Token导航 LogoToken导航TokenDH.com
研究检索需要联网github未标认证来源可访问许可证需确认审计通过

safe-ts安全 ts

Agent Skill

safe-ts 用于查找、检索和筛选相关信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

489

周安装

21

GitHub Stars

公开资料未说明

下载量

171
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:safe-ts(安全 ts)
来源仓库:https://github.com/thedumptruck/skills
仓库路径:skills/safe-ts
安装命令:
npx skills add https://github.com/thedumptruck/skills --skill safe-ts
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/thedumptruck/skills --skill safe-ts

简介

查找、检索和筛选相关信息。适用宿主包括 Codex、Claude、Cursor、Gemini CLI,接入前应确认版本、权限和运行环境要求。

  • 根据关键词或任务场景快速定位候选结果。
  • 适合需要信息聚合时使用。safe-ts 属于研究检索类 Skill,可作为该场景下的辅助能力补充。
  • 可结合来源仓库进一步核验具体用法。
  • 安装前建议确认权限范围和维护状态。

SKILL.md

Safe TypeScript

Build highly predictable, robust, and performant TypeScript/Node.js applications with a "zero technical debt" policy.

Retrieval-First Development

Always verify standards against the reference documentation before implementing.

ResourceURL / Path
Safety & Control Flow./references/safety.md
Performance Patterns./references/performance.md
Developer Experience./references/dx.md

Review the relevant documentation when writing new logic or performing code reviews.

When to Use

  • Writing new TypeScript logic from scratch
  • Refactoring existing TS/JS code to improve safety, performance, or memory stability
  • Reviewing PRs for code quality and strict compiler standard adherence
  • Optimizing memory allocations or V8 hot paths (e.g., GC pause mitigation)
  • Implementing strict error handling without throw / try-catch

Reference Documentation

  • ./references/safety.md - Control flow limits, bounded Promises, assertions, Result types
  • ./references/performance.md - Object pools, TypedArrays, monomorphic shapes
  • ./references/dx.md - Naming conventions, options structs, strict compiler flags, zero dependencies

Search: no recursion, AbortSignal, ObjectPool, Result<T,E>, noUncheckedIndexedAccess, Zod

Core Principles

Apply Safe TypeScript For

NeedExample
Predictable ExecutionBounded for loops, bounded Promises via AbortSignal.timeout()
Memory StabilityPre-allocating arrays/pools at startup, Uint8Array, in-place object mutation
Operational ReliabilityReturning explicit Result<T, E> types, never throwing operational errors
MaintainabilityMaximum 70 lines per function, max 100 columns per line, options interfaces

Do NOT Use

  • Unbounded while(true) loops or Promises without timeouts
  • Dynamic memory allocations (new Object(), [], {}) inside hot paths (triggers GC pauses)
  • Unchecked array indices or implicit any types
  • Expected control flow via throw and catch (Exceptions are for bugs/panics *only*)
  • Proxy, Reflect, or runtime decorator magic

Quick Reference

Bounded Asynchronous Pattern (No Leaked Promises)

// Always bound asynchronous operations with a timeout
async function fetchWithBounds(url: string, timeoutMs: number): Promise<Result<Response, Error>> {
    const controller = new AbortController();
    const timeoutId = setTimeout(() => controller.abort(new Error("Timeout")), timeoutMs);

    try {
        const res = await fetch(url, { signal: controller.signal });
        if (!res.ok) return { ok: false, error: new Error(`HTTP ${res.status}`) };
        return { ok: true, value: res };
    } catch (err) {
        // Only catch native exceptions/abort errors to wrap them into Results
        return { ok: false, error: err instanceof Error ? err : new Error(String(err)) };
    } finally {
        clearTimeout(timeoutId);
    }
}

Allocation-Free Hot Path (Object Pooling)

// Pre-allocate at startup to avoid GC pauses during execution
class BufferPool {
    private pool: Uint8Array[];

    constructor(size: number, bufferSize: number) {
        this.pool = Array.from({ length: size }, () => new Uint8Array(bufferSize));
    }

    acquire(): Uint8Array | null {
        return this.pool.pop() || null;
    }

    release(buf: Uint8Array): void {
        // Reset state before returning to pool
        buf.fill(0);
        this.pool.push(buf);
    }
}

const pool = new BufferPool(100, 1024);

function processData(target: Uint8Array): Result<void, Error> {
    // Acquire from pool instead of `new Uint8Array(1024)`
    const buf = pool.acquire();
    if (!buf) return { ok: false, error: new Error("Pool exhausted") };

    try {
        // ... mutate target or buf in-place
        return { ok: true, value: undefined };
    } finally {
        pool.release(buf);
    }
}

Result Types over Exceptions

// Define explicit union returns instead of throwing
type Result<T, E = Error> =
  | { ok: true; value: T }
  | { ok: false; error: E };

function parseData(input: string): Result<ParsedData, ValidationError> {
    if (!input) return { ok: false, error: new ValidationError("Empty input") };

    // ...
    return { ok: true, value: data };
}

Critical Rules

  1. No Recursion - Keep control flow simple and execution bounds completely static.
  2. Fixed Upper Bounds - All loops, arrays, and Promises must be bounded (e.g., by size or timeouts).
  3. No Dynamic Memory After Init - Allocate all significant memory (Object Pools/Arrays) at startup.
  4. Short Functions - Hard limit of 70 lines per function. Push ifs up, push fors down.
  5. Check All Returns - Never ignore the result of a Result<T, E> or a Promise. Await everything.
  6. Explicit Panics Only - throw *only* for programmer errors/broken invariants (like assertion failures). Use standard explicit Result returns for operational issues.
  7. Strict Compilation - Must use strict: true, noUncheckedIndexedAccess: true, and noImplicitReturns: true.
  8. Options Interfaces - Use explicit options interfaces for configuration instead of multiple boolean/primitive arguments.
  9. Zero Dependencies - Strictly avoid third-party NPM dependencies outside standard library tools or extensively vetted utilities (like zod).
  10. Strict Naming - Add units or qualifiers at the end of variables (e.g., timeoutMs, latencyMaxMs).

Anti-Patterns (NEVER)

  • Using any or explicit type assertions (as Type) to bypass the compiler
  • Throwing exceptions for expected business logic errors (e.g., throw new Error("Invalid User"))
  • Using unbounded while(true) loops or new Promise(() => {}) without a reject mechanism
  • Accessing arrays without verifying the index exists (requires noUncheckedIndexedAccess)
  • Returning implicitly or ignoring awaited variables (void myAsyncFunc())
  • Magic metaprogramming (Proxy, Reflect, dynamically adding/deleting object properties delete obj.prop)

Credits

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

32.17%
按下载量换算55

Claude

31.34%
按下载量换算54

Cursor

18.21%
按下载量换算31

Gemini CLI

9.06%
按下载量换算15

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

需要联网

该 Skill 可能需要联网访问来源站点、仓库或外部 API;具体网络访问范围需要结合源码和 README 复核。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills