ds-fix

ds-fix is a skill for Claude Code, Codex from sungurerdim/dev-skills. It costs 52 tokens per session (4,519 once invoked), scanned A, original, MIT.

A code-quality cleanup workflow that checks formatting, lint rules, type errors, language-and-region consistency, and exposed secrets. Lint rules are automated checks for common code problems, while a type check verifies that values are used with the right kinds of data.

In plain words
What is it for?
Use it to format code, fix lint or type-check failures, check localization consistency, scan for hardcoded secrets, and audit dependency security warnings.
Why use it?
It gathers several routine checks into one verified pass, helping find inconsistent code, type mistakes, translation issues, and accidentally committed secrets.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one.

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/sungurerdim/dev-skills/ds-fix
Any agent
npx skills add sungurerdim/dev-skills --skill ds-fix
Clone the repo
git clone --depth 1 https://github.com/sungurerdim/dev-skills

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for ds-fix

README.md
[![agentmods](https://agentmods.dev/badge/skills/sungurerdim/dev-skills/ds-fix.svg)](https://agentmods.dev/skills/sungurerdim/dev-skills/ds-fix)
Your own site
<a href="https://agentmods.dev/skills/sungurerdim/dev-skills/ds-fix"><img src="https://agentmods.dev/badge/skills/sungurerdim/dev-skills/ds-fix.svg" alt="Measured on agentmods" height="20"></a>
Per session 52 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 4,519 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00052 $0.04519
Opus 5 $0.00026 $0.02259
Sonnet 5 $0.00010 $0.00904
Haiku 4.5 $0.00005 $0.00452

Measured 2d ago against content hash eb7174dff4dd, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-05, from the pricing page.

Security

Grade A, and why

ds-fix scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Asks for rootlowPrivilege escalation

A mod that escalates privileges can change anything on the machine, not only the project.

| Installable tool missing | Default: install (Trust-Verified — registry-published, non-trivial age), re-run scope; blocked by missing system/sudo perms → `only you can do`, scope `skipped`. `--ask`: show install command

Downgraded: this mod is about security review, or the phrase is quoted, so it is likely naming the pattern rather than instructing it.

ds-fix/SKILL.md · 219 lines

How it starts

The opening of the file, as written. The whole thing — 219 lines — stays where its author put it; the contents beside it link to each section on GitHub.

/ds-fix

AI assistants skip formatting, ignore lint errors, and never run type checks. This skill runs all five passes in order and verifies the result.

Universal Code Quality Fix — format, lint, type-check, l10n, security scan for any stack.

Completion Evidence — applies to every phase: Report done/OK only with the machine-checkable evidence the gates name — the exact command run and its observed output (or file:line diff). Missing evidence → report INCOMPLETE plus what is missing. Self-assessment is never evidence. (This band repeats at file end by design — both copies are normative.)

Triggers

  • User runs /ds-fix, or asks to format code, run linters/fix lint errors, run type checks, scan for secrets, or audit dependencies

Triggers — INVOKE / DON'T INVOKE

INVOKE DON'T INVOKE
"run formatter, linter, type checker", "fix lint errors" "review architecture / patterns" (→ ds-review --strategic)
"scan for hardcoded secrets / dep CVEs" "full regulatory security audit" (→ ds-compliance --security)
"format + l10n consistency check" "generate translations / new locales" (→ manual / external)
"fix all auto-fixable issues across stack" "design a new API" (→ ds-backend)

Contract

Dimensions: B1 (fix), A8 (mechanical), C1 (mechanical)

  • Runs automated fixers in safe order: l10n → format → lint → typecheck → security — mutating scopes first, read-only verification after (typecheck validates the post-fix state), matching the ds-quality gate order (format → lint → type).
  • --preview mode: report only, zero modifications.
  • Missing tools skip with a warning — never fails on absent optional tooling.
  • Re-validates after fix to confirm it worked. Reports counts, not verbose output.
  • Does not perform code review, architecture analysis, or refactoring.
  • Standalone. Uses blueprint profile or ds/audit/findings.md when available; own analysis when absent.
  • Full accounting enforced: every finding and planned check ends in an explicit disposition (fixed / skipped + reason / only you can do); summary totals balance.
  • Pre-existing / out-of-scope errors detected during work are NOT skipped — fixed inline or escalated with concrete blocker.
  • Exempt from state protocol: tool-driven, fast, independent passes — re-running repeats idempotent fixes. No ds/audit/fix.json written.

Read the full file on GitHub · 219 lines

Files

What ships with it

5 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago Changed · -75 lines eb7174dff4dd
  2. 5d ago First seen · 294 lines · 52 tokens per session scan A 61510a3d8385

Subscribe to this mod's changes

ds-fix is a skill published in the GitHub repository sungurerdim/dev-skills (1 stars, last pushed 2d ago), licensed MIT. It adds 52 tokens to every session and 4,519 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 1 finding (asks for root). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

ring:migrating-to-lib-observability

Migrating a Lerian Go app off lib-commons observability imports (deprecated shims or removed APIs) to lib-observability via a fixed mapping table, then bumps go.mod and validates the build; ring:backend-go applies the edits. Covers log/zap/runtime/assert, opentelemetry/tracing, HTTP middleware, context helpers, and…

LerianStudio/ring · 104 tokens

ring:exploring-codebases

Exploring a codebase across phases: scopes the target, detects architecture, components, and layers, deep-dives each discovered perspective, then synthesizes findings into actionable guidance with file:line evidence. Use to understand how a feature or system works before planning changes, or to orient on an unfamiliar…

LerianStudio/ring · 91 tokens

ring:searching-code

Forensic code search and analysis with optional Chain of Draft (CoD) ultra-concise mode. Five-phase methodology (clarification, planning, execution, analysis, synthesis) with severity assessment. Use for targeted investigation of specific patterns, bugs, or vulnerabilities. Skip for broad architecture mapping (use…

LerianStudio/ring · 74 tokens

ring:instrumenting-streaming-events

Instrumenting streaming events: wires lib-streaming event emission end-to-end into a Lerian Go service via a 13-gate cycle (catalog, Builder bootstrap, Emit sites, outbox, HTTP manifest, NoopEmitter fallback, integration and chaos tests), dispatching ring:backend-go under TDD. Consumes the validated…

LerianStudio/ring · 102 tokens

ring:planning-codebase-simplification

Planning a whole-codebase simplification: audits a Go/TS codebase for needless abstraction and emits a KILL/REVIEW/KEEP plan plus a ring:running-dev-cycle task array. Plans only — no edits. Detects single-impl interfaces, pass-through shims, translation-free adapters, and dead-code cascade chains under an inverted…

LerianStudio/ring · 105 tokens

ring:mapping-feature-relationships

Mapping how features relate and phasing the work: categorizing PRD features, grouping them into domains, charting cross-feature journeys, dependencies, and integration points, and defining the binding Phases that plan.md mirrors one-to-one at Gate 7. Gate 2 of ring:planning-large-features; runs after…

LerianStudio/ring · 104 tokens