Dev & Engineering

Skill Lifecycle Governance Skill

Authoritative skill lifecycle state model to prevent invalid states or transitions.

46/ 100
Use with care

Useful, but reliability, evidence or controls still have material gaps.

See how it was scored ↓
Works as-is in
Codex · Claude Code
Stars
★ 5.2k
Last updated
3d ago
License
Apache-2.0
skill-lifecyclestate-machinegovernancerbac
+4audit-logversioningreview-workflowskill-registry

What does this skill do, and when should you use it?

This skill provides the complete state model for skill containers, versions, review tasks, and visibility overlays, along with all valid state transitions and governance actions (hide, yank, archive). It is based on the SkillHub codebase and design docs, explicitly noting discrepancies between design intent and code (e.g., the hidden flag preferred over an enum state). As a reference-only skill, it performs no operations; it guides agents in modifying publish, review, or unpublish flows to follow the correct state machine and permission boundaries.

The skill defines authoritative enums (SkillStatus, SkillVersionStatus, ReviewTaskStatus, SkillVisibility), lists all valid transitions with triggers (first upload, review approve/reject, withdraw, yank, hide, archive, etc.), specifies the latestVersionId pointer recalculation rules, explains read-model projections (headlineVersion, publishedVersion, etc.) and permission boundaries (who can withdraw, delete, archive, hide, etc.). It also records domain events (SkillPublishedEvent, SkillStatusChangedEvent) and common pitfalls (setting SkillStatus.HIDDEN directly, forgetting to recalc latestVersionId, etc.).

Good fit
  • A developer modifying the publish flow needs to verify that new state transitions conform to the defined legal transition table.
  • A backend engineer adding or changing status fields consults the canonical enum definitions and design notes.
  • An engineer implementing governance actions (hide, yank, archive) checks the correct implementation and permissions.
  • When displaying skill state in search or detail pages, a developer uses the skill to understand which projection to use (publishedVersion, ownerPreviewVersion).
  • A code reviewer validates new state transitions or permission checks against the skill's rules.

How do you install this skill?

Before you use it
  • This skill is a knowledge document only, with no executable code; manual reference to the codebase is required for actual use.
  • Publisher is unverified; independent verification of source and update support is recommended.
  • The skill references internal code and design docs but provides no tests or independent validation; static review cannot confirm accuracy.

This is a documentation-only skill without executable files. To use it, place the .agents/skills/skill-lifecycle folder in your agent's skills directory. If using the SkillHub registry, install via CLI (e.g., skillhub install skill-lifecycle --agent codex).

Generic route: install into Claude Code manually (macOS / Linux)
tmp="$(mktemp -d)"
git clone --depth 1 https://github.com/iflytek/skillhub.git "$tmp"
mkdir -p ~/.claude/skills
cp -R "$tmp/.agents/skills/skill-lifecycle" ~/.claude/skills/
rm -rf "$tmp"

Generated from the source repository and skill path; it copies only this skill's folder. If the author's install steps above differ, follow those first. To scope it to one project, replace ~/.claude/skills with that project's .claude/skills.

How do you use this skill?

Try saying

Once installed, send your agent any of these to trigger it:

  • Consult the skill-lifecycle skill to ensure the new state transitions are valid.

Prompt your agent to reference this skill when modifying skill publish, review, or unpublish flows. For example: 'Consult the skill-lifecycle skill to ensure the new state transitions are valid.' The agent will use the state model and transition tables to validate your code or design.

What are this skill's strengths and limitations?

Pros
  • Provides an authoritative state model, reducing design inconsistencies
  • Explicitly flags design-vs-code discrepancies, guiding new code
  • Detailed transition tables, permission boundaries, and common pitfalls are practical
  • Documentation-only, easy to integrate into any agent workflow
Limitations
  • Specific to SkillHub; not applicable to other registries
  • No executable scripts or tests; reference only
  • Depends on specific class names and docs that may drift from the codebase
  • Does not cover all edge cases (e.g., concurrent publishing)

How does this skill compare with similar options?

Side by side with related skills; every score comes from the same FSRS standard.

Skill FS score Stars Last updated License
Skill Lifecycle Governance Skill this page 46 · Use with care ★ 5.2k 3d ago Apache-2.0
Isaac for Healthcare Workflow Validator ✓ NVIDIA · Official 52 · Use with care ★ 3.5k 3d ago Apache-2.0
Yao Meta Skill 49 · Use with care ★ 2.7k 1mo ago MIT
Gemini Enterprise Skill Registry ✓ Google · Official 43 · Not recommended ★ 21k 3d ago Apache-2.0
Azure Cosmos DB ARM for .NET ✓ Microsoft · Official 54 · Use with care ★ 2.7k 3mo ago MIT

None. The skill is based on SkillHub's internal design and does not mention other similar tools.

How did FollowSkills review this skill?

FollowSkills review · FSRS-2.0
Use with care
46/ 100 5-point scale 2.3 / 5
The upstream repository has new commits since this review. The score still applies to the reviewed revision shown and may not cover the latest changes.
1Trust13 / 25 · 2.6/5

The skill describes permission boundaries and governance actions, but as a knowledge document, it does not execute permissions. It clearly lists who can perform which actions and emphasizes review processes and audit logs, but lacks details on user confirmation or data flow transparency. Deduction for lacking explicit disclosure of data flow and sensitive data handling.

2Reliability5 / 20 · 1.3/5

The document provides clear state transitions and code references, with specific descriptions of key paths (publish, review, withdraw). However, no tests or failure examples are included, and static review cannot verify execution, so deduction.

3Adaptability10 / 15 · 3.3/5

The skill clearly defines trigger conditions and applicable scenarios, but lacks non-fit range boundaries. Environment fit: description does not depend on overseas services, so no deduction.

4Convention10 / 15 · 3.3/5

Documentation is well-structured with state model, transitions, permission boundaries, and common pitfalls, but lacks install/dependency notes, versioning and changelog. Deduction for missing maintenance responsibility and update path.

5Effectiveness5 / 15 · 1.7/5

The skill serves as a reference document that can answer lifecycle-related questions, but direct usability is limited as it provides no concrete outputs or examples. Deduction for unclear deliverable.

6Verifiability3 / 10 · 1.5/5

The skill references specific code files and design docs, but provides no independent verification material or test evidence, so evidence strength is limited.

1 2 3 4 5 6

Open a dimension to read why it scored that way

Reviewed Aug 07, 2026 Reviewed revision 6e133c006e49 Review evidence[1][2][3][4][5][6][7][8]

Evidence confidence:Low — Mostly static review, author material or a limited demo; useful for discovery, not high-risk decisions.

See the full review method →

FAQ

Is this skill portable to other platforms?
It is documentation-only and platform-agnostic, but its content is tailored to SkillHub's architecture. It may be of limited value elsewhere.
Does this skill perform any automated actions?
No, it contains no scripts or executables; it only provides state model guidance.
How can I keep the skill in sync with the latest code?
The skill is derived from SkillHub's docs and code; check the repository regularly for updates.

More skills from this repository

All from iflytek/skillhub

Related skills