Skip to content

External Capability Intake

本手册用于搜罗、评估和分层引入开源 skill 与工程实践,避免“看到一个仓库就直接接进 canonical source”。

如果你已经完成 intake,想继续推进到 approval 和 enablement,继续看 external-capability-approval-and-enablement-workflow.md

使用原则

  • 不把外部仓库整包搬进 canonical source。
  • 只允许“本地化改写适配”,不做 wholesale import。
  • AGPL / 强 copyleft 来源默认只允许 reference-only-runbook,不直接拷文本或代码进正式层。
  • skills/ 只承接公司专属领域能力;开源通用工程能力默认去 skills/docs/runbooks/
  • 目录站、聚合站、awesome list 只能作为 discovery feed,不能直接当 canonical import source。

Intake 卡片

后续所有外部 skill / 工程实践都先登记这张卡片,再决定是否进入正式层:

yaml
source_name:
source_url:
license:
trust_tier:
maintenance_signal:
portability:
overlap_with_existing:
import_mode:
target_layer:
target_name:
why_now:
status:

字段定义

  • trust_tier: A-official / B-proven-community / C-discovery-only
  • portability: codex+claude / claude-first / practice-only
  • import_mode: adapt-into-local-skill / reference-only-runbook / reject
  • target_layer: shared / ecc / company / runbook / toolkit / rules
  • status: candidate / approved / backlog / rejected

当前候选台账

source_namesource_urllicensetrust_tiermaintenance_signalportabilityoverlap_with_existingimport_modetarget_layertarget_namewhy_nowstatus
anthropics/skills:webapp-testinganthropics/skillsApache-2.0 / verify target folder before adaptationA-official65.8k stars;2025-11 仍有 webapp-testing 相关 PR 活跃codex+claude已有 frontend-engineering、前端门禁,但没有独立浏览器 smoke / webapp 测试 skilladapt-into-local-skilleccbrowser-smoke-testing补齐前端与发布链之间的浏览器验证空位approved
nexu-io/open-designnexu-io/open-designApache-2.0B-proven-community30k+ stars;2026-05 仍活跃更新;包含本地 daemon、web UI、31 个 design skills、设计系统库、preview/export 与多 CLI agent adapterscodex+claude已有 frontend-ui-ux-systemfrontend-slidesdesign-systemui-demo,但缺少“Claude Design 类”本地优先设计工作台的受控接入路径reference-only-runbook + full-profile-sidecar-installrunbook + skillsopen-design-integration为 TSP 补齐原型、deck、dashboard、mobile flow、DESIGN.md 和导出 artifact 的外部设计工作台协同能力;full profile 自动准备 ~/.tsp/open-design,但不把上游 daemon 和 Node 24/pnpm 生命周期并入 TSP 默认 npm 依赖approved
alchaincyf/huashu-designalchaincyf/huashu-designCustom / personal use free;企业商用与工具链集成需上游授权B-proven-community4.4k+ stars;2026-04 仍活跃更新;包含独立 SKILL.md、演示与导出工具链practice-only已有 frontend-ui-ux-systemui-ux-promax 与前端门禁,但没有专门面向高保真 HTML 原型、HTML-first deck、时间轴动画与设计评审的外部设计 skill 接入说明reference-only-runbookrunbookhuashu-design-integration在不复制上游内容的前提下,为 TSP 补齐外部设计 skill 接入路径、README 说明与致谢归档;待获得授权后再决定是否升级为本地化适配候选approved
Colin4k1024/andrej-karpathy-skillsColin4k1024/andrej-karpathy-skillsMITB-proven-community轻量仓库,当前核心内容稳定;包含 CLAUDE.mdkarpathy-guidelines skill 形态codex+claude已有 coding-standardstdd-workflowverification-loop,但缺少一层专门约束“先暴露假设、避免过度设计、限定改动边界、先定义成功标准”的行为护栏adapt-into-local-skillecckarpathy-guidelines补齐实现前的行为约束层,让现有质量与验证技能前面多一道“别猜、别做重、别多改、先定义成功”的轻量护栏approved
tanweai/puatanweai/puaMITB-proven-community16k+ stars;2026-04 仍持续更新;多平台技能分发和 Claude hooks 已成型claude-first已有 systematic-debuggingverification-looploop-operator,但没有统一的高能动性、高压闭环与失败升级协议adapt-into-local-skilleccpua补齐“别放弃、别甩锅、别空口完成”的行为层能力,并与现有验证/调试能力互补approved
obra/superpowers:systematic-debuggingobra/superpowersMITB-proven-community20.2k stars;含 Codex 实验支持说明;技能库覆盖调试与验证codex+claude已有 /verify,但缺少根因定位流程adapt-into-local-skilleccsystematic-debugging补强“排查根因”而不只是“反复验证”approved
obra/superpowers:verification-before-completionobra/superpowersMITB-proven-community同上,作为调试/验证配套技能活跃维护codex+claude与现有 /verify 高度重叠reference-only-runbookrunbookverification-playbook更适合作为 /verify 与验证 runbook 的增强项,而不是新入口backlog
obra/superpowers:using-git-worktrees + finishing-a-development-branchobra/superpowersMITB-proven-community技能库包含完整开发分支收口与 worktree 流程codex+claude已有 rules/common/git-workflow.md,但缺少可直接执行的 PR / branch runbookreference-only-runbookrunbookgit-pr-workflow补齐 GitHub / PR / branch 收口工作流approved
omkamal/pypict-claude-skillomkamal/pypict-claude-skillMITB-proven-communityCHANGELOGQUICKSTART、Releases;聚焦单一问题codex+claude已有 QA 测试口径与回写规则,但没有组合测试 / pairwise 设计 skilladapt-into-local-skilleccpairwise-test-design精准补齐测试设计缺口,且可移植性高approved
qodo-ai/pr-agentqodo-ai/pr-agentAGPL-3.0B-proven-community9.8k stars;2025-11 仍有 release 与 GitHub Action 更新practice-only已有 /code-review 与 review specialist,但没有 PR 自动化 playbookreference-only-runbookrunbookai-pr-review-automation可沉淀为 PR 自动 review 方案,但许可证不适合直接本地化成 skillapproved
reviewdog/reviewdogreviewdog/reviewdogMITB-proven-community8.9k stars;2026-01 仍有更新;支持多 CI / 多 reporterpractice-only已有 lint / review 规则,但没有 PR 注释与检查门禁自动化手册reference-only-runbookrunbookreviewdog-pr-gates适合沉淀成 PR gate 与 inline review 实践approved
reviewdog/action-eslintreviewdog/action-eslintMITB-proven-community2026-01 更新;GitHub Marketplace Action;用例清晰practice-only与前端质量门禁互补,但当前没有 GitHub PR review gate 样例reference-only-runbookrunbookreviewdog-pr-gates作为 reviewdog 的具体 GitHub Actions 落地示例approved
semantic-release/release-notes-generatorsemantic-release/release-notes-generatorMITB-proven-community2026-01 更新;发布说明生成插件稳定practice-only已有发布治理 runbook,但没有发布说明自动化方法reference-only-runbookrunbookrelease-notes-automation用于补齐 changelog / release notes 自动化approved
semantic-release/semantic-releasesemantic-release/semantic-releaseMITB-proven-community23k stars;2026-01 仍持续更新practice-only与发布治理 runbook 互补,但当前缺少正式 release automation baselinereference-only-runbookrunbookrelease-notes-automation提供完整 release automation 参考面approved
OpenAPITools/openapi-diffOpenAPITools/openapi-diffApache-2.0B-proven-community1.1k stars;22 releases;2.1.7 latest 2026-01-26codex+claude已有 api-contract 与接口设计 runbook,但没有 OpenAPI breaking change gatereference-only-runbookrunbookapi-breaking-change-gates补齐 API 向后兼容性校验与发布前 breaking change 检查approved
stoplightio/spectralstoplightio/spectralApache-2.0B-proven-community3.1k stars;107 releases;v6.15.0 latest 2025-04-22codex+claude已有接口设计 runbook 与 api-contract,但没有 API lint / ruleset gatereference-only-runbookrunbookapi-lint-gates补齐 OpenAPI / AsyncAPI 风格与规范门禁approved
testcontainers/testcontainers-javatestcontainers/testcontainers-javaMITB-proven-community8.6k stars;91 releases;2.0.4 latest 2026-03-19codex+claude已有 maven-qajava-unit-test,但没有容器化集成测试工作流adapt-into-local-skillecctestcontainers-integration-testing补齐 Java 服务对数据库、中间件和浏览器依赖的可重复集成验证approved
actions/dependency-review-actionactions/dependency-review-actionMITA-official799 stars;56 releases;4.9.0 latest 2026-03-03practice-only已有 security / review 规则,但没有依赖变更与许可证门禁手册reference-only-runbookrunbookdependency-review-gates补齐 PR 级依赖漏洞与许可证变化检查approved
github/codeql-actiongithub/codeql-actionMIT / CodeQL CLI 附加使用条件A-official1.5k stars;v4.31.10 latest 2026-01-12practice-only已有安全评审与 review 规则,但没有 PR 级静态安全扫描接入手册reference-only-runbookrunbookcodeql-pr-security-gates可补齐 GitHub 原生代码扫描与安全查询门禁approved
aquasecurity/trivy-actionaquasecurity/trivy-actionMITB-proven-community1.4k stars;v0.33.1 latest 2025-09-03practice-only已有 dependency review 与 CodeQL,但没有镜像 / 文件系统 / IaC 扫描接入手册reference-only-runbookrunbooktrivy-security-gates可补齐容器镜像、文件系统和 IaC 的漏洞扫描与门禁实践approved
ossf/scorecard-actionossf/scorecard-actionApache-2.0B-proven-community348 stars;v2.4.3 latest 2025-09-30practice-only已有依赖、代码和制品扫描入口,但没有仓库级供应链基线手册reference-only-runbookrunbookscorecard-supply-chain-gates可补齐仓库级供应链基线、发布流程与 token 使用面的审计实践approved
anchore/sbom-actionanchore/sbom-actionApache-2.0B-proven-community209 stars;v0.20.9 latest 2025-10-23practice-only已有 dependency review 与镜像扫描,但没有 SBOM 生成与发布实践手册reference-only-runbookrunbooksbom-generation-gates可补齐构建产物与镜像的 SBOM 生成、归档与发布链追溯approved
actions/attest-build-provenanceactions/attest-build-provenanceMITA-official847 stars;v3.0.0 latest 2025-08-28practice-only已有 SBOM 和供应链基线入口,但没有 provenance attestation 手册reference-only-runbookrunbookartifact-attestation-gates可补齐构建产物 provenance 与发布证明链实践approved
sigstore/cosign-installersigstore/cosign-installerApache-2.0B-proven-community175 stars;v4.0.0 latest 2025-10-16practice-only已有 SBOM 与 provenance 入口,但没有签名与验证手册reference-only-runbookrunbookcosign-signing-gates可补齐 artifact / image signing 与验证链实践approved
slsa-framework/slsa-verifierslsa-framework/slsa-verifierApache-2.0B-proven-community394 stars;v2.7.1 latest 2025-07-18practice-only已有 attestation 与签名入口,但没有统一的 provenance 验证手册reference-only-runbookrunbookslsa-verification-gates可补齐 provenance / attestation 的独立验证实践approved
sigstore/policy-controllersigstore/policy-controllerApache-2.0B-proven-community1k+ stars;v0.13.1 latest 2025-09-17practice-only已有签名与验证入口,但没有集群侧策略强制手册reference-only-runbookrunbookpolicy-controller-gates可补齐 Kubernetes / admission 层的签名与验证策略执行实践approved
pact-foundation/pact-jvmpact-foundation/pact-jvmApache-2.0B-proven-community1.1k stars;331 releases;4.7.0-beta.4 latest 2026-02-18codex+claude已有 api-contract,但没有 consumer/provider contract testing 工作流reference-only-runbookrunbookcontract-testing-playbook可补齐跨服务 consumer/provider 契约验证,但接入成本高于普通 API lint / diff gateapproved
slsa-framework/slsa-github-generatorslsa-framework/slsa-github-generatorApache-2.0B-proven-community169 stars;v2.1.0 latest 2026-02-24;2025-10 仍有更新practice-only已有 GitHub 官方 attestation,但没有更广的 SLSA provenance 生成模式手册reference-only-runbookrunbookslsa-generator-patterns可补齐 GitHub Actions 侧更通用的 provenance 生成设计模式approved
in-toto/attestationin-toto/attestationApache-2.0B-proven-community317 stars;v1.1.2 latest 2025-06-14;2025-11 仍有更新practice-only已有 attestation 生成与验证手册,但缺少 attestation predicate / schema 设计参考reference-only-runbookrunbookin-toto-attestation-framework可补齐 attestation schema、predicate 和证据模型的设计参考approved
in-toto/witnessin-toto/witnessApache-2.0B-proven-community503 stars;v0.10.1 latest 2025-10-15;2025-11 仍有更新practice-only已有 attestation / signing / verification,但没有 policy-engine 视角的高级治理手册reference-only-runbookrunbookwitness-policy-gates可补齐基于证据和策略引擎的更高级供应链治理实践approved
renovatebot/renovaterenovatebot/renovateAGPL-3.0B-proven-community20.5k stars;42.76.4 latest 2026-01-10;持续高频发布practice-only已有依赖门禁,但缺少持续升级发现、批量 triage 和自动化分组手册reference-only-runbookrunbookdependency-update-automation可补齐依赖升级自动化与分批治理实践,但许可证不适合直接本地化成 skillapproved
gitleaks/gitleaksgitleaks/gitleaksMITB-proven-community24k stars;v8.30.0 latest 2025-11-26;规则持续更新practice-only已有依赖、代码、镜像与供应链门禁,但没有 secret scanning 手册reference-only-runbookrunbooksecret-scanning-gates可补齐 PR / 仓库级硬编码凭据发现、baseline 管理与泄漏处置实践approved
step-security/harden-runnerstep-security/harden-runnerApache-2.0B-proven-communityv2.14.0 latest 2025-12-09;持续维护 GitHub Actions runtime hardeningpractice-only已有仓库级供应链基线,但没有 runner 运行时 egress hardening 手册reference-only-runbookrunbookrunner-egress-hardening可补齐 GitHub Actions runner 的出站访问控制、实时监测与异常 triage 实践approved
rhysd/actionlintrhysd/actionlintMITB-proven-communityv1.7.8 latest 2025-10-11;持续跟进 GitHub Actions 语法、runner label 与 popular actions 数据practice-only已有仓库级供应链基线,但没有 workflow 语法、结构与 shell 误用门禁手册reference-only-runbookrunbookactionlint-workflow-gates可补齐 GitHub Actions workflow 文件级静态 lint 与结构化 triage 实践approved
zizmorcore/zizmorzizmorcore/zizmorMITB-proven-community3.3k stars;2025-11 仍保持活跃更新;配套 zizmor-action 持续维护practice-only已有 Scorecard 和 runner hardening,但没有 workflow 安全审计手册reference-only-runbookrunbookzizmor-workflow-audits可补齐 GitHub Actions workflow 的安全审计、triage 和 review 回写实践approved
open-policy-agent/conftestopen-policy-agent/conftestApache-2.0B-proven-community3.1k stars;92 releases;v0.66.0 latest 2025-12-22practice-only已有 Trivy 和 policy-controller,但没有 PR / 发布前的 policy-as-code 预检手册reference-only-runbookrunbookconftest-policy-gates可补齐 Helm / Kubernetes / Terraform / YAML / JSON 的配置策略预检实践approved
bridgecrewio/checkovbridgecrewio/checkovApache-2.0B-proven-community2026-03 仍持续发布;框架覆盖 Terraform、Kubernetes、Helm、CloudFormation、Dockerfile 等 IaC 目标practice-only已有 Trivy 和 Conftest,但没有 IaC 安全与合规基线门禁手册reference-only-runbookrunbookcheckov-iac-gates可补齐 Terraform / Kubernetes / Helm / CloudFormation 等 IaC 的误配置与合规预检实践approved
yannh/kubeconformyannh/kubeconformApache-2.0B-proven-community2026-02 仍持续发布;配套 kubernetes-json-schema 仓库持续维护practice-only已有 Conftest 和 policy-controller,但没有 Kubernetes manifest schema 校验手册reference-only-runbookrunbookkubeconform-schema-gates可补齐 Kubernetes / Helm / kustomize 输出的 schema 级校验与 CRD 覆盖实践approved
GitHubSecurityLab/actions-permissionsGitHubSecurityLab/actions-permissionsMITB-proven-communityPUBLIC BETA;围绕 Monitor / Advisor 持续维护 GitHub token permissions 收敛实践practice-only已有 Scorecard、Zizmor 和 runner hardening,但没有基于真实运行的 token 最小权限手册reference-only-runbookrunbookgithub-token-permissions-baseline可补齐 GitHub Actions GITHUB_TOKEN 最小权限建议、收敛与 triage 实践approved
kyverno/kyvernokyverno/kyvernoApache-2.0B-proven-community2026-03 官方文档与 releases 持续更新;覆盖 admission、background scan、policy reports、image verificationpractice-only已有 Conftest、policy-controller,但没有 Kubernetes 原生 policy engine 手册reference-only-runbookrunbookkyverno-policy-gates可补齐 Kubernetes 原生策略治理、background scan 与 policy report 实践approved
helm-unittest/helm-unittesthelm-unittest/helm-unittestMITB-proven-community2026-03 仓库和插件文档持续维护;聚焦 Helm chart 单元测试与 snapshot 回归practice-only已有 Kubeconform 和 Conftest,但没有 Helm chart 模板单测手册reference-only-runbookrunbookhelm-unittest-playbook可补齐 Helm chart 模板渲染断言、snapshot 回归与 values 组合测试实践approved
Kubernetes Docs: kubectl server-side dry-runkubectl applyCC BY 4.0 docs / Kubernetes project materialsA-official2026-03 官方文档持续维护;server-side apply / dry-run=server 是长期稳定能力practice-only已有 Kubeconform、Conftest,但没有 API server 接受性预检手册reference-only-runbookrunbookkubectl-server-dry-run-gates可补齐 manifest 渲染后、正式 apply 前的 API server 接受性与字段冲突预检实践approved
safishamsi/graphifysafishamsi/graphifyMITB-proven-community2026-04 社区活跃;v4 文档包含架构、CLI 与 Python 依赖说明codex+claude已有 /team-* 主链与 workflow-engine,但缺少可复用的知识图谱结构分析能力adapt-into-local-skillrunbook + skillsgraphify-knowledge-graph为 brownfield 认知、架构问答、依赖路径分析补结构化证据层approved
abhigyanpatwari/GitNexusabhigyanpatwari/GitNexusPolyForm-Noncommercial-1.0.0B-proven-community2026-04 仍有 release;npm 包 1.6.3;README/ARCHITECTURE 覆盖 CLI、MCP、impact、detect_changes 与多仓模式codex+claude与 Graphify 同属代码图谱能力,但 GitNexus 更偏 MCP 查询、symbol impact、git diff impact 和多仓证据reference-only-runbookrunbook + skillsgitnexus-code-intelligence为复杂 brownfield 改造补齐 MCP-backed impact/detect_changes 证据;因非商业许可证和 Node 20 要求,不内置依赖approved
skillcreatorai/Ai-Agent-Skillsskillcreatorai/Ai-Agent-SkillsMITC-discovery-only443 stars;支持 Claude / Codex / Copilot / Gemini 等多代理安装codex+claude与本仓库的安装面相关,但更适合作为发现与对标来源rejectrunbookdiscovery-feed-only可继续发现候选 skill,不作为直接导入源rejected
VoltAgent/awesome-claude-skillsVoltAgent/awesome-claude-skillsMITC-discovery-only聚合官方与社区技能,适合持续检索候选practice-only不提供稳定单项事实源rejectrunbookdiscovery-feed-only只保留为 awesome list 型发现源rejected
letta-ai/skillsletta-ai/skillsMITC-discovery-only社区知识库型仓库;体量小但结构清晰;包含 webapp-testing 等条目codex+claude与本仓库的 skill 形态兼容,但当前信号更适合作为次级发现源rejectrunbookdiscovery-feed-only用来发现可评估主题,不直接当 canonical import sourcerejected

首批批准实施的 3 项

先锁定这 3 项做本地化试点,避免一次引入过多:

target_nametarget_layerupstream为什么现在做
systematic-debuggingeccobra/superpowers当前平台能验证,但缺少系统化根因定位流程
browser-smoke-testingeccanthropics/skills:webapp-testing当前平台有前端治理,没有独立浏览器 smoke skill
pairwise-test-designeccomkamal/pypict-claude-skill当前平台有测试策略,没有组合测试设计入口

当前进展:

下一批待补充候选

这一批 3 项已经完成,本轮先不预设新的默认候选;后续若继续搜罗,再按本台账 intake 合同补录。

下一轮实施默认边界

下一轮若实施以上 approved 项,默认遵循这些边界:

  • 只吸收方法论、流程和结构,不直接复制外部仓库整体目录。
  • 先落 skills/ 本地化版本,再决定是否补 rules/runbooks/ 或 specialist 文案。
  • 不改 roles/*/role.yaml/team-* 命令,除非本地化 skill 已成型并通过校验。
  • 若上游后续许可证、维护状态或内容方向变化,重新走本台账更新状态。

Released under the MIT License.