소스 정보
- 저장소
- dabit3/sonic-agent
- 최근 소스 활동
- 2026년 7월 15일 23:45
- 감지된 SKILL.md 언어
- 영어
- 스타
- 0
- 포크
- 0
설치 방법
기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.
소스 파일 검토
설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.
메뉴
기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.
설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
직접 명령은 검토 Prompt를 거치지 않습니다. 실행하기 전에 소스를 확인하세요.
npx skills add https://github.com/dabit3/sonic-agent --skill sonic-agent-skill-authoring명령은 한 줄로 유지됩니다. 복사하기 전에 가로로 스크롤해 전체 내용을 확인하세요.
로컬 사본을 원하시나요? SkillsMP에서 현재 제공할 수 있는 파일을 다운로드하세요.
SKILL.md 표시 중
| name | sonic-agent-skill-authoring |
| description | Author in-repo SKILL.md: frontmatter, validator, structure. |
| version | 1.0.0 |
| author | Sonic Agent |
| license | MIT |
| platforms | ["linux","macos","windows"] |
| metadata | {"sonic":{"tags":["skills","authoring","sonic-agent","conventions","skill-md"],"related_skills":["writing-plans","requesting-code-review"]}} |
There are two places a SKILL.md can live:
~/.sonic/skills/<maybe-category>/<name>/SKILL.md — personal, not shared. Created via skill_manage(action='create')./home/bb/sonic-agent/skills/<category>/<name>/SKILL.md — committed, shipped with the package. Use write_file + git add. skill_manage(action='create') does NOT target this tree./home/bb/sonic-agent/skills/ (use patch for small edits, write_file for rewrites; skill_manage still works for patch on in-repo skills, but not for create)Source of truth: tools/skill_manager_tool.py::_validate_frontmatter. Hard requirements:
--- as the first bytes (no leading blank line).\n---\n before the body.name field present.description field present, ≤ 1024 chars (MAX_DESCRIPTION_LENGTH).---.Peer-matched shape used by every skill under skills/software-development/:
---
name: my-skill-name # lowercase, hyphens, ≤64 chars (MAX_NAME_LENGTH)
description: Use when <trigger>. <one-line behavior>.
version: 1.0.0
author: Sonic Agent
license: MIT
metadata:
sonic:
tags: [short, descriptive, tags]
related_skills: [other-skill, another-skill]
---
version / author / license / metadata are NOT enforced by the validator, but every peer has them — omit and your skill sticks out.
MAX_SKILL_CONTENT_CHARS, ~36k tokens).software-development/ sit at 8-14k chars. Aim for that range. If you're pushing past 20k, split into references/*.md and reference them from SKILL.md.Every in-repo skill follows roughly:
# <Title>
## Overview
One or two paragraphs: what and why.
## When to Use
- Bulleted triggers
- "Don't use for:" counter-triggers
## <Topic sections specific to the skill>
- Quick-reference tables are common
- Code blocks with exact commands
- Sonic-specific recipes (tests via scripts/run_tests.sh, ui-tui paths, etc.)
## Common Pitfalls
Numbered list of mistakes and their fixes.
## Verification Checklist
- [ ] Checkbox list of post-action verifications
## One-Shot Recipes (optional)
Named scenarios → concrete command sequences.
Not every section is mandatory, but Overview + When to Use + actionable body + pitfalls are the minimum for the skill to feel like a peer.
skills/<category>/<skill-name>/SKILL.md
Categories currently in repo (confirm with ls skills/): autonomous-ai-agents, creative, data-science, devops, dogfood, email, gaming, github, leisure, mcp, media, mlops/*, note-taking, productivity, red-teaming, research, smart-home, social-media, software-development.
Pick the closest existing category. Don't invent new top-level categories casually.
ls skills/<category>/
Read 2-3 peer SKILL.md files to match tone and structure.tools/skill_manager_tool.py if unsure.write_file to skills/<category>/<name>/SKILL.md.import yaml, re, pathlib
content = pathlib.Path("skills/<category>/<name>/SKILL.md").read_text()
assert content.startswith("---")
m = re.search(r'\n---\s*\n', content[3:])
fm = yaml.safe_load(content[3:m.start()+3])
assert "name" in fm and "description" in fm
assert len(fm["description"]) <= 1024
assert len(content) <= 100_000
skill_view / skills_list will not see the new skill until a new session. This is expected, not a bug.metadata.sonic.related_skills unions both trees (skills/ in-repo and ~/.sonic/skills/) at load time. You CAN reference a user-local skill from an in-repo skill, but it won't resolve for other users who clone the repo fresh. Prefer referencing only in-repo skills from in-repo skills. If a frequently-referenced skill lives only in ~/.sonic/skills/, consider promoting it to the repo.
skill_manage(action='patch', name=..., old_string=..., new_string=...) works fine on in-repo skills.write_file the whole SKILL.md. skill_manage(action='edit') also works but requires supplying the full new content.write_file to skills/<category>/<name>/references/<file>.md, templates/<file>, or scripts/<file>. skill_manage(action='write_file') also works and enforces the references/templates/scripts/assets subdir allowlist.Using skill_manage(action='create') for an in-repo skill. It writes to ~/.sonic/skills/, not the repo tree. Use write_file for in-repo creation.
Leading whitespace before ---. The validator checks content.startswith("---"); any leading blank line or BOM fails validation.
Description too generic. Peer descriptions start with "Use when ..." and describe the trigger class, not the one task. "Use when debugging X" > "Debug X".
Forgetting the author/license/metadata block. Not validator-enforced, but every peer has it; omitting makes the skill look half-finished.
Writing a skill that duplicates a peer. Before creating, ls skills/<category>/ and open 2-3 peers. Prefer extending an existing skill to creating a narrow sibling.
Expecting the current session to see the new skill. It won't. The skill loader is initialized at session start. Verify in a fresh session or via skill_view using the exact path.
Linking to skills that don't exist in-repo. related_skills: [some-user-local-skill] works for you but breaks for other clones. Prefer only in-repo links.
skills/<category>/<name>/SKILL.md (not in ~/.sonic/skills/)---, closes with \n---\nname, description, version, author, license, metadata.sonic.{tags, related_skills} all present# Title → ## Overview → ## When to Use → body → ## Common Pitfalls → ## Verification Checklistrelated_skills references resolve in-repo (or are explicitly OK to be user-local)git add skills/<category>/<name>/ && git commit completed on the intended branchDelegate coding to OpenHands CLI (model-agnostic, LiteLLM).
Authorized web application penetration testing — reconnaissance, vulnerability analysis, proof-based exploitation, and professional reporting. Adapts Shannon's "No Exploit, No Report" methodology with hard guardrails for scope, authorization, and aux-client leakage. Active testing against running applications you own or have written authorization to test.
Generate wiki docs + Mermaid diagrams for any codebase.
SOC 직업 분류 기준