利用できません

最近のメンテナンス

合格

最終プッシュから 1 日

ライセンスの明確さ

合格

MIT

良いシグナル

  • AI レビュー承認済み
  • インストールパスを利用できます
  • リポジトリの根拠を利用できます
  • 最近保守されたリポジトリ
  • インストールコマンドに明確な高リスクパターンはありません
  • 成果ループは準備済みですが、最初の実行が必要です

インストール前にレビュー

  • Skill is highly specific to the gza codebase, limiting reusability for other projects.
  • Low GitHub adoption signal
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution
  • GitHub adoption: 11 GitHub stars
  • Stars/forks activity: 11 stars, 1 forks; issue activity unavailable in current metadata
  • Dependency/runtime risk: command execution surface, credential or environment access
  • Permission surface: secrets or environment access, shell or command execution
  • 実際の Agent 成果レポートはまだありません
  • 無人インストールの前に人によるレビューが必要です

推奨アクション

Choose a stronger alternative or inspect the source manually before any install attempt.

品質プロファイル

有望 Agent ワークフロー向けの候補

有用な候補ですが、採用前に代替と比較してください。

57
GitHub スター
11
鮮度
1 日前
インストール準備完了
はい
ライセンス
MIT
インストール前にレビュー: Low GitHub adoption signal · Skill is highly specific to the gza codebase, limiting reusability for other projects.

ワークフロー適合

このスキルを使うシナリオ

ワークフロー適合

完全なワークフローに追加

代替候補

インストール前に比較

このタスクに適する可能性のある類似スキル。

すべて比較

概要

--- name: gza-code-review-full description: Comprehensive pre-release code review assessing test coverage, code duplication, and component interactions allowed-tools: Read, Glob, Grep, Bash(uv run pytest:*), Bash(uv run python:*), Bash(uv run mypy:*), Bash(ls:*), Bash(wc:*) version: 1.0.0 public: false ---

# Full Codebase Code Review

Perform a comprehensive code review of the gza codebase, suitable for pre-release assessment. This review covers: 1. Unit test coverage 2. Functional test coverage 3. Code duplication 4. Component interaction patterns 5. Error handling consistency 6. API/interface consistency 7. Configuration and hardcoding audit 8. Logging and observability 9. Resource management 10. Type safety

## When to Use

- Before a release to assess codebase health - When you want a comprehensive quality check - To identify areas needing more tests or refactoring

## Output

Write findings to `reviews/<timestamp>-code-review-full-<model>.md` in the project root, where `<timestamp>` is the current date/time in `YYYYmmddHHMMSS` format and `<model>` is a short identifier for the model performing the review (e.g., `reviews/20260305114139-code-review-full-opus-4-6.md`). Use your own model name/ID to derive the short identifier.

## Process

### Step 1: Inventory the codebase

Map out the source modules and test files:

1. **List all source modules:** ```bash ls -la src/gza/*.py ls -la src/gza/providers/*.py ```

2. **List all test files:** ```bash ls -la tests/*.py ls -la tests_integration/*.py 2>/dev/null || echo "No integration tests dir" ```

3. **Create a mapping** of source file → test file(s): - `db.py` → `test_db.py` - `cli.py` → `test_cli.py` - etc.

4. **Identify untested modules** - source files with no corresponding test file

### Step 2: Assess unit test coverage

For each source module:

1. **Read the source file** to understand its public interface (functions, classes, methods)

2. **Read the corresponding test file** (if exists)

3. **Check coverage by listing:** - Functions/methods that ARE tested - Functions/methods that are NOT tested - Edge cases that aren't covered (error paths, boundary conditions)

4. **Run the tests** to verify they pass: ```bash uv run pytest tests/ -v --tb=short ```

Focus especially on: - **`db.py`** - Core task storage, critical for correctness - **`cli.py`** - User-facing commands, all subcommands should have tests - **`runner.py`** - Task execution logic - **`git.py`** - Git operations (mocked tests preferred) - **`github.py`** - GitHub integration

### Step 3: Assess functional test coverage

Functional tests verify end-to-end workflows. Check for:

1. **Core workflows that should have integration tests:** - Creating a task → running it → verifying completion - Task dependencies (task B waits for task A) - PR creation workflow - Review workflow - Improve workflow

2. **Read `tests_integration/`** (if exists) to see what's covered

3. **Identify missing functional tests** - workflows documented in AGENTS.md that aren't tested

### Step 4: Analyze code duplication

Look for patterns of duplicated code:

1. **Search for similar code blocks:** - Similar function signatures doing similar things - Copy-pasted error handling - Repeated patterns that could be extracted

2. **Check specific areas prone to duplication:** - CLI command handlers (do they share common patterns that could be unified?) - Database queries (repeated query patterns) - Git operations (similar git command sequences)

3. **Use grep to find suspicious patterns:** ```bash # Find similar function definitions grep -n "def.*task" src/gza/*.py

# Find repeated patterns grep -n "subprocess.run" src/gza/*.py grep -n "click.echo" src/gza/cli.py ```

4. **Read AGENTS.md** section on "Single code path principle" and verify it's followed

### Step 5: Check error handling consistency

Review how errors are handled across the codebase:

1. **Identify error handling patterns:** ```bash # Find exception raising grep -n "raise " src/gza/*.py

# Find try/except blocks grep -n "except " src/gza/*.py

# Find custom exceptions grep -rn "class.*Exception" src/gza/ grep -rn "class.*Error" src/gza/ ```

2. **Check for consistency:** - Are errors handled uniformly? (always raise vs sometimes return None) - Are custom exceptions used where appropriate vs generic `Exception`? - Do error messages provide actionable information? - Are exceptions caught too broadly? (`except Exception` vs specific types)

3. **Look for problematic patterns:** - Silent failures (bare `except:` or `except: pass`) - Swallowed exceptions without logging - Inconsistent error return values (None vs empty list vs raise) - Missing error handling on I/O operations

4. **Document findings:** - List any inconsistencies in error handling approach - Note functions that should raise but return None (or vice versa) - Identify error messages that aren't helpful for debugging

### Step 6: Check API/interface consistency

Review function signatures and naming conventions:

1. **Check naming consistency:** ```bash # Find all public function definitions grep -n "^def " src/gza/*.py grep -n " def " src/gza/*.py | grep -v "__" ```

2. **Look for inconsistencies:** - Similar operations with different names (`get_task` vs `fetch_task` vs `retrieve_task`) - Parameter ordering inconsistencies (does `db` come first or last?) - Return type inconsistencies (objects vs dicts vs tuples)

3. **Check function signatures:** - Do similar functions have similar signatures? - Are there functions with too many parameters (>5)? - Are boolean parameters used where enums would be clearer?

4. **Review public interfaces:** - Are module `__all__` exports defined? - Is it clear what's public vs private? (underscore prefix convention) - Are there functions that should be private but aren't?

### Step 7: Audit configuration and hardcoding

Look for magic values that should be configurable:

1. **Find hardcoded values:** ```bash # Find numeric literals (potential magic numbers) grep -En "[^a-zA-Z_][0-9]{2,}[^0-9]" src/gza/*.py

# Find string literals that might be paths or config grep -n '"/.*"' src/gza/*.py grep -n "'/.*'" src/gza/*.py ```

2. **Check for:** - Magic numbers (timeouts, retry counts, limits) - Hardcoded file paths - Hardcoded URLs or endpoints - Default values that should be configurable

3. **Review path handling:** - Are paths constructed safely using `pathlib`? - Are there string concatenations for paths? (`dir + "/" + file`) - Are relative vs absolute paths handled correctly?

4. **Check configuration loading:** - Is `config.py` the single source for configuration? - Are there config values scattered in other modules? - Are defaults documented?

### Step 8: Review logging and observability

Assess the ability to debug and monitor the system:

1. **Check logging usage:** ```bash # Find logging calls grep -n "logging\." src/gza/*.py grep -n "logger\." src/gza/*.py grep -n "log\." src/gza/*.py

# Find print statements (should these be logs?) grep -n "print(" src/gza/*.py ```

2. **Assess logging quality:** - Is there consistent logging for key operations? - Can you trace a task's execution through the logs? - Are log levels used appropriately? (debug vs info vs warning vs error) - Are there operations that fail silently without logging?

3. **Check for sensitive data exposure:** ```bash # Look for potential credential logging grep -in "api.key\|token\|password\|secret\|credential" src/gza/*.py ``` - Are API keys, tokens, or passwords properly excluded from logs? - Are there any `repr()` or `str()` methods that might expose secrets?

4. **Review error logging:** - Are exceptions logged with stack traces where needed? - Are error messages actionable? - Is there enough context to debug issues?

### Step 9: Check resource management

Look for resource leaks and cleanup issues:

1. **Check file handling:** ```bash # Find file operations grep -n "open(" src/gza/*.py grep -n "with open" src/gza/*.py ``` - Are all file opens using context managers (`with`)? - Are there any `open()` calls without corresponding `close()`?

2. **Check database connections:** ```bash grep -n "connect(" src/gza/*.py grep -n "cursor" src/gza/*.py ``` - Are database connections properly closed? - Are cursors managed with context managers? - Is there connection pooling or is it connect-per-operation?

3. **Check subprocess management:** ```bash grep -n "subprocess" src/gza/*.py grep -n "Popen" src/gza/*.py ``` - Are subprocesses properly waited on? - Are there potential zombie processes? - Are stdin/stdout/stderr handles closed?

4. **Check for memory issues:** - Are there unbounded caches or growing lists? - Are large objects cleaned up after use? - Are there circular references that prevent garbage collection?

5. **Check temp file cleanup:** ```bash grep -n "tempfile\|mktemp\|NamedTemporaryFile" src/gza/*.py ``` - Are temp files cleaned up after use? - Are temp directories removed?

### Step 10: Assess type safety

Review type hints and type correctness:

1. **Check type hint coverage:** ```bash # Find functions without return type hints grep -n "def.*):$" src/gza/*.py

# Find functions with type hints grep -n "def.*) ->" src/gza/*.py ```

2. **Run mypy (if configured):** ```bash uv run mypy src/gza/ --ignore-missing-imports 2>&1 | head -100 ```

3. **Look for type safety issues:** - Functions with `Any` types that could be more specific - `Optional` types without proper `None` checks - Type: ignore comments (are they justified?) - Inconsistent types (function returns `str | None` but callers don't check)

4. **Check for common type issues:** ```bash # Find potential None issues grep -n "\.get(" src/gza/*.py # dict.get returns Optional grep -n "or None" src/gza/*.py grep -n "if.*is None" src/gza/*.py ```

### Step 11: Analyze component interaction patterns

Understand how modules interact and assess the clarity of these interactions:

1. **Map the import graph:** ```bash grep -h "^from gza" src/gza/*.py | sort | uniq -c | sort -rn grep -h "^import gza" src/gza/*.py | sort | uniq -c | sort -rn ```

2. **Identify the layering:** - Which modules are "lower level" (few dependencies)? - Which are "higher level" (many dependencies)? - Are there circular dependencies?

3. **Check separation of concerns:** - Does `cli.py` only handle CLI concerns, delegating to other modules? - Does `db.py` only handle database concerns? - Does `runner.py` only handle execution concerns?

4. **Look for unclear interfaces:** - Functions with too many parameters - Functions that do too many things - Tight coupling between modules that should be loosely coupled

5. **Document the interaction patterns:** ``` cli.py → db.py (task CRUD) cli.py → runner.py (task execution) runner.py → providers/* (AI execution) runner.py → git.py (git operations) etc. ```

### Step 12: Compile the review report

Create a structured report at `reviews/code-review-full.md`:

```markdown # Gza Code Review - Pre-Release Assessment

Date: YYYY-MM-DD Reviewer: Claude

## Executive Summary

[2-3 sentence overview of codebase health]

## Test Coverage

### Unit Tests

| Module | Test File | Coverage Assessment | |--------|-----------|---------------------| | db.py | test_db.py | Good - covers CRUD, queries | | cli.py | test_cli.py | Partial - missing `gza pr` tests | | ... | ... | ... |

#### Well-Tested Areas - [List modules/features with good coverage]

#### Under-Tested Areas - [List modules/featur

技術詳細

バージョン
1.0.0
ライセンス
MIT
最終更新
2026年8月21日
公開日
2026年8月21日

判断の要約

検証が必要

56
準備完了
レビュー
段階

最近のリポジトリ活動

監査

インストールレビュー

インストールと採用のレビュー

69
要レビュー
セキュリティ
68/100
メンテナンス
100/100
インストール
92/100
完全な監査を開く評価レポートを見る

Agent 実証エビデンス

Agent 実証エビデンス

Resolve、レビュー、インストール、限定実行後の成果レポート。

0
実証済み
Needs first agent run自動インストール: 先にレビュー最新: 不明
成功率
直近の失敗
成果
0
出力品質
失敗
0
非該当
0
インストール数
0
リスクによりブロック
0
設定が必要
0
本番
0

Agent の実行結果はまだありません。最初の実行では /api/agent/outcome を通じて成功、設定要件、リスクによるブロック、失敗、非該当を報告できます。

インストール

Agent ワークフローに追加

無料・オープンソース. 本番 Agent にインストールする前にレポートを確認してください。

成長ループ

共有キット

X

gza-code-review-full 用のシナリオベース草案です。X へ手動投稿できます。

キュレーターノート
gza-code-review-full: Comprehensive pre-release code review assessing test coverage, code duplication, and componen...

11 stars

https://www.openagentskill.com/skills/mhawthorne-gza-code-review-full?ref=x
X 下書きを開く
任意:インストールコマンド付きの返信
Listing + install path for gza-code-review-full:
https://www.openagentskill.com/skills/mhawthorne-gza-code-review-full?ref=x

Install: npx skills add mhawthorne/gza --skill gza-code-review-full
返信の下書きを開く

掲載元

Registry により登録

申請可能

この掲載は公開ソースから登録されており、メンテナー申請が承認されるまで公式として表示されません。

作成者
mhawthorne
インデックス作成者
OpenAgentSkill コミュニティインデックス

帰属は公開リポジトリまたは作成者プロフィールにリンクされています。作成者は掲載を申請して所有権シグナルを更新できます。

このスキルを申請

所有者の申請

このスキル掲載を申請

この Registry により登録 掲載は mhawthorne に帰属していますが、まだ公式として表示されていません。申請すると、確認済み所有者シグナルが追加され、今後の公開、インストール、監査更新の信頼性が高まります。

クリエイター被リンクキット

README にエビデンスバッジを追加

開発者がリポジトリを評価する場所で、正規掲載、現在の信頼・監査シグナル、実際の Agent-Proven エビデンスを表示します。

[![Listed on OpenAgentSkill](https://www.openagentskill.com/api/badge/mhawthorne-gza-code-review-full?metric=listed&label=Listed)](https://www.openagentskill.com/skills/mhawthorne-gza-code-review-full)
[![OpenAgentSkill Trust](https://www.openagentskill.com/api/badge/mhawthorne-gza-code-review-full?metric=trust&label=Trust)](https://www.openagentskill.com/skills/mhawthorne-gza-code-review-full)
[![OpenAgentSkill Audit](https://www.openagentskill.com/api/badge/mhawthorne-gza-code-review-full?metric=audit&label=Audit)](https://www.openagentskill.com/skills/mhawthorne-gza-code-review-full/audit)
[![Agent Proven](https://www.openagentskill.com/api/badge/mhawthorne-gza-code-review-full?metric=proven&label=Agent%20Proven)](https://www.openagentskill.com/skills/mhawthorne-gza-code-review-full)

作者

M

mhawthorne

@mhawthorne

プラットフォーム適合

健全性シグナル

GitHub スター
11
品質スコア
31/100
最終 GitHub プッシュ
2026年8月21日
フレームワークのヒント
不明
OpenAgentSkill 閲覧数
1
インストールコピー数
0
外部クリック
0

コミュニティシグナル

このスキルが Agent ワークフローに役立つかを共有してください。集約されたフィードバックがランキングを改善します。

信頼と安全性

Do not auto-install

50
  • GitHub 採用度GitHub スター 11修正
  • スター/フォーク活動スター 11、フォーク 1; 現在のメタデータでは Issue 活動を利用できません修正
  • 最近のメンテナンス最終プッシュから 1 日合格
  • ライセンスの明確さMIT合格
  • README/SKILL.md の完全性メタデータには十分な利用・ワークフロー文脈があります合格
  • 依存関係/ランタイムのリスクcommand execution surface, credential or environment access修正