Creator · rstackjs
Last updated · Sep 7, 2026
Audit and modernize RstackJS/Rspack ecosystem repositories against current infrastructure baselines. Choose between the Rsbuild-style Rstack CLI monorepo lane and the standalone Rslib/Rslint/Rstest package lane; maintain package.json metadata, exports, dependency placement and ve
Sandbox only
Install targets
Codex install prompt
Install the "rstack-repo-maintain" agent skill from https://github.com/rstackjs/agent-skills/tree/main/.agents/skills/rstack-repo-maintain. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Audit and modernize RstackJS/Rspack ecosystem repositories against current infrastructure baselines. Choose between the Rsbuild-style Rstack CLI monorepo lane and the standalone Rslib/Rslint/Rstest package lane; maintain package.json metadata, exports, dependency placement and version freshness; align ESM or dual output, Node/pnpm/TypeScript versions, formatter, CI action pins, release validation, docs, dependencies, and infra PR conventions. Use when updating rstackjs repositories, refreshing infrastructure or package manifest baselines, copying patterns from Rsbuild or maintained exemplars, or reviewing package and tooling consistency. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"rstackjs-rstack-repo-maintain","task":"Install rstack-repo-maintain","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.
Scenario
GitHub automation
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Agent fit
Claude Code + Browser agents + CLI
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add rstackjs/agent-skills --skill rstack-repo-maintain
Maintenance
fresh
4d since push
Risk
Needs review
Dependency or permission surface needs review
GitHub quality
93
67/100 Quality · 72/100 Trust
Coverage tags
Review notes
Dependency or permission surface needs review · Permission surface may require sandboxing
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
PromisingUseful candidate, but compare it with alternatives before adopting.
Trust
Sandbox onlyUseful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Run only in a sandbox and compare close alternatives before using it for real work.
Stars
93 GitHub stars
Repo activity
93 stars, 4 forks
Maintenance
4d since push
License
MIT
Install
npx skills add rstackjs/agent-skills --skill rstack-repo-maintain
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add rstackjs/agent-skills --skill rstack-repo-maintainDo not use when
Agent safety v2
Sparse or mixed signals. Useful for discovery, but not for autonomous installation.
Test manually in an isolated workspace and compare against safer alternatives.
high
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Skill may drive a browser or interact with web pages.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20rstack-repo-maintain%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20rstack-repo-maintain%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/rstackjs-rstack-repo-maintain/install
Agent should check
Copy prompt
Task: Use rstack-repo-maintain in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20rstack-repo-maintain%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/rstackjs-rstack-repo-maintain/install
Install command: npx skills add rstackjs/agent-skills --skill rstack-repo-maintain
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/rstackjs-rstack-repo-maintain/install
LLM text format
/api/skills/rstackjs-rstack-repo-maintain/install?format=text
Find alternatives
/api/skills/search?q=rstack-repo-maintain&limit=3
Agent prompt
Use rstack-repo-maintain for this task. Review https://www.openagentskill.com/api/skills/rstackjs-rstack-repo-maintain/install, then install with: npx skills add rstackjs/agent-skills --skill rstack-repo-maintainRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/rstackjs-rstack-repo-maintain
LLM text
/api/registry/manifest/rstackjs-rstack-repo-maintain?format=text
Install alias
/api/registry/install/rstackjs-rstack-repo-maintain
Recommend
/api/registry/recommend?task=Use%20rstack-repo-maintain%20in%20an%20agent%20workflow&limit=3
Agent fit
GitHub automation
Use-case tags
Platforms
Claude Code, Browser agents
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Prototype with this skill first; keep a fallback candidate ready.
Role in stack
Fallback candidate
Primary fit
GitHub automation
Trust label
Prototype first
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
GitHub adoption
CHECK93 GitHub stars
Stars/forks activity
CHECK93 stars, 4 forks; issue activity unavailable in current metadata
Recent maintenance
PASS4d since push
License clarity
PASSMIT
Good signals
Review before install
Recommended action
Run only in a sandbox and compare close alternatives before using it for real work.
Quality profile
Useful candidate, but compare it with alternatives before adopting.
Workflow fit
Manage repositories
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Operate web apps
I need my agent to control a browser, fill forms, and verify web app workflows.
Verify behavior
I need my agent to test a web app, reproduce bugs, and verify fixes.
Workflow fit
Operate and verify web apps
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Inspect, patch, and verify code
A workflow for software agents that inspect repositories, review pull requests, generate tests, and turn findings into shippable patches.
Turn skills into distribution
A workflow for turning newly indexed skills into SEO briefs, social drafts, comparison pages, and reusable publishing workflows.
Alternative shortlist
Similar skills that may fit this task.
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
Infisical is the open-source platform for secrets, certificates, and privileged access management.
--- name: rstack-repo-maintain description: 'Audit and modernize RstackJS/Rspack ecosystem repositories against current infrastructure baselines. Choose between the Rsbuild-style Rstack CLI monorepo lane and the standalone Rslib/Rslint/Rstest package lane; maintain package.json metadata, exports, dependency placement and version freshness; align ESM or dual output, Node/pnpm/TypeScript versions, formatter, CI action pins, release validation, docs, dependencies, and infra PR conventions. Use when updating rstackjs repositories, refreshing infrastructure or package manifest baselines, copying patterns from Rsbuild or maintained exemplars, or reviewing package and tooling consistency.' metadata: internal: true ---
<!-- cspell:words oxfmt -->
# Rstack Repo Maintain
## Overview
Modernize RstackJS repositories without blindly copying config. Use the target's compatibility surface plus current exemplar repositories to make small, verifiable infrastructure upgrades.
## Baseline Evidence
Read `references/repo-baselines.md` when choosing a template repo, explaining where the baseline came from, or deciding between pure ESM and dual output, standalone tools and Rstack CLI, runtime floors, TypeScript majors, formatters, package validation, or CI patterns.
Read `references/package-json-baseline.md` when auditing or changing `package.json`, checking whether dependencies are current, choosing an `@rsbuild/core` peer range, or validating published package contents.
Default starting points:
- Large monorepo and integrated-tooling baseline: `web-infra-dev/rsbuild`. Use its Rstack CLI, pnpm catalog, supply-chain, `oxfmt`, and CI patterns selectively; do not treat it as a drop-in small-package template. - Primary standalone small-package baseline: `rstackjs/rslog`. - Pure ESM and Node 20 plugin package baseline: `rstackjs/rsbuild-plugin-publint`. - Concise AGENTS.md and publint reference: `rstackjs/rslog`, after checking that its prose still matches its configs. - Additional package validation reference: `rstackjs/rsbuild-plugin-arethetypeswrong`. - Generated-artifact CLI reference: `rstackjs/prebundle`. - Dual-package compatibility reference: `rstackjs/rsbuild-plugin-virtual-module`.
Always re-check the target repo and exemplar repo before editing. The reference file is a dated snapshot, not a permanent source of truth.
## Workflow
1. **Inventory the target repo** - Read `package.json`, lockfile, `pnpm-workspace.yaml`, `.node-version`, `.rstack/**`, `rstack.config.*`, `rslib.config.*`, `rslint.config.*`, `rstest.config.*`, `vitest.config.*`, `jest.config.*`, `playwright.config.*`, `tsconfig*.json`, `.github/workflows/*`, `README.md`, `AGENTS.md`, release config, and source entry points. - Identify package kind: library, Rsbuild/Rspack plugin, CLI, app template, test fixture, or docs package. - List current build, lint, typecheck, test, release, and package manager commands before changing them. - For published packages, map `files`, `bin`, `types`, and every `exports` target to the source or generated artifact that provides it.
2. **Choose the migration target** - Use the standalone lane for focused packages that are already clear with direct Rslib, Rslint, and Rstest configs. - Consider the Rstack CLI lane for multi-package repositories that benefit from shared build/test config, unified type-aware linting, staged-file handling, and hook setup. Require each migrated command to have an equivalent Rstack CLI path; do not add the CLI merely to match Rsbuild. - Prefer pure ESM for modern libraries and plugins when consumers can support it. - Use dual package output only as a deliberate transition when existing CommonJS consumers or public exports require it. - Treat runtime support, package exports, CLI bins, side effects, and documented deep imports as compatibility constraints.
3. **Update the infrastructure in small layers** - **Package manifest**: follow `references/package-json-baseline.md`. Select the matching core/CLI, plugin, or library profile; check metadata and published entry points; separate npm release freshness from compatibility ranges; and update the manifest and lockfile together. Use `@rsbuild/core` as live evidence, not as a field-for-field template for every package. - **Build tooling**: in the standalone lane, use Rslib, keep config minimal, set appropriate `lib.syntax`, emit declarations, and align `package.json#exports` with real output. In the integrated lane, use `rstack.config.ts`, `define.lib`, and shared `rstack/lib` config only when that reduces duplicated configuration. Add `rsbuild-plugin-publint` when the package should validate publish metadata during build. When upgrading `@rslib/core` from 0.x to `1.0.0-beta` or another v1 prerelease, follow the official [Rslib v0-to-v1 upgrade guide](https://v1.rslib.rs/zh/guide/upgrade/v0-to-v1) and audit every listed breaking default instead of treating it as a routine dependency bump. - **Linting**: in the standalone lane, use `@rslint/core` and `ts.configs.recommended`; add `js.configs.recommended` only when JavaScript source or config files are intentionally linted. In the integrated lane, use the repository's supported `rs lint` command and preserve type-check coverage. - **Formatting**: preserve the repository's formatter unless the migration explicitly includes formatter replacement. Current Rsbuild uses `oxfmt`, while maintained standalone packages may use Prettier or dprint. Keep generated artifacts and lock files ignored where appropriate. - **Test tooling**: prefer Rstest for JavaScript/TypeScript unit tests in Rstack repositories. When a repo still uses Vitest or Jest, use the `migrate-to-rstest` skill, map scripts and configs to `@rstest/core`, keep Playwright or other browser E2E tooling separate, and remove legacy runner deps/configs only after the migrated scope is green. - **Runtime and package manager**: verify Node support from code, dependencies, package `engines`, `.node-version`, CI, and release workflows. Update `packageManager`, pnpm engine constraints, lockfile, and CI together. Do not copy Rsbuild's Node 22 minimum into a Node 20-compatible package without a concrete runtime reason. - **pnpm policy**: for monorepos, consider catalogs, `catalogMode`, unused-catalog cleanup, peer-install policy, build-script allowlists, `minimumReleaseAge`, and strict dependency-build settings. Adopt each option only after checking install behavior, native dependencies, trusted release exceptions, and the repository's pnpm version. - **GitHub Actions**: keep `.github/workflows/*` aligned with the chosen baseline repo. Pin third-party actions to commit hashes, not floating tags, and update action pins by copying or refreshing the baseline pattern instead of inventing new pins. - **TypeScript**: choose the major supported by the target toolchain instead of applying one global version. Remove stale compiler options, prefer `target: "ES2023"` for compatible Node packages, and keep module resolution consistent with runtime output. For TypeScript 7 packages, remove the old direct `@typescript/native-preview` dependency and manual tsgo selection from Rslib config. Current Rslib automatically uses tsgo when the installed TypeScript version is 7 or later, so keep declaration generation enabled and validate emitted declarations without adding preview-specific wiring. - **Docs**: keep `README.md` focused on purpose, install, usage, options, supported runtimes, release/license links. Add a concise `AGENTS.md` in the rsbuild-style shape: Stack, Commands, Project structure, and Code style. - **Dependency cleanup**: run a repo-appropriate unused dependency check such as Knip when feasible, then remove only dependencies proven unused or misplaced. Do not add Knip as a dependency unless the repo starts using it in scripts; treat `pnpm stage` and intentional legacy tsgo tool dependencies as known false positives when applicable.
4. **Preserve behavior while modernizing** - Do not touch business logic unless the infra change requires it. - Keep compatibility breaks explicit in commit/PR notes: ESM-only output, removed exports, changed CLI behavior, or dependency placement changes. - If a repo needs multiple risky changes, split them into reviewable PR-sized batches.
5. **Prepare the infra PR** - Create the infrastructure update branch from the latest `origin/main` unless the user asks for a different base. - Use a specific PR title starting with `chore(infra):`, for example `chore(infra): adopt Rstack CLI and package validation` or `chore(infra): align build and lint tooling`. - Keep each tool update or tool configuration as its own commit unit. Use commit titles such as `chore(deps): update rslint`, `chore(infra/build): align declaration output`, or `chore(infra/ci): pin workflow actions`. - Do not mix unrelated tool changes, generated lockfile updates, and source fixes in a single commit unless the tool update requires them to stay atomic.
6. **Validate before cleanup** - Run install with the repo package manager. - Run lint, format check, typecheck if present, build, and tests. - For pnpm packages, prefer `pnpm pack --dry-run` when the repository's pnpm version supports it. Otherwise, use `pnpm pack --pack-destination <temporary-directory>` and remove the temporary archive after inspection; use `npm pack` only when npm is the target repository's package manager. Skip the separate pack command only when package inclusion rules have been inspected, every published entry is provably included, and an enforcing `pluginPublint` in `rslib.config.ts` has completed in a successful non-watch build. Do not take this shortcut when inclusion is uncertain, the plugin is disabled, conditional activation was not satisfied, `throwOn: 'never'` is set, only a watch build ran, or the task explicitly requires tarball inspection. Never run `pnpm pack` without `--dry-run`, `--pack-destination`, or another explicit output path in the target working tree because it writes a `.tgz` there. - Smoke test import/CLI paths that changed. - When migrating to Rstack CLI, compare generated package artifacts and test discovery with the pre-migration commands. - Remove obsolete configs and dependencies only after the new path is green.
## Output
When reporting back, include:
- Target baseline and why it was chosen. - Files changed, grouped by build/lint/TypeScript/CI/docs/dependencies. - Breaking changes or compatibility risks. - Commands run and their result. - Any deliberate deviations from the Rstack baseline.
Source provenance
Decision snapshot
recent repository activity
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for rstack-repo-maintain, ready for a manual X post.
A practical pick for source-backed research: rstack-repo-maintain: Audit and modernize RstackJS/Rspack ecosystem repositories against current infrastructure baselines. Choose between the Rsb... 93 stars https://www.openagentskill.com/skills/rstackjs-rstack-repo-maintain?ref=x
Listing + install path for rstack-repo-maintain: https://www.openagentskill.com/skills/rstackjs-rstack-repo-maintain?ref=x Install: npx skills add rstackjs/agent-skills --skill rstack-repo-maintain
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to rstackjs but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/rstackjs-rstack-repo-maintain?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/rstackjs-rstack-repo-maintain?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/rstackjs-rstack-repo-maintain/audit)
[](https://www.openagentskill.com/skills/rstackjs-rstack-repo-maintain?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)rstackjs
@rstackjs
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Sandbox only
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16.3K StarsMaigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
32.9K StarsNuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29.2K StarsInfisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
27.4K StarsPermission surface
shell or command execution, filesystem or document access
Agent outcomes
No agent outcome data yet
Docs
Strong README/SKILL.md context
Risk summary
Install readiness