Member card of the skills catalog optimization program #14292 (maintainer mandate 2026-09-02, verbatim: 「审核所有的 skills,进行全面的优化。」). Filed by the skills lane seat (session session_01LraLgQVGq8egUwfYZpbYt1). Read-only audit at objectstack origin/maina59f78d (skills/** byte-identical at d63c8a2); 43 findings DATA-A-01 … DATA-I-04. The full findings table is the audit record: the dev posts it verbatim as the first comment on this card at claim time (source: the seat container's scratchpad audit/objectstack-data/findings.md).
Audit summary
12 files, 4,942 lines, 45,780 hand-authored tokens (+1,483 generated) = 25.2% of the published catalog, 29% larger than the next package; total headroom across 10 ratcheted files: 47 tokens, five at 0. Real usage (examples/** + packages/apps/**): 31 ObjectSchema.create() calls in 26 object files, ~250 Field.* calls vs 22 literals (92% factory), 3 defineSeed modules, 2 hook files, 2 datasource files, 0 *.seed.ts. All 9 patterns with ≥3 real usages are covered; 8 documented surfaces have zero corpus usage; two high-frequency keys have no coverage at all. Verdict RESTRUCTURE: hooks (14,779 tok, 32% of the package) are split across rules/hooks.md and references/data-hooks.md where the second calls itself a pointer and then restates five sections; the rules/ routing table is buried at line 312 of 1,216; the package holds 41% of the catalog's TypeScript (151 fences) with 3.3% os:check coverage — seven unmarked self-contained blocks would fail check-skill-examples today.
Top findings (token-delta × confidence)
| id | span | proposal | Δtok |
|---|
| DATA-B-01 / I-03 | rules/hooks.md (whole) ∥ references/data-hooks.md | MERGE-INTO one file — hooks.md:3 calls itself "a reference pointer", then restates 5 sections | −1,880 |
| DATA-D-04 | references/data-hooks.md:765-1046 | DELETE patterns 1,2,4,5,7,9 (generic JS); keep 3,6,8,10 | −1,000 |
| DATA-C-05 | SKILL.md:858-971 | REWRITE-AS-CONSTRUCT — 3 near-identical examples + Studio-banner narration for a 4-value enum; 0 corpus uses | −600 |
| DATA-B-04 | references/data-hooks.md:1050-1133 | DELETE — "Registration, three methods" also at rules/hooks.md:145-176 | −566 |
| DATA-D-11 | rules/naming.md:15-93, 103-107 | DELETE — 6 ❌/✅ pairs + rationale for a rule the regex at :9 already states | −566 |
| DATA-D-06 | rules/indexing.md:161-234 | REWRITE-AS-CONSTRUCT — one textbook fact (left-to-right) in 3 subsections | −480 |
| DATA-B-03 | rules/hooks.md:99-126 ∥ data-hooks.md:41-70 | DELETE one copy of the 8-event table | −466 |
| DATA-C-04 | 25 tombstone sites | DELETE standalone blocks — each key is refused by a parse error carrying its own prescription; objectstack-upgrade owns this | −450 |
| DATA-C-03 | references/data-hooks.md:1209-1275 | DELETE — vitest + LiteKernel harnesses; platform's frontmatter claims that surface | −432 |
| DATA-D-07 | rules/indexing.md:277-298, 312-340 | DELETE — unsourced Table Size → Max Indexes table, pg_stat_user_indexes SQL, 10 best-practices | −430 |
| DATA-B-05 | references/data-hooks.md:1136-1160 | DELETE — DO/DON'T also at rules/hooks.md:180-194 | −418 |
| DATA-D-12 | SKILL.md:540-555 | DELETE — "CRM Schema Blueprint" points at 6 things covered above it | −358 |
| DATA-C-01 | SKILL.md:162-189 | DELETE — two verbatim CLI/HTTP error transcripts; the 400 text is word-for-word in objectstack-query | −343 |
| DATA-D-09 | rules/validation.md:420-438 | DELETE — best-practices + unsourced perf claims | −338 |
| DATA-D-01/02/03 | references/data-hooks.md:1279-1444 | DELETE — invented benchmark table, "Advanced Topics" (a for loop), Troubleshooting, Summary | −990 |
Net after +825 of paid additions ≈ −10,150 tokens (−22.2%), touching none of the 9 live patterns.
Incidental falsehoods (fix in this flight)
- INC-01
SKILL.md:393 — required: true → false "dev auto-heals (autoMigrate:'safe')". Nullability drift is compared against storage.notNull, NOT required (packages/drivers/driver-sql/src/schema-drift.ts:795-798; field.zod.tsrequired.describe()), and the emitted op is severity: 'warning', category: 'needs_confirm', op: 'relax_not_null' — never auto-applied. HIGH. - INC-02
SKILL.md:398-401 — the "stale NOT NULL column" 400 story: schema-drift.ts:800-802 says that configuration produces a raw driver error, not a clean validation 400. MED.
Three funded additions
sharingModel (DATA-F-01, +130, paid by DATA-C-05) — used by 31/31 real objects, absent from both property tables; an object publish with no authored sharingModel is refused (security-owd-unset, packages/lint/src/validate-security-posture.ts:62).Field.* factory spelling in rules/field-types.md (DATA-E-03, +150, paid by DATA-D-14 + DATA-D-11) — the file whose job is field authoring contains zero Field.*; corpus is 92% factory.required vs storage.notNull (DATA-F-02, +60) and 4 security-lint rows (DATA-F-04, +90), paid by DATA-D-15 + DATA-D-13.
Flight scope
IMPLEMENT (same-file, shrink-only): every DELETE / MERGE-INTO / REWRITE-AS-CONSTRUCT row in the findings table at HIGH or MED confidence; the three funded additions; INC-01/INC-02 corrections; os:check markers on the top-traffic examples with the seven would-fail blocks repaired (DATA-E-01/03/05); the hooks consolidation — delete rules/hooks.md, keep references/data-hooks.md as the single hooks file with its unique content preserved and paid by the data-hooks deletions; drop the deleted file's ceiling row.
ANCHOR RULINGS (this package is the anchor): objects, fields, relationships, hooks, seeds, datasources, permissions/RLS. Sibling flights (ui, api, platform, query, automation) delete their copies and point HERE — keep the paths rules/relationships.md, rules/datasources.md, rules/field-types.md, references/data-hooks.md stable. The inbound link rules/hooks.md:202 → objectstack-platform rules/plugin-hooks-events.md: the platform flight retires that file; re-point to objectstack-platform/references/plugin-hooks.md. DATA-C-03 (test harness) → delete + one-line pointer to objectstack-platform. DATA-C-01 → delete (query keeps its copy).
DEFER (pending #14296): DATA-I-04 (new rules/security.md), DATA-H-01 (evals ceiling / stub), DATA-F-07 (defineHook() prescription — maintainer call; record as a follow-up in the PR body), DATA-F-05 retire-surface candidates → shrink to one schema-pointing row, do not delete.
Flight constraints (binding)
- ONE draft PR, first line
Fixes #<this card>; governed (skills/** md) ⇒ stays draft; review requests are the seat's step. - Token ratchet: no ratcheted file may grow; additions paid by deletions in the SAME file; ⛔ re-wrap is not payment; ⛔ no ceiling raise; ⛔ no new files;
scripts/check-skills-token-ratchet.mjs touched ONLY to drop the row of a file this PR deletes. - ⛔ Never edit another package's files: MERGE-INTO another package = DELETE here + one-line pointer; a missing/weaker anchor goes in the PR body under "follow-up for ".
- Generated files untouched (
references/_index.md); frontmatter edits ⇒ regenerate skills/README.md (pnpm --filter @objectstack/spec gen:skill-docs). - Live surface with zero measured usage ⇒ one row pointing at its schema, never delete the last mention; retired/tombstoned surface ⇒ delete.
- A false claim matching a spec
.describe() string ⇒ file the spec-side twin as an out-of-scope card. - Gates:
node scripts/check-skills-token-ratchet.mjs, pnpm --filter @objectstack/spec check:skill-examples, pnpm check:skill-compatibility, pnpm check:skill-identifier-liveness, plus node scripts/pm/dispatch-gates.mjs --commands <changed paths>; record the head sha. - PR body: per-item 落点 | before | after list keyed by finding id; per-file token delta;
needs:contract-review on both carriers if any operator/contract-semantics claim changes (INC-01 does).
Refs: #14292 · #14296 (batch-1 decisions) · #13658 (truth sweep).
Member card of the skills catalog optimization program #14292 (maintainer mandate 2026-09-02, verbatim: 「审核所有的 skills,进行全面的优化。」). Filed by the skills lane seat (session
session_01LraLgQVGq8egUwfYZpbYt1). Read-only audit at objectstackorigin/maina59f78d (skills/** byte-identical at d63c8a2); 43 findings DATA-A-01 … DATA-I-04. The full findings table is the audit record: the dev posts it verbatim as the first comment on this card at claim time (source: the seat container's scratchpadaudit/objectstack-data/findings.md).Audit summary
12 files, 4,942 lines, 45,780 hand-authored tokens (+1,483 generated) = 25.2% of the published catalog, 29% larger than the next package; total headroom across 10 ratcheted files: 47 tokens, five at 0. Real usage (examples/** + packages/apps/**): 31
ObjectSchema.create()calls in 26 object files, ~250Field.*calls vs 22 literals (92% factory), 3defineSeedmodules, 2 hook files, 2 datasource files, 0*.seed.ts. All 9 patterns with ≥3 real usages are covered; 8 documented surfaces have zero corpus usage; two high-frequency keys have no coverage at all. Verdict RESTRUCTURE: hooks (14,779 tok, 32% of the package) are split acrossrules/hooks.mdandreferences/data-hooks.mdwhere the second calls itself a pointer and then restates five sections; therules/routing table is buried at line 312 of 1,216; the package holds 41% of the catalog's TypeScript (151 fences) with 3.3%os:checkcoverage — seven unmarked self-contained blocks would failcheck-skill-examplestoday.Top findings (token-delta × confidence)
rules/hooks.md(whole) ∥references/data-hooks.mdhooks.md:3calls itself "a reference pointer", then restates 5 sectionsreferences/data-hooks.md:765-1046SKILL.md:858-971references/data-hooks.md:1050-1133rules/hooks.md:145-176rules/naming.md:15-93, 103-107:9already statesrules/indexing.md:161-234rules/hooks.md:99-126∥data-hooks.md:41-70references/data-hooks.md:1209-1275rules/indexing.md:277-298, 312-340Table Size → Max Indexestable,pg_stat_user_indexesSQL, 10 best-practicesreferences/data-hooks.md:1136-1160rules/hooks.md:180-194SKILL.md:540-555SKILL.md:162-189rules/validation.md:420-438references/data-hooks.md:1279-1444forloop), Troubleshooting, SummaryNet after +825 of paid additions ≈ −10,150 tokens (−22.2%), touching none of the 9 live patterns.
Incidental falsehoods (fix in this flight)
SKILL.md:393—required: true → false"dev auto-heals (autoMigrate:'safe')". Nullability drift is compared againststorage.notNull, NOTrequired(packages/drivers/driver-sql/src/schema-drift.ts:795-798;field.zod.tsrequired.describe()), and the emitted op isseverity: 'warning',category: 'needs_confirm',op: 'relax_not_null'— never auto-applied. HIGH.SKILL.md:398-401— the "stale NOT NULL column" 400 story:schema-drift.ts:800-802says that configuration produces a raw driver error, not a clean validation 400. MED.Three funded additions
sharingModel(DATA-F-01, +130, paid by DATA-C-05) — used by 31/31 real objects, absent from both property tables; an object publish with no authoredsharingModelis refused (security-owd-unset,packages/lint/src/validate-security-posture.ts:62).Field.*factory spelling inrules/field-types.md(DATA-E-03, +150, paid by DATA-D-14 + DATA-D-11) — the file whose job is field authoring contains zeroField.*; corpus is 92% factory.requiredvsstorage.notNull(DATA-F-02, +60) and 4 security-lint rows (DATA-F-04, +90), paid by DATA-D-15 + DATA-D-13.Flight scope
IMPLEMENT (same-file, shrink-only): every DELETE / MERGE-INTO / REWRITE-AS-CONSTRUCT row in the findings table at HIGH or MED confidence; the three funded additions; INC-01/INC-02 corrections;
os:checkmarkers on the top-traffic examples with the seven would-fail blocks repaired (DATA-E-01/03/05); the hooks consolidation — deleterules/hooks.md, keepreferences/data-hooks.mdas the single hooks file with its unique content preserved and paid by the data-hooks deletions; drop the deleted file's ceiling row.ANCHOR RULINGS (this package is the anchor): objects, fields, relationships, hooks, seeds, datasources, permissions/RLS. Sibling flights (ui, api, platform, query, automation) delete their copies and point HERE — keep the paths
rules/relationships.md,rules/datasources.md,rules/field-types.md,references/data-hooks.mdstable. The inbound linkrules/hooks.md:202→ objectstack-platformrules/plugin-hooks-events.md: the platform flight retires that file; re-point toobjectstack-platform/references/plugin-hooks.md. DATA-C-03 (test harness) → delete + one-line pointer to objectstack-platform. DATA-C-01 → delete (query keeps its copy).DEFER (pending #14296): DATA-I-04 (new
rules/security.md), DATA-H-01 (evals ceiling / stub), DATA-F-07 (defineHook()prescription — maintainer call; record as a follow-up in the PR body), DATA-F-05 retire-surface candidates → shrink to one schema-pointing row, do not delete.Flight constraints (binding)
Fixes #<this card>; governed (skills/**md) ⇒ stays draft; review requests are the seat's step.scripts/check-skills-token-ratchet.mjstouched ONLY to drop the row of a file this PR deletes.references/_index.md); frontmatter edits ⇒ regenerateskills/README.md(pnpm --filter @objectstack/spec gen:skill-docs)..describe()string ⇒ file the spec-side twin as an out-of-scope card.node scripts/check-skills-token-ratchet.mjs,pnpm --filter @objectstack/spec check:skill-examples,pnpm check:skill-compatibility,pnpm check:skill-identifier-liveness, plusnode scripts/pm/dispatch-gates.mjs --commands <changed paths>; record the head sha.needs:contract-reviewon both carriers if any operator/contract-semantics claim changes (INC-01 does).Refs: #14292 · #14296 (batch-1 decisions) · #13658 (truth sweep).