← CorezoidCONTENT HISTORY

Update to Corezoid

Snapshot Oct 9, 2026 · 00:04 UTC · version 3.9.0

Collection source: downloaded plugin package.

WHAT CHANGED · RULE-BASED ANALYSIS

First saved snapshot

No earlier snapshot is available to establish a change.

Compare saved observations

Download comparison JSON
Full technical diff · 0 changed fields
Full snapshot data
{
  "description": "Corezoid process review and audit specialist. Use when the user wants to analyze, review, audit, or improve an existing Corezoid process. Activate when the user says \"review a process\", \"analyze\", \"check\", \"audit\", \"find issues\", \"explain this process\", \"what's wrong with\", \"optimize\", or \"check for hardcoded values\".\n",
  "included_files": [],
  "name": "corezoid-review",
  "skill_md_contents": "---\nname: corezoid-review\ndescription: >\n  Corezoid process review and audit specialist. Use when the user wants to\n  analyze, review, audit, or improve an existing Corezoid process. Activate\n  when the user says \"review a process\", \"analyze\", \"check\", \"audit\", \"find\n  issues\", \"explain this process\", \"what's wrong with\", \"optimize\", or\n  \"check for hardcoded values\".\n---\n\n# Review a Corezoid Process\n\nYou are a specialist in auditing and analyzing Corezoid processes using the `corezoid` MCP server.\n\n## Identify the Process (MANDATORY FIRST STEP)\n\n**Before doing anything else**, resolve `PROCESS_PATH`:\n\n1. Check whether the user already provided a process identifier — a file path, process name, or process ID — in the current message or conversation history.\n2. If no identifier is provided, ask:\n\n   > \"Please specify the process — you can provide a file path (e.g. `1278273_Business.folder/2778176_payment.conv.json`), a process name, or a process ID.\"\n\n   Do **not** call any MCP tools until the user provides an identifier.\n3. If the user gave a **name or ID** (not a file path), search the local working directory for the matching `.conv.json` file using the `find` or `grep` Bash tools (the project is already pulled locally).\n4. Once `PROCESS_PATH` is known, begin the audit below.\n\n---\n\n## Step 1: Structural Lint\n\nRun the linter to detect structural issues automatically:\n\nCall MCP tool **`lint-process`** with `process_path: \"<PROCESS_PATH>\"`.\n\nThis checks for:\n- **Orphaned nodes** — unreachable nodes not connected from Start\n- **No-op conditions** — all branches of a condition leading to the same node\n- **Unused set_param** — variables set but never referenced downstream\n\nRecord all findings. They will be included in the final report.\n\n---\n\n## Step 2: Load and Parse the Process\n\nRead the `.conv.json` file and extract nodes:\n\n- `ops[0]['scheme']` is a **list** — always index `[0]`\n- `node['condition']` is a dict with keys `logics` (list) and `semaphors` (list)\n- `node['extra']` is a **string** (escaped JSON) — not a dict\n- Conditions in `go_if_const` logics live in `lg['conditions']`, NOT in `lg['extra']`\n\nCollect node groups for analysis:\n\n```python\ncode_nodes  = [n for n in nodes for lg in n['condition']['logics'] if lg['type'] == 'code']\napi_nodes   = [n for n in nodes for lg in n['condition']['logics'] if lg['type'] == 'api']\nrpc_nodes   = [n for n in nodes for lg in n['condition']['logics'] if lg['type'] == 'api_rpc']\ncopy_nodes  = [n for n in nodes for lg in n['condition']['logics'] if lg['type'] == 'api_copy']\ncond_nodes  = [n for n in nodes for lg in n['condition']['logics'] if lg['type'] == 'go_if_const']\n```\n\n---\n\n## Step 3: Hardcode Check\n\n- **`code` nodes** — look for hardcoded IDs, URLs, tokens\n- **`api` nodes** — check URLs; must use `{{env_var[@name]}}`, not literals\n- **`api_rpc` / `api_copy`** — check `conv_id` values; numeric IDs instead of `@alias` are a flag\n- **`api_rpc` extra fields** — check for hardcoded values that should be variables\n\nFlag each hardcoded value for extraction to env_var (see `${CLAUDE_PLUGIN_ROOT}/docs/variables-guide.md`).\n\n### Root-level process metadata — do NOT flag as hardcoded\n\nThe `.conv.json` file has top-level fields that are process metadata assigned by the platform. Do **not** report them as hardcoded values:\n\n| Field | Description |\n|-------|-------------|\n| `conv_id` | The ID of this process itself |\n| `user_id` | Owner/author user ID |\n| `company_id` | Company/tenant identifier |\n| `folder_id` | Folder identifier |\n| `project_id` | Project identifier |\n| `stage_id` | Stage/environment identifier |\n\nThese are read-only platform metadata, not configuration that should be extracted to env_vars.\n\n---\n\n## Step 4: Repeated Logic\n\n- Compare similarly named nodes (e.g. multiple `CREATE ACTOR`, `MANAGE ACCESS RULES`)\n- If structure is identical → mark as duplicated logic, recommend extracting into a subprocess\n\n---\n\n## Step 5: Cycle Verification\n\n### Internal cycles\n\n- Detect nodes with `semaphors` of type `time` or `go_if_const` that create loops\n- Verify exit conditions exist and iteration limits are enforced\n\n### Cross-process cycles\n\nAny automatic action that causes a task to appear in another process is a potential cycle point. Before adding such a call, verify that the called process cannot return control back to the originating process — neither directly nor through a chain of intermediate processes — without user interaction.\n\nA cycle is acceptable only if it contains an explicit break point: a user action, an iteration counter, or a timeout.\n\n**Checklist for every automatic inter-process call (`api_copy`, `api_rpc`, `api`, or any other mechanism that creates a task in another process):**\n\n1. Can the called process return a call to the originating process — directly or through a chain?\n2. If yes — is there a break point?\n3. If no break point — a bypass parameter or a different route is required.\n\n**How to check** *(apply after Step 11 — outbound call data from Steps 10–11 is required)*:\n\n1. Using the outbound dependency list from Step 10, collect all direct outbound calls.\n2. For each dependency pulled in Step 11, collect *its* outbound calls (sub-dependencies listed there).\n3. Continue tracing until either:\n   - the originating process reappears in the chain → **cycle found**, or\n   - every branch reaches a terminal node or a user-interaction gate → **safe**.\n\n> ⚠️ Step 11 is explicitly 1-level deep and will not surface 3+-hop cycles on its own. For processes that act as dispatchers (high out-degree, parameter-based routing), always trace at least one level deeper manually before concluding no cycle exists.\n\nFlag any chain where the originating process appears as a downstream target without a break point.\n\n> **Execution note:** Record the checklist questions now (Step 5) and run the \"How to check\" trace at the end of Step 11, once all dependency schemes have been pulled.\n\nReport format:\n\n```markdown\n## 4. Cycles\n\n### Internal\n- [ ] Node W: no exit condition → add iteration limit\n\n### Cross-process\n- [ ] conv_id X → conv_id Y → conv_id Z → back to this process without break point\n  → add bypass parameter or change routing\n```\n\n---\n\n## Step 6: Node Naming\n\n- Identify nodes with empty `title`\n- Check for duplicate or vague names\n- Recommended format: `Action_Object_Context` (e.g. `Create_Stream_Active`)\n\n---\n\n## Step 7: Code Node Analysis\n\n### JavaScript nodes — check for:\n\n- `try/catch` wrapping all external calls\n- No hardcoded values (IDs, tokens, URLs)\n- Safe type conversions (`parseInt`, `Number`)\n- Input validation (`if (!data.var) { ... }`)\n- No `eval` usage\n\n### Erlang nodes — check for:\n\n- Pattern matching covers all cases\n- `catch` or `case` for invalid data\n- No recursion without termination conditions\n\n### set_param optimization\n\nCode nodes that only do simple assignments should be replaced with `set_param`. Flag these patterns:\n\n| Pattern in code node                    | Replace with set_param                      |\n|-----------------------------------------|---------------------------------------------|\n| `data.x = data.y;`                      | `\"x\": \"{{y}}\"`                              |\n| `data.x = data.a + \"_\" + data.b;`       | `\"x\": \"{{a}}_{{b}}\"`                        |\n| `data.x = data.a + data.b;` (numeric)   | `\"x\": \"$.math({{a}}+{{b}})\"`                |\n| `data.x = data.a * data.b;`             | `\"x\": \"$.math({{a}}*{{b}})\"`                |\n| `data.x = \"constant\";`                  | `\"x\": \"constant\"`                           |\n| `data.x = data.x;`                      | remove entirely (self-assignment, no-op)     |\n\n`$.math()` takes exactly **two operands**. For 3+, nest: `$.math($.math({{a}}+{{b}})+{{c}})`. Supported operators: `+`, `-`, `*`, `/`. Use `extra_type: \"number\"` when the result should be numeric.\n\nOperations that genuinely require a code node: `str.length`, regex, `JSON.parse/stringify`, array `.map/.filter`, complex `if/else`, object key iteration.\n\n---\n\n## Step 8: Semaphor Coverage\n\nCheck for missing semaphors by severity:\n\n- 🔴 **`api_callback`** — MUST have a `time` semaphor. Without one tasks hang forever if the user abandons the session.\n- 🟡 **`api`** (outbound HTTP) — Should have a `time` semaphor as safety net against unresponsive endpoints.\n- 🟢 **`api_rpc`** — Lower severity; target process handles its own timeouts. Still recommended.\n- 🟢 **`api_copy` with `is_sync: true`** — Informational; target process manages its own lifecycle.\n\n---\n\n## Step 9: Error Handling Review\n\n- Every error node (obj_type 3) must transition to a final error node (obj_type 2)\n- Every error reply node must have `throw_exception: true`\n- Every success reply node must have `throw_exception: false`\n- Each error node should have a meaningful `errorText`\n- Detect duplicated error nodes with identical titles/messages\n\n---\n\n## Step 10: External Dependencies Inventory\n\nScan all nodes and collect every outbound reference:\n\n1. **api_rpc** — unique `conv_id` values\n2. **api_copy** — unique `conv_id` values\n3. **State reads** — `conv[@alias]` references inside `set_param` extra values or condition parameters\n\nFlag:\n- ⚠️ Numeric `conv_id` without `@alias` — flag in the report; suggest a `short_name` derived from the process title (lowercase, hyphens). Do **not** call `create-alias` automatically — only create aliases when the user explicitly requests it.\n- ⚠️ Same alias called with both create and modify modes\n- ⚠️ More than 5 unique dependencies — note coupling risk\n- ⚠️ `conv[@alias]` state reads — implicit dependencies that break if the referenced process changes schema\n\nTo manually verify unused set_param findings, search for each variable name across the `.conv.json` file — check all logics, extras, conditions, and semaphors.\n\n---\n\n## Step 11: Dependency Process Reviews\n\nPerform a **1-level deep** review of all unique outbound dependencies. Review each direct dependency but do NOT recurse into their sub-dependencies — only list them.\n\nFor each dependency:\n\n1. Collect all unique `conv_id` values from the main process\n2. Pull the dependency process using MCP tool **`pull-process`** with `process_id` set to the `conv_id` value, then read the resulting `.conv.json`\n3. Run a lightweight review covering:\n   - Node count and type distribution\n   - Untitled node count\n   - JS/Erlang code nodes: `try/catch`, hardcoded values\n   - API nodes missing semaphors\n   - Hardcoded values in RPC extra fields / URLs\n   - Sub-dependencies (list but do NOT recurse)\n   - Flag processes with 200+ nodes as needing their own dedicated review\n\nAfter pulling all dependencies, apply the **cross-process cycle trace** from Step 5 (\"How to check\"): use the sub-dependency lists collected above to trace whether any chain leads back to the originating process without a break point.\n\nReport format:\n\n```markdown\n## Dependency Process Reviews\n\n### @alias-name (conv_id=XXXXX) — \"Process Title\"\n\nNN nodes. MM/NN untitled.\n\n- [ ] ⚠️ X API nodes missing semaphors\n- [ ] ⚠️ JS code without try/catch in node \"Y\"\n- [ ] Sub-dependencies: @a, @b, 12345\n- [ ] **Needs own dedicated review** (200+ nodes)\n\n## Dependency Health Summary\n\n| Dependency | Nodes | Untitled | Missing Semaphors | Hardcoded conv_ids | JS no try/catch | Needs Own Review |\n|-----------|-------|----------|-------------------|-------------------|-----------------|--------------------|\n| @alias    | 154   | 74       | 6                 | 0                 | 10              | —                  |\n```\n\n---\n\n## Step 12: Dependency Graph\n\nBased on the dependency data collected in Steps 10–11, produce a Mermaid diagram of direct process-to-process dependencies:\n\n````markdown\n```mermaid\ngraph TD\n    MainProcess[\"Process Name\"] --> Dep1[\"@alias-name (conv_id=XXXXX)\"]\n    MainProcess --> Dep2[\"@alias2 (conv_id=YYYYY)\"]\n    Dep1 --> SubDep1[\"@sub-alias\"]\n```\n````\n\nInclude in the report:\n\n```markdown\n## 12. Dependency Graph\n\n\\`\\`\\`mermaid\ngraph TD\n    ...\n\\`\\`\\`\n\nN direct dependencies, N total processes mapped.\n```\n\n---\n\n## Step 13: Generate Report\n\nProduce a Markdown report:\n\n```markdown\n# Process Review: <process name>\n\n## 1. Structural Issues (lint-process)\n\n- [ ] 🔴 N orphaned nodes — list each: (id, title, type)\n- [ ] ⚠️ No-op condition in node \"X\" (id) — all branches route to same node \"Y\"\n- [ ] ⚠️ Unused set_param in node \"Z\" (id) — variable `{{var}}` not referenced downstream\n\n## 2. Hardcode\n\n- [ ] Node X: API key hardcoded → move to env_var\n\n## 3. Repeated Logic\n\n- [ ] Nodes Y, Z: identical structure → extract into subprocess\n\n## 4. Cycles\n\n### Internal\n- [ ] Node W: no exit condition → add iteration limit\n\n### Cross-process\n- [ ] conv_id X → conv_id Y → conv_id Z → back to this process without break point\n  → add bypass parameter or change routing\n\n## 5. Naming\n\n- [ ] Node without title → rename to \"Validate Token\"\n- [ ] Duplicate titles \"error manage access rules\" → make unique\n\n## 6. Code Review\n\n- [ ] JS: Node \"Code_123\" has no try/catch → add error handling\n- [ ] Erlang: Node \"Code_456\" has recursion without termination condition\n\n## 7. Code Node Optimization (set_param migration)\n\n- [ ] ⚠️ Node \"X\": `data.a = data.b + \"__\" + data.c` → set_param: `\"a\": \"{{b}}__{{c}}\"`\n- [ ] ⚠️ Node \"Y\": `data.total = data.x + data.y` → set_param: `\"total\": \"$.math({{x}}+{{y}})\"`\n- [ ] ⚠️ Node \"Z\": `data.x = data.x` → remove (self-assignment, no-op)\n\n## 8. Semaphor Coverage\n\n- [ ] 🔴 api_callback node \"X\" — missing time semaphor (tasks will hang)\n- [ ] 🟡 api node \"Y\" — missing time semaphor (risk on unresponsive endpoint)\n\n## 9. Error Handling\n\n- [ ] Missing err_node_id on set_param in node \"X\"\n- [ ] Duplicated error messages across nodes \"Y\", \"Z\"\n- [ ] Node \"Z\" reply node missing throw_exception: true\n\n## 10. External Dependencies\n\n| # | Alias / conv_id | Call Type | Count | Usage Summary | Notes |\n|---|----------------|-----------|-------|---------------|-------|\n| 1 | @send-message  | api_rpc   | 10    | OTP prompt, errors, success | — |\n| 2 | 21123          | api_copy  | 2     | Send report   | ⚠️ hardcoded numeric |\n\n### State Store References\n\n- `conv[@user-profile]` — reads language, registration_ban\n\n## 11. Dependency Process Reviews\n\n### @alias-name (conv_id=XXXXX) — \"Process Title\"\n\nNN nodes. MM/NN untitled.\n\n- [ ] ⚠️ X API nodes missing semaphors\n- [ ] Sub-dependencies: @a, @b\n\n## Dependency Health Summary\n\n| Dependency | Nodes | Untitled | Missing Semaphors | Hardcoded conv_ids | JS no try/catch | Needs Own Review |\n|-----------|-------|----------|-------------------|-------------------|-----------------|--------------------|\n| @alias    | 154   | 74       | 6                 | 0                 | 10              | —                  |\n\n## 12. Dependency Graph\n\n```mermaid\ngraph TD\n    ...\n```\n\nN direct dependencies, N total processes mapped.\n```\n\n---\n\n## Reference Documents\n\nUse the `Read` tool to load these files when specific node or validation details are needed:\n\n| Path | When to read |\n|---|---|\n| `${CLAUDE_PLUGIN_ROOT}/docs/nodes/code-node.md` | Code node details and available JS libraries |\n| `${CLAUDE_PLUGIN_ROOT}/docs/nodes/call-process-node.md` | Call a Process node, semaphores |\n| `${CLAUDE_PLUGIN_ROOT}/docs/nodes/api-call-node.md` | HTTP API call configuration |\n| `${CLAUDE_PLUGIN_ROOT}/docs/process/error-handling.md` | Error handling patterns |\n| `${CLAUDE_PLUGIN_ROOT}/docs/process/process-json-validation.md` | Validation rules and common errors |\n\n---\n\n## Final Step: Update Git Context\n\n> **Do NOT report the task as complete and do NOT stop until this step is evaluated.**\n> The main task being deployed does not mean the session is over — this step is next.\n\nImmediately after `push-process` or `create-process` succeeds, check whether\n**at least one** of the following is true:\n\n- `push-process` or `create-process` was actually called (not just previewed);\n- a new external host/API/service appeared that is not yet in `dependencies.md`;\n- an architectural decision was made (one approach chosen over another);\n- an issue was found or closed during this session.\n\n**If yes → activate `corezoid-git-context` skill right now.** Do not wait for the\nuser to ask. Do not skip because the main task \"looks done\".\n\n**If none of the above → skip** and tell the user the session is complete.\n\nThe skill handles everything autonomously: reads current `_ext/docs/`, proposes\na unified diff, asks confirmation, writes files, and pushes — one invocation.\n"
}

SHA-256 of public snapshot: 24a1944b8484e040c25fbc1df0c3630e3ed1bcc2596fe824cc5ec85b48bae3d4