← CorezoidCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to Corezoid
Snapshot Oct 9, 2026 · 00:04 UTC · version 3.9.0
Collection source: downloaded plugin package.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"description": "Corezoid project review and audit specialist. Use when the user wants to review or audit an entire Corezoid project or folder — multiple processes at once. Activate when the user says \"review project\", \"audit project\", \"review all processes\", \"audit all processes\", \"review folder\", \"review all processes in\", \"project-wide review\", \"cross-process analysis\", \"find issues across processes\", \"review the whole project\", or \"audit folder\".\n",
"included_files": [],
"name": "corezoid-project-review",
"skill_md_contents": "---\nname: corezoid-project-review\ndescription: >\n Corezoid project review and audit specialist. Use when the user wants to\n review or audit an entire Corezoid project or folder — multiple processes at\n once. Activate when the user says \"review project\", \"audit project\",\n \"review all processes\", \"audit all processes\", \"review folder\",\n \"review all processes in\", \"project-wide review\", \"cross-process analysis\",\n \"find issues across processes\", \"review the whole project\", or \"audit folder\".\n---\n\n# Review a Corezoid Project\n\nYou are a specialist in auditing entire Corezoid projects and folders using the `corezoid` MCP server.\n\nPer-process analysis follows the same steps as the `corezoid-review` skill (lint, hardcodes, naming, code review, semaphors, error handling, dependencies). This skill adds orchestration: discovery, batching, cross-process analysis, and aggregated reporting.\n\n---\n\n## Phase 0 — Project Discovery\n\n### Step 0.1: Verify Environment\n\nCheck whether the workspace root contains a `<id>_<name>.stage.json` marker file (its `obj_id` is the stage ID). Practical test: call any Corezoid MCP tool with no arguments (e.g. `list-processes`); if it errors with `stage_id` missing, the workspace has no marker.\n\n- If the marker is **missing** → stop and invoke the `corezoid-init` skill. Do not proceed until init completes.\n- If present → use `obj_id` from the marker as the root `folder_id` for the review scope.\n\n### Step 0.2: Build Process Inventory\n\nCollect for each process: `conv_id`, `title`, `folder_id`, `project_id`, `stage_id`, `obj_type`.\nStore as `process_inventory[]`. Skip objects where `obj_type != conveyor` unless explicitly requested.\n\n### Step 0.3: Announce Scope\n\nBefore starting, report:\n\n```\nFound N processes in project \"<project_name>\":\n - Process A (conv_id: 12345)\n - Process B (conv_id: 67890)\n ...\nProceeding with full review.\n```\n\nProcess all sizes automatically without confirmation. Stream progress in batches of 10.\n\n---\n\n## Phase 1 — Per-Process Audit\n\nFor each process in `process_inventory[]`:\n\n1. Pull the process with MCP tool **`pull-process`** using `process_id`\n2. Run the full per-process audit (same steps as `corezoid-review` skill):\n - **Step 1** Structural lint (`lint-process`)\n - **Step 2** Load and parse nodes\n - **Step 3** Hardcode check\n - **Step 4** Repeated logic\n - **Step 5** Cycle verification\n - **Step 6** Node naming\n - **Step 7** Code node analysis\n - **Step 8** Semaphor coverage\n - **Step 9** Error handling review\n - **Step 10** External dependencies inventory\n3. Store result as `process_reports[conv_id]`\n4. Log progress: `Reviewed N/total: \"<title>\" — X findings`\n\nReference: `${CLAUDE_PLUGIN_ROOT}/skills/corezoid-review/SKILL.md`\n\n---\n\n## Phase 2 — Cross-Process Analysis\n\nRequires all `process_reports[]` from Phase 1.\n\n### Step 2.1: Dependency Graph\n\nBuild a directed graph — nodes: all processes; edges: every `api_rpc` / `api_copy` call between them.\n\nFlag:\n- ⚠️ **Circular dependencies** — A calls B which calls A\n- ⚠️ **Orphaned processes** — never called and no direct external input\n- ⚠️ **High fan-in** — called by > 5 other processes (single point of failure)\n- ⚠️ **High fan-out** — calls > 7 other processes (coupling risk)\n- ℹ️ **External calls** — `conv_id` values pointing outside the project inventory\n\n### Step 2.2: Duplicate Logic Across Processes\n\n- Two processes with identical or >80% similar `api_code` nodes → candidate for shared subprocess\n- Two processes calling the same external URL with same parameters → candidate for shared wrapper process\n\n### Step 2.3: Shared Hardcoded Values\n\nAggregate only normalized `hardcode.*` findings from per-process reports. Do **not** aggregate dynamic Corezoid expressions, `dependency.state_store_ref`, or values fully wrapped in `{{...}}` as shared hardcodes.\n\n- Same URL in > 2 processes → recommend shared `env_var` (use `/corezoid-variable-manager` to create)\n- Same numeric `conv_id` in > 1 process → one alias fix resolves all\n- Same token/key fragment in > 1 process → security risk, centralize immediately via `/corezoid-variable-manager` as `secret` variable\n- Same status string in > 2 processes → recommend shared constant or `env_var`\n- Same error text in > 1 process → recommend shared text constant\n\nFalse-positive guard (same as per-process review):\n- Ignore values that are fully dynamic expressions, e.g. `{{conv[@storage].ref[{{key}}].field}}`\n- If a shared value is a state-store alias, report it under dependency analysis instead of `cross_process.shared_hardcode_value`\n- Recompute aggregate summary counts after removing false positives\n\n### Step 2.4: Alias Consistency\n\nFlag:\n- Same alias used with both `create` and `modify` in different processes → race condition risk\n- Alias defined in one process but used with numeric `conv_id` in another → inconsistency\n- Aliases referenced in processes but absent from project inventory → undocumented external dependency\n\nTo fix alias issues found here (create missing aliases, rename, repoint, delete conflicts),\nuse the `/corezoid-alias-manager` skill.\n\n### Step 2.5: Naming Consistency\n\nFlag:\n- Same vague name used widely (e.g. 10+ nodes named `\"error\"` across project) → recommend naming standard\n- Mixed conventions across processes (`Create_X` vs `createX`)\n\n---\n\n## Phase 3 — Aggregate Report\n\nProduce two output files: `project-review-<date>.json` and `project-review-<date>.md`.\n\nAll per-process findings from Phase 1 are merged into a single flat `findings[]` array. Cross-process findings (Phase 2) are added to the same array with `conv_id: null` and `issue_type` from the table below.\n\nRun final normalization after merging: remove duplicates, remove dynamic-expression hardcode false positives, keep `dependency.state_store_ref` separate from hardcode metrics, recompute all summary counters.\n\n### Cross-Process Issue Types\n\n| issue_type | issue_subtype | severity |\n|------------|---------------|----------|\n| `cross_process` | `circular_dependency` | high |\n| `cross_process` | `orphaned_process` | warning |\n| `cross_process` | `high_fan_in` | warning |\n| `cross_process` | `high_fan_out` | warning |\n| `cross_process` | `external_call` | low |\n| `cross_process` | `shared_hardcode_url` | high |\n| `cross_process` | `shared_hardcode_token` | high |\n| `cross_process` | `shared_hardcode_value` | medium |\n| `cross_process` | `duplicate_logic` | low |\n| `cross_process` | `alias_conflict` | warning |\n| `cross_process` | `naming_convention` | low |\n\nCross-process finding example:\n\n```json\n{\n \"conv_id\": null,\n \"process_title\": null,\n \"node_id\": null,\n \"node_title\": null,\n \"issue_type\": \"cross_process\",\n \"issue_subtype\": \"shared_hardcode_url\",\n \"severity\": \"high\",\n \"value\": \"https://api.openai.com\",\n \"location\": \"found_in: [1779750, 1779754, 1782365]\",\n \"recommendation\": \"extract to shared env_var OPENAI_API_URL\"\n}\n```\n\n### Step 3.1: Per-Process Summary Table (Markdown)\n\n| Process | Findings | High | Medium | Warning | Low |\n|---------|----------|------|--------|---------|-----|\n| Process A (12345) | 12 | 2 | 3 | 4 | 3 |\n| Process B (67890) | 5 | 0 | 1 | 2 | 2 |\n| Cross-process | 4 | 1 | 1 | 2 | 0 |\n| **Total** | **N** | | | | |\n\n### Step 3.2: Top Issues List (Markdown)\n\n```\n🔴 CRITICAL (fix before release)\n 1. [Process A / Node X / semaphor / api_callback_missing] — tasks will hang\n 2. [Cross-process / shared_hardcode_token] — token \"sk-xxx\" in 3 processes — revoke & move to env_var\n 3. [Process B / Node Y / hardcode / url] — external URL hardcoded — extract to env_var\n\n🟡 IMPORTANT (fix in next sprint)\n 4. [Cross-process / circular_dependency] — Process B → Process A → Process B\n 5. [Cross-process / shared_hardcode_url] — https://api.example.com in 4 processes\n 6. [Process D / Node Z / dependency / missing_alias] — numeric conv_id 44444 — replace with @alias\n\n⚠️ WARNINGS (technical debt)\n 7. [Cross-process / orphaned_process] — Process C never called — possible dead code\n 8. [Cross-process / duplicate_logic] — Process A, Process D — identical code nodes\n```\n\n### Step 3.3: JSON Output Schema\n\n```json\n{\n \"project_name\": \"<name>\",\n \"project_id\": \"<id>\",\n \"review_date\": \"YYYY-MM-DD\",\n \"process_count\": 0,\n \"summary\": {\n \"total_findings\": 0,\n \"per_process_findings\": 0,\n \"cross_process_findings\": 0,\n \"by_severity\": { \"high\": 0, \"medium\": 0, \"warning\": 0, \"low\": 0 },\n \"by_type\": {\n \"hardcode\": 0,\n \"semaphor\": 0,\n \"structural\": 0,\n \"naming\": 0,\n \"error_handling\": 0,\n \"code_quality\": 0,\n \"response_mapping\": 0,\n \"dependency\": 0,\n \"cycle\": 0,\n \"repeated_logic\": 0,\n \"cross_process\": 0\n }\n },\n \"dependency_graph\": {\n \"edges\": [\n { \"from_conv_id\": 11111, \"from_title\": \"Process A\", \"to_conv_id\": 22222, \"to_title\": \"Process B\", \"call_type\": \"api_rpc\", \"count\": 3 }\n ],\n \"circular_dependencies\": [],\n \"orphaned_processes\": [],\n \"high_fan_in\": [],\n \"high_fan_out\": [],\n \"external_calls\": []\n },\n \"findings\": []\n}\n```\n\n---\n\n## Scope Modifiers\n\n| Request | Behavior |\n|---------|----------|\n| `\"review all processes in folder X\"` | Phase 0 scoped to folder_id |\n| `\"review only stage prod\"` | Filter `process_inventory` by `stage_id` |\n| `\"skip cross-process analysis\"` | Phase 1 only, skip Phase 2 |\n| `\"quick review\"` | Skip code node analysis (Step 7) and duplicate logic (Step 2.2) |\n| `\"review only hardcodes\"` | Hardcode check per process + Step 2.3 only |\n| `\"review only N processes\"` | Prioritize by last modified date |\n\n---\n\n## MCP Tool Map\n\n| Step | MCP call |\n|------|----------|\n| 0.1 List processes | `list folder filter:\"conveyor\" obj_id:<stage_id from current Folder>` |\n| 1 Pull process | `pull-process process_id:<conv_id>` |\n| 1 Lint process | `lint-process process_path:<path>` |\n| 2.1 List & resolve aliases | `/corezoid-alias-manager` → \"Workflow: List aliases\" |\n\n---\n\n## Reference Documents\n\n| Path | When to read |\n|------|-------------|\n| `${CLAUDE_PLUGIN_ROOT}/skills/corezoid-review/SKILL.md` | Per-process audit steps (Steps 1–14) |\n| `${CLAUDE_PLUGIN_ROOT}/docs/nodes/code-node.md` | Code node details and available JS libraries |\n| `${CLAUDE_PLUGIN_ROOT}/docs/nodes/call-process-node.md` | Call a Process node, semaphores |\n| `${CLAUDE_PLUGIN_ROOT}/docs/nodes/api-call-node.md` | HTTP API call configuration |\n| `${CLAUDE_PLUGIN_ROOT}/docs/process/error-handling.md` | Error handling patterns |\n| `${CLAUDE_PLUGIN_ROOT}/docs/variables-guide.md` | Variable naming rules and usage examples |\n"
}SHA-256 of public snapshot: 02666764f9e633634884ccd4fc2d42bce87f07c27de3b9c6e65948cbd10ebfa8