Skip to content
Back to skills

Rex Refactor Hardening Certification 2026 09 28T08 31 26 880Z

ASecurity

Use only after rex-harness selects behavior-preserving hardening and supplies the current Command.

  • 54 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 30, 2026
ai-agents

Works with

  • cli

Security analysis

A100/100

Pro scans all 8 files and shows the line behind each finding

Scanned September 30, 2026

npx -y skills add rexleimo/aios --skill rex-refactor-hardening-certification-2026-09-28T08-31-26-880Z --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Rex Refactor Hardening Certification 2026 09 28T08 31 26 880Z?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Rex Refactor Hardening Certification 2026 09 28T08 31 26 880Z
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/rexleimo-rex-refactor-hardening-certification-2026-09-28t08/badge)](https://www.skillsdirectory.com/skills/rexleimo-rex-refactor-hardening-certification-2026-09-28t08)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: rex-refactor-hardening
description: Use only after rex-harness selects behavior-preserving hardening and supplies the current Command.
---

# Rex Refactor Hardening

仅在 rex-harness 已经根据 `behavior-preserving-hardening` 决定激活本 Capability,
并提供当前 Command 后执行。此路径用于没有诚实 RED 的安全加固、重构或私有边界收紧;
不得把已经通过的测试、Mock 调用或静态推断伪装为 `failing-test-observed`。

**前置**:执行任何步骤前先读 `rex-engineering-standards`(工程质量基线);
加固后的结构必须满足其边界(§1)、深层模块(§2)与文件粒度(§4)要求。

## Baseline

1. 使用稳定的公共入口,在独立、可清理的真实场景环境中运行基线。
2. 环境必须包含与任务相同类型的真实 I/O,例如实际 CLI、临时 home、符号链接、文件账本或网络边界;不直接调用私有 helper 代替场景。
3. 使用 `rex-harness receipt --root <project-root> -- <scenario-command>` 记录精确命令、前置状态、预期、实际结果和执行回执。`baseline-scenario-observed` 必须引用真实零退出的 `receipt:<id>`;基线失败、环境失败或未执行都必须停在当前阶段,不能继续修改。

## Harden

1. 只做实现目标所需的最小加固;复用现有抽象,保持封装和目录归属,不新增 test-only 产品出口。
2. 运行受影响边界的真实场景,确认公开行为保持不变且不安全路径不能绕过新校验。`affected-boundary-scenario-observed` 必须引用真实零退出的 `receipt:<id>`。
3. 不得通过放宽断言、删除用例、跳过测试或仅验证 mock/helper 来获得通过。

## Verify Invariants

1. 审查 diff,确认副作用操作只能在所需校验完成后发生。
2. 审查测试 diff,确认没有弱化用户可观察约束,也没有把内部实现细节作为唯一证明。
3. 返回当前阶段真实、可核验的 Evidence 引用;命令型 Evidence 必须引用宿主或 Rex 记录的执行回执。自然语言、`command:`、旧日志或未执行命令都不是回执。

宿主要求 `AIOS_REX_EVIDENCE` 时,只在结尾输出当前 `activationId` 的恰好一个证据信封,并为每项提交真实引用。当证据不足、场景无法真实执行,或发现任务实际包含新用户可观察行为时,停止并报告当前 Command `blocked`;不要自行切换到 TDD,也不要伪造 RED 或调用下一个 Provider。

### S5 sediment boundary

Hardening 只能沉淀已确认的行为不变量:把 no-op、否定条款、旧 baseline 和 rollback digest 分开记录。发现新的用户可观察目标时返回 `replan-required`;没有新的差异或真实场景时返回 `no-op-recorded`/`blocked`,不得用旧 CI 日志推进。

Files in this skill

  • baseline-skill.md2.8 KB
  • baseline.raw.json24.4 KB
  • baseline.scored.json1.7 KB
  • candidate.raw.json24.1 KB
  • candidate.scored.json1.7 KB
  • state.json1.2 KB
  • tasks.json357 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…