Claude Skill

drift-canary

Compatibility and schema drift canary — checks for database schema migration safety, breaking API contract changes, serializable payload mismatches, and backward compatibility drift. Triggers on keywords: "/drift-canary", "drift-canary", "contract drift", "breaking changes". Use

LLM Mart · 0 points · 1 views 16 listing impressions 0 install-command copies
Virus-scanned Reviewed automatically before listing.

Full trust report

Download hetcreep-coalmine-plugin_skills_drift-canary-85306d7.zip · 6 KB
Part of hetcreep/coalmine — 18 skills

Install

skills CLI npx skills add https://github.com/TheColliery/CoalMine/tree/main/plugin/skills/drift-canary
Claude Code claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install hetcreep-coalmine@llmmart
Git git clone https://github.com/TheColliery/CoalMine.git

The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole hetcreep/coalmine collection as a plugin from our marketplace. Git is the plain clone.

Skill manifest

Drift Canary (Contract & Schema Drift Audit)

Language: Generate EVERYTHING at runtime in the user's language — questions, answer options, menu labels, recommendations, report narrative. Detect from their messages; never default to English just because this file is English. English is allowed only for technical terms: commands, paths, code identifiers, severity labels (CRITICAL/HIGH/MEDIUM/LOW), and tier names (Light/Standard/Heavy).

Config reads — every config key, always the CASCADE, never the bare project file: ~/.claude/.coalmine.json first, then the project config (own agent dir → other known agent dirs → legacy <gitroot>/.coalmine.json), project wins per key. A bare project read is ABSENT on a machine configured only globally, so it silently yields defaults.

Audit code to ensure changes do not break backward compatibility or cause database/API mismatches.

Auditing Categories

  1. Breaking Schema Migrations — dropping columns, changing types, or adding non-null columns without defaults (crashes on deploy).
  2. API Contract breaking changes — modifying existing REST/GraphQL properties, removing endpoints, or adding required query fields that break old clients.
  3. Serialization mismatches — editing properties in serialized payloads (JSON, Protobuf, XML) without deserialization fallbacks.
  4. Library Contract Drift — changing a public method signature in a shared library without a deprecated wrapper.
  5. Environment Configuration drift — introducing new required config keys (.env / OS vars) without defaults or fallback.

Expand/contract migration rules, per-format serialization fallbacks, and the breaking-vs-additive API checklist: read references/checks.md before scanning.

Scope: honor .coalmine.json schemaPaths / migrationDirs if set — scan those globs/dirs; else infer by inspecting the repo.

Discipline

  • Style Drift Resolution (Fix mode): when an approved fix touches mixed-style code, conform the minority patterns to the dominant style (highest average usage) to minimize churn — never start a standalone style refactor.

Fix mode (choice-gated)

In Agent Context, after the report, present via ask_question:

  • Apply safe deprecations: mark endpoints/methods deprecated + add backward-compatibility mapping wrappers. Each fix: checkpoint (git stash/commit in a git repo; else copy the file aside — never assume git) → apply → build + tests → auto-revert if newly red.
  • Let me pick: user selects specific compatibility fixes.
  • Report only: exit unchanged.

Grants & denials (CLASSIFY-BLOCK)

class step it powers grant on denial
read scan schema/API/serialization surfaces for the categories above Read·Grep·Glob refuse that file, name it — never a clean bill
write Fix mode's deprecation/compat-wrapper apply, incl. checkpoint → build+tests → auto-revert if newly red Edit·Bash (checkpoint/build/revert need exec) report the fix as NOT applied AND the checkpoint/revert as NOT available, never claim done

A denial reaches the WORKER as a visible message and propagates no further — never to a caller, never as a catchable condition. Every row above states a grant or an explicit death; a step that dies says so in the output, never as a false "done"/"skipped"/"clean".

  • read denied → refuse before scanning; never a false clean bill.
  • write denied → report the change as NOT applied — never claim done.
  • network denied/unfetchable → ⚠️ unverified: check [source].
  • spawn denied → degrade per Escalation's own capability-lever fallback (never fake parallelism) and say the fan-out did not happen — already discharged there; a row above is only for a spawn this skill does OUTSIDE tier escalation.

Output

| file:line | contract interface | severity | finding | migration path |

Severity: CRITICAL (breaking DB schema mutation / breaking API change) · HIGH (serialization type change) · MEDIUM (unmapped new required env key) · LOW (missing deprecation doc)

Reporting: call ReportFindings when callable — file/line MUST be the defect site, never the enclosing function; an unresolvable line reports your best guess, named imprecise in the wrap-up — never dropped, never faked. Severity prefixed in summary (e.g. [HIGH] …), ranked most-severe first, SUSPECTED as verdict: PLAUSIBLE; chat then carries only the wrap-up line (counts · coverage gaps · overflow past 32 · any imprecise-line findings) + the fix menu, never a restatement of findings. Not callable → the table above, unchanged. An Apply-fixes click = consent to the safe-fix class only — gated the same as this skill's own fix-mode (Hook Context needs an interactive session, per the Hook Context rule below) — composing with (never bypassing) the fix-mode discipline. After any fix round, re-report the same findings with outcome: fixed/skipped/no_change_needed — skipping this leaves the round UNFINISHED.

Escalation — Scope & Model Quality

Tiers are capability targets, not platform commands — resolve each to your host's nearest lever. No lever for one? Degrade gracefully — never fake parallelism you can't do; escalate via model tier + reasoning depth instead.

Level Intent Capability target Cost
Light Spot contract check, key interfaces only Cheapest model · single agent, no sub-agents. Low
Standard Balanced drift audit, multi-category Balanced model · raised reasoning · sub-agents per category only if your platform runs concurrent workers (else single-agent). Balanced
Heavy Full 5-category audit + adversarial compatibility verify Most capable model + largest context · deepest reasoning · max sub-agent fan-out if supported · adversarial cross-check where available. High

Per-platform Heavy levers + Heavy-run durability: read references/escalation.md before a Heavy run. No concurrent fan-out on your host → escalate by model + reasoning only.

Agent Context (interactive): score the tier rubric, then call ask_question once with the 3 tiers — the pick marked , score shown, labels localized — and wait for the choice before starting. ask_question = your platform's question tool: Claude Code AskUserQuestion · Cline ask_question · Copilot askQuestions · Gemini CLI ask_user (business-tier product; individual tiers ended 2026-06-18 → Antigravity CLI) · Codex request_user_input · Cursor/Devin Desktop (ex-Windsurf)/Antigravity built-in prompts; none → numbered text menu.

Tier rubric (deterministic): +1 each — ① >20 files or whole-repo/cross-module reach ② >2 of this skill's categories relevant ③ release/security/pre-ship context ④ findings will drive code changes. 0–1 Light · 2–3 Standard · 4 Heavy. Freshness cap: scope already audited ≥Standard this session → cap at Light (re-auditing fresh ground wastes tokens; scope to what changed). Default tier: honor .coalmine.json defaultTier unless the user requests a tier for that run — an explicit request overrides everything.

Hook Context (auto-triggered): auto-Light, no tier question, no sub-agents — report first. Interactive session (a user is present) → follow this skill's own Fix mode section, if it defines one, for what to offer after the report; non-interactive → report-only. Where a Fix mode section exists, never fix without a chosen option.

Entanglement: after the report, if confirmed findings fall in another canary's domain, offer it once via ask_question (one line, max one offer): perf/N+1 → scale-canary · contract/serialization/config → drift-canary · failure-path/retry → resilience-audit · logging/metrics → telemetry-canary · coupling/DI → testability-canary · dependency/CVE → supply-chain-audit · unverified version-sensitive claim → source-grounding · missing/stale rule → gold-standard.

Self error-report: if this skill misbehaves (contradictory instruction, broken procedure, wrong finding class), OFFER to file it at https://github.com/HetCreep/CoalMine/issues/new/choose with a user-reviewed summary — never auto-submit, never include unapproved code or paths.

Files (coalmine)
  • references
    • checks.md 2.3 KB
      <!-- coalmine: verified 2026-06-12 · revalidate 90d · definition file for drift-canary -->
      # Drift canary — concrete detection procedures
      
      ## 1. Breaking schema migrations — expand/contract rule
      Safe order (expand → migrate → contract; never combined in one release):
      1. **Expand:** add nullable column / new table / new index — old code keeps working.
      2. **Migrate:** backfill data; deploy code that writes both / reads new-with-fallback.
      3. **Contract:** only after all writers upgraded — add NOT NULL, drop old column.
      
      Flag as CRITICAL in one migration: `DROP COLUMN`/`DROP TABLE` still referenced by deployed code · type narrowing (`TEXT→INT`, shrinking varchar) · `ADD COLUMN ... NOT NULL` without `DEFAULT` on a populated table · renames (= drop+add to every old client).
      
      ## 2. Breaking API contract changes
      Breaking (flag): removing/renaming an endpoint, field, or enum value · changing a field's type/format · making an optional param required · changing error shape/status codes clients branch on.
      Safe (additive): new optional field · new endpoint · new enum value IF clients tolerate unknowns (verify!).
      Check: OpenAPI/GraphQL schema diff if present; otherwise diff DTO/serializer classes.
      
      ## 3. Serialization mismatches
      - JSON: removed/renamed properties without alias support (`[JsonPropertyName]`, `@JsonAlias`, serde `alias`) · strict deserializers that throw on unknown fields meeting a newer producer.
      - Protobuf: field NUMBER reuse or type change (wire-breaking) — numbers must be `reserved` after deletion; new fields = new numbers.
      - Queues/events: producer upgraded before consumers — old messages still in flight must deserialize.
      
      ## 4. Library contract drift (shared/public libs)
      - Public signature changes without `[Obsolete]`/`@deprecated` wrapper for one release window.
      - Behavior changes under an unchanged signature (return null→throw) — worse than signature breaks; flag.
      - SemVer: breaking change without major bump.
      
      ## 5. Config drift
      - New required env/config key read with no default and no startup validation → first crash happens in production.
      - Right shape: default value, or fail-fast at startup with the exact missing-key name, plus README/.env.example entry.
      
      ## Migration-path column (output)
      Each finding names its safe path: expand/contract step · alias/reserved-number · deprecated wrapper · default+validate.
      
    • escalation.md 1.4 KB
      <!-- coalmine: verified 2026-07-23 · revalidate 30d · shared escalation detail for all canaries -->
      # Heavy-tier escalation — per-platform levers & durability
      
      Read this only before a **Heavy** run (deep fan-out). Light/Standard never need it.
      
      ## Per-platform Heavy lever
      Use your host's, if it has concurrent fan-out:
      
      - **Claude Code** → Dynamic Workflows / `ultracode` (≤16 concurrent agents)
      - **OpenAI Codex** → `xhigh` + subagents + Cloud `--attempts`
      - **Cursor** → Max Mode + parallel Cloud Agents
      - **Amp** → Oracle + subagents
      - **GitHub Copilot** → `/fleet` (Copilot CLI) + Cloud agent
      - **Goose** → subagents
      - **JetBrains** → Junie CLI
      - **Gemini CLI (business-tier product; individual tiers ended 2026-06-18 → Antigravity CLI) / Cline (read-only) / Devin Desktop (ex-Windsurf)** → subagents
      
      No concurrent fan-out on your host → escalate by model tier + reasoning depth only; never fake parallelism you cannot do.
      
      ⚠️ Subagent support CHURNS fast — most major agents added it through 2026 — so verify your platform's current capability rather than trusting this list.
      
      ## Heavy-run durability
      Run in short phases, reading results between them. If a run dies, recover finished sub-agent results from your platform's run records and re-spawn only what is missing. On Claude Code, fan out with the bundled `coalmine-scanner` agent (read-only, one dimension per spawn, table output).
      
  • skill-meta.json 195 B
    { "lightIntent": "Spot contract check, key interfaces only", "standardIntent": "Balanced drift audit, multi-category", "heavyIntent": "Full 5-category audit + adversarial compatibility verify" }
    
  • SKILL.md 8.6 KB
    ---
    name: drift-canary
    description: >-
      Compatibility and schema drift canary — checks for database schema migration safety, breaking API contract changes, serializable payload mismatches, and backward compatibility drift. Triggers on keywords: "/drift-canary", "drift-canary", "contract drift", "breaking changes". Use when changing DB schemas, API contracts, serialized payloads, or required config keys.
    ---
    
    # Drift Canary (Contract & Schema Drift Audit)
    
    **Language:** Generate EVERYTHING at runtime in the user's language — questions, answer options, menu labels, recommendations, report narrative. Detect from their messages; never default to English just because this file is English. English is allowed only for technical terms: commands, paths, code identifiers, severity labels (CRITICAL/HIGH/MEDIUM/LOW), and tier names (Light/Standard/Heavy).
    
    **Config reads — every config key, always the CASCADE, never the bare project file:** `~/.claude/.coalmine.json` first, then the project config (own agent dir → other known agent dirs → legacy `<gitroot>/.coalmine.json`), project wins per key. A bare project read is ABSENT on a machine configured only globally, so it silently yields defaults.
    
    Audit code to ensure changes do not break backward compatibility or cause database/API mismatches.
    
    ## Auditing Categories
    1. **Breaking Schema Migrations** — dropping columns, changing types, or adding non-null columns without defaults (crashes on deploy).
    2. **API Contract breaking changes** — modifying existing REST/GraphQL properties, removing endpoints, or adding required query fields that break old clients.
    3. **Serialization mismatches** — editing properties in serialized payloads (JSON, Protobuf, XML) without deserialization fallbacks.
    4. **Library Contract Drift** — changing a public method signature in a shared library without a deprecated wrapper.
    5. **Environment Configuration drift** — introducing new required config keys (`.env` / OS vars) without defaults or fallback.
    
    Expand/contract migration rules, per-format serialization fallbacks, and the breaking-vs-additive API checklist: read `references/checks.md` before scanning.
    
    **Scope:** honor `.coalmine.json` `schemaPaths` / `migrationDirs` if set — scan those globs/dirs; else infer by inspecting the repo.
    
    ## Discipline
    - **Style Drift Resolution (Fix mode):** when an approved fix touches mixed-style code, conform the minority patterns to the dominant style (highest average usage) to minimize churn — never start a standalone style refactor.
    
    ## Fix mode (choice-gated)
    
    In Agent Context, after the report, present via `ask_question`:
    
    - **Apply safe deprecations:** mark endpoints/methods deprecated + add backward-compatibility mapping wrappers. Each fix: checkpoint (git stash/commit in a git repo; else copy the file aside — never assume git) → apply → build + tests → auto-revert if newly red.
    - **Let me pick:** user selects specific compatibility fixes.
    - **Report only:** exit unchanged.
    
    ## Grants & denials (CLASSIFY-BLOCK)
    | class | step it powers | grant | on denial |
    |---|---|---|---|
    | read | scan schema/API/serialization surfaces for the categories above | `Read`·`Grep`·`Glob` | refuse that file, name it — never a clean bill |
    | write | Fix mode's deprecation/compat-wrapper apply, incl. checkpoint → build+tests → auto-revert if newly red | `Edit`·`Bash` (checkpoint/build/revert need exec) | report the fix as NOT applied AND the checkpoint/revert as NOT available, never claim done |
    
    A denial reaches the WORKER as a visible message and propagates no further — never to a
    caller, never as a catchable condition. Every row above states a grant or an explicit death;
    a step that dies says so in the output, never as a false "done"/"skipped"/"clean".
    
    - **read** denied → refuse before scanning; never a false clean bill.
    - **write** denied → report the change as NOT applied — never claim done.
    - **network** denied/unfetchable → `⚠️ unverified: check [source]`.
    - **spawn** denied → degrade per Escalation's own capability-lever fallback (never fake
      parallelism) and say the fan-out did not happen — already discharged there; a row above
      is only for a spawn this skill does OUTSIDE tier escalation.
    
    ## Output
    `| file:line | contract interface | severity | finding | migration path |`
    
    Severity: CRITICAL (breaking DB schema mutation / breaking API change) · HIGH (serialization type change) · MEDIUM (unmapped new required env key) · LOW (missing deprecation doc)
    
    **Reporting:** call `ReportFindings` when callable — `file`/`line` MUST be the defect site, never the enclosing function; an unresolvable line reports your best guess, named imprecise in the wrap-up — **never dropped, never faked.** Severity prefixed in `summary` (e.g. `[HIGH] …`), ranked most-severe first, SUSPECTED as `verdict: PLAUSIBLE`; chat then carries only the wrap-up line (counts · coverage gaps · overflow past 32 · any imprecise-line findings) + the fix menu, never a restatement of findings. Not callable → the table above, unchanged. An Apply-fixes click = consent to the safe-fix class only — gated the same as this skill's own fix-mode (Hook Context needs an interactive session, per the Hook Context rule below) — composing with (never bypassing) the fix-mode discipline. **After any fix round, re-report the same findings with `outcome: fixed`/`skipped`/`no_change_needed` — skipping this leaves the round UNFINISHED.**
    
    ## Escalation — Scope & Model Quality
    
    Tiers are **capability targets**, not platform commands — resolve each to your host's nearest lever. No lever for one? **Degrade gracefully — never fake parallelism you can't do**; escalate via model tier + reasoning depth instead.
    
    | Level | Intent | Capability target | Cost |
    |---|---|---|---|
    | **Light** | Spot contract check, key interfaces only | Cheapest model · single agent, no sub-agents. | Low |
    | **Standard** | Balanced drift audit, multi-category | Balanced model · raised reasoning · sub-agents per category **only if your platform runs concurrent workers** (else single-agent). | Balanced |
    | **Heavy** | Full 5-category audit + adversarial compatibility verify | Most capable model + largest context · deepest reasoning · max sub-agent fan-out **if supported** · adversarial cross-check where available. | High |
    
    Per-platform Heavy levers + Heavy-run durability: read `references/escalation.md` before a Heavy run. No concurrent fan-out on your host → escalate by model + reasoning only.
    
    **Agent Context (interactive):** score the tier rubric, then call `ask_question` once with the 3 tiers — the pick marked `✓`, score shown, labels localized — and wait for the choice before starting. `ask_question` = your platform's question tool: Claude Code `AskUserQuestion` · Cline `ask_question` · Copilot `askQuestions` · Gemini CLI `ask_user` (business-tier product; individual tiers ended 2026-06-18 → Antigravity CLI) · Codex `request_user_input` · Cursor/Devin Desktop (ex-Windsurf)/Antigravity built-in prompts; none → numbered text menu.
    
    **Tier rubric (deterministic):** +1 each — ① >20 files or whole-repo/cross-module reach ② >2 of this skill's categories relevant ③ release/security/pre-ship context ④ findings will drive code changes. **0–1 Light · 2–3 Standard · 4 Heavy.** **Freshness cap:** scope already audited ≥Standard this session → cap at Light (re-auditing fresh ground wastes tokens; scope to what changed). **Default tier:** honor `.coalmine.json` `defaultTier` unless the user requests a tier for that run — an explicit request overrides everything.
    
    **Hook Context (auto-triggered):** auto-Light, no tier question, no sub-agents — report first. Interactive session (a user is present) → follow this skill's own Fix mode section, if it defines one, for what to offer after the report; non-interactive → report-only. Where a Fix mode section exists, never fix without a chosen option.
    
    **Entanglement:** after the report, if confirmed findings fall in another canary's domain, offer it once via `ask_question` (one line, max one offer): perf/N+1 → scale-canary · contract/serialization/config → drift-canary · failure-path/retry → resilience-audit · logging/metrics → telemetry-canary · coupling/DI → testability-canary · dependency/CVE → supply-chain-audit · unverified version-sensitive claim → source-grounding · missing/stale rule → gold-standard.
    
    **Self error-report:** if this skill misbehaves (contradictory instruction, broken procedure, wrong finding class), OFFER to file it at https://github.com/HetCreep/CoalMine/issues/new/choose with a user-reviewed summary — never auto-submit, never include unapproved code or paths.
    
    

Comments (0)

Sign in to join the conversation.

No comments yet.

Reviews (0)

No reviews yet.

Related