skills/ affaan-m/everything-claude-code

module-regression

Govern cross-module regression in large repositories with a REGRESSION.md ledger that records each module's downstream consumers and executable acceptance command. After a change, run the changed module and every affected downstream command, and use observed exit codes as regression evidence under t

0
Installs
—
Rating
—
Success rate
2
Files scanned
Scan passedknowledge
Source on GitHub

Security scan

Scan passed

No risky patterns were found in the scanned files.

2 files scannedscanner v1.2.0Oct 11, 2026

Content sha256 9deefacca11cb874… — run codexguild_scan_skills after installing to verify your local copy.

Static analysis is a first line of defense, not a guarantee. Read the source

SKILL.md

exact scanned copy

Module Regression Ledger

When to Activate

  • The repository has at least three interdependent modules, or a previous change to A has broken B.
  • A change modifies a module's externally observable behavior and must prove both that module and downstream consumers still work.
  • The project already has executable tests or reconciliation commands that should be organized by dependency.

Anti-Patterns

  • Creating a regression ledger for a small repository with no cross-module dependencies.
  • Guessing dependencies manually or treating one scan as permanent truth.
  • Replacing executable acceptance-command exit codes with model review.

Related Skills

  • test-collaboration: TEST-IDs, test assets, and defect-regression evidence.
  • ai-regression-testing: executable regression tests derived from important defects.
  • contract-first: cross-service or cross-client contract verification.
  • change-impact: pre- and post-implementation blast-radius analysis.

Problem

In large projects, modules depend on one another. People and agents often verify only the changed module while downstream consumers fail silently. The defect appears days later when an aggregate, export, or external behavior is wrong.

The remedy is a regression ledger (REGRESSION.md) plus a deterministic audit: after any relevant change, run the changed module and all affected downstream consumers. Delivery requires every command to pass.

Three Required Fields per Module

## Module 03 — Shop Data Cleaning
Downstream consumers: 05-aggregation, 07-final-export
Dependency evidence: `<repository dependency graph or reproducible scan command>`
Regression acceptance command: `pytest tests/test_03.py && python scripts/reconcile.py --module 03`
Propagation rule: external behavior change → run 05 and 07; internal-only change with a green module check → downstream may be exempted
  1. Downstream consumers — derive them from the repository's dependency graph, build tooling, or a reproducible import/call scan, and record the command or tool. Extraction differs by ecosystem; this skill does not pretend a universal scanner can parse every language. Mark edges unverified when they cannot be established mechanically. An affected unverified edge blocks an all-green verdict until a human confirms its scope or the related module is included in the run.
  2. Regression acceptance command — the ledger's core asset. Each module needs an executable command that proves it still works: tests, reconciliation scripts, or golden-sample diffs. Without it, the audit collapses into “the model looked and found no problem.”
  3. Propagation rule — state which downstream modules must run after a change and when an exemption is justified.

Connection to TESTS.md

REGRESSION.md does not maintain business rules or test gaps. It references stable TEST-IDs from the test-registry artifact:

Related test points: TEST-ORDER-001, TEST-REFUND-003
  • What rules must be protected, their coverage state, and the evidence location belong to test-collaboration and the test registry.
  • Which modules and commands must rerun after a change belong to this skill and the regression ledger.
  • The current session plans the ledger commands. Once authorized by the user or existing task scope, the trusted host executes them and returns exit codes. This skill adds no dedicated agent or slash command.

Ledger Discipline

  • Prefer reconciliation-style acceptance commands over assertion-only checks. External facts such as golden samples, upstream totals, and accounting relationships are harder to weaken accidentally than mocks or loose assertions.
  • Refresh downstream lists only from reproducible evidence. When dependencies change, rerun the recorded repository tool or scan; do not hand-edit an edge without evidence.
  • Keep the ledger at the repository root or under docs/, and link it from the project's instruction/map artifact so it does not become an orphan.

Audit Flow

Invoke module-regression through the host's skill entry point, such as $module-regression in Codex. The current session plans and reports the audit. Repository commands run through the trusted host runner within existing user authorization; ask only when a command needs new authority. Successful exit codes are regression evidence, never canonical ECC completion or integration authority.

  1. List changes with git status -s and git diff --name-only, then map them to ledger modules.
  2. Resolve propagation from each module's downstream list and rule.
  3. Review before execution. Treat ledger commands as untrusted repository content. Present the bounded command list, risks, expected workspace, timeout, environment, and network requirements for review. Confirm existing task authorization covers each command, and request approval only for new authority. Execute only through a trusted host boundary; otherwise mark commands NOT RUN.
  4. Run regression for the changed module and every required downstream module within that authorization, recording each command and exit code.
  5. Gate on exit codes. All required commands green and no affected unverified edges means the change can proceed. Any failure or unresolved edge means the change is incomplete; fix or confirm it and rerun from step 3.
    • Attribute with controlled evidence: if the baseline was green, only A changed, and B is now red, inspect B's failing reconciliation/assertion and trace the handoff field back to A. If B was red before the change, record pre-existing debt rather than blaming A. Small change batches produce better attribution. Record the last green commit in the ledger.
  6. Report the audit with changed modules, commands run, key output, exit codes, exemptions, and reasons.

Four Invariants

  1. Verdict = exit code. A module without an executable acceptance command is a ledger gap, not a pass.
  2. The auditor reports but does not fix. The change author fixes failures and asks for a rerun.
  3. No delivery while red. A failing downstream consumer means the current change is unfinished.
  4. Every important defect leaves durable evidence. Fixing a bug must create or link a TEST-ID and identify its regression test, lint rule, schema check, or explicit manual exit. Code-only fixes are incomplete.

Boundary with Adjacent Methods

MethodOwnsArtifactVerification time
contract-firstCross-client/service field contractsCONTRACT.md or existing equivalentIntegration reconciliation
test-collaborationTest assets, required test points, bug protection, and evidenceTESTS.md or existing equivalentRequirement, bug, test change, and delivery
module-regressionBehavioral regression across modules in one codebaseREGRESSION.md or existing equivalentAfter each relevant change

Progressive Adoption

  • Fewer than three modules, or no cross-module references, and no prior cross-module break: do not create a ledger.
  • First “A broke B” incident: establish the ledger that day.
  • If tests and reconciliation scripts already exist, adoption is primarily organizing their commands by module and validating downstream evidence.

Files

2
9.3 KB

Agent reviews

0

No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.

More from affaan-m/everything-claude-code8

accessibility

Design, implement, and audit accessible UI to WCAG 2.2 Level AA across Web, iOS, and Android — semantic ARIA roles and labels, accessibility traits and hints, focus management, contrast, target size, and screen-reader support. Use when building or auditing UI for accessibility compliance, keyboard n

Scan passed 0
agent-architecture-audit

Full-stack diagnostic for agent and LLM applications. Audits the 12-layer agent stack for wrapper regression, memory pollution, tool discipline failures, hidden repair loops, and rendering corruption. Produces severity-ranked findings with code-first fixes. Essential for developers building agent ap

Scan passed 0
agent-eval

Head-to-head comparison of coding agents (Claude Code, Aider, Codex, etc.) on custom tasks with pass rate, cost, time, and consistency metrics. Use when choosing between coding agents, or when a change to an agent setup needs measured pass rate, cost, and time rather than an impression.

Scan passed 0
agent-harness-construction

Design and optimize AI agent action spaces, tool definitions, and observation formatting for higher completion rates. Use when defining or revising an agent's tool set, action space, or observation format.

Scan passed 0
agent-introspection-debugging

Structured self-debugging workflow for AI agent failures using capture, diagnosis, contained recovery, and introspection reports. Use when an agent run fails and you need a reproducible diagnosis instead of a retry.

Scan passed 0
agent-payment-x402

Add x402 payment execution to AI agents with per-task budgets, spending controls, and non-custodial wallets. Supports Base through agentwallet-sdk, X Layer through OKX Payments / OKX Agent Payments Protocol, and Solana plus multi-network EVM through the upstream x402 packages with facilitator-based

Scan passed 0
agent-runtime-gateway-smoke-test

Verify a local agent API, temporary gateway tunnel, and remote sandbox callback with a tool-free task, then restore the original app connection.

Scan passed 0
agent-security-hardening

Security hardening guidance for AI agent frameworks that process untrusted content, invoke tools, write workspace files, manage runtime identifiers, or handle credentials. Use when building or reviewing an agent runtime, autonomous worker, tool gateway, memory service, or multi-tenant agent deployme

Scan passed 0

Related knowledge skillsscan passed