Member card of the skills catalog optimization program #14292 (maintainer mandate 2026-09-02, verbatim: 「审核所有的 skills,进行全面的优化。」). Filed by the skills lane seat (session session_01LraLgQVGq8egUwfYZpbYt1). Read-only audit at objectstack origin/main a59f78d. The full findings table is the audit record: the dev posts it verbatim as the first comment on this card at claim time (seat scratchpad audit/objectstack-pm-dispatch/findings.md).
⚠️ Fence: this is the PUBLISHED process skill. .claude/skills/pm-dispatch/** and .claude/agents/os-dev.md are a separate corpus under audit #13597 — read them only as the comparison oracle, ⛔ never edit them in this flight, ⛔ never in the same PR.
Audit summary
One file, SKILL.md, 1,086 lines, 14,549 tokens, headroom 0 — 7.7% of the bundle, the 2nd-largest published SKILL.md, 1.75× the other process skill. Teaches no ObjectStack surface (0 TypeScript fences). Customer decision points covered: 5 (label state machine; safe claim; dispatch with a binding template; review-against-GitHub and land; escalate vs decide) ≈ 2,900 tokens per decision. Customer-inert or duplicated text measured at 4,445 tokens (30.6%) before any restructure. Verdict RESTRUCTURE: zero progressive disclosure, zero evals, two blocks duplicated inside the file (the report JSON at 869-882 / 894-908; the sanitizer trap at 346-365 / 884-888), a 2,376-token verbatim paste-block paid in every session, and a second job (upstream reporting) restating objectstack-platform :59-70.
Top findings
| id |
span |
proposal |
delta |
| PMD-B-01 |
SKILL.md:729-891, 916-986 |
MOVE-TO rules/dev-template.md (DEFERRED, #14296 items 1+4) |
−3,258 from entry |
| PMD-C-01 |
SKILL.md:916-986 vs objectstack-platform :59-70 |
DELETE the upstream-reporting job; keep ≤250-token residue pointing at objectstack-platform |
−882 |
| PMD-E-05 |
SKILL.md:987-1033 |
REWRITE-AS-CONSTRUCT — shard registry conclusion is one line for a single-repo project |
−580 |
| PMD-E-02 |
SKILL.md:416-452 |
RETIRE-SURFACE — "N independent implementations" is the platform's compiler problem, not an app's |
−565 |
| PMD-E-03 |
SKILL.md:591-618 |
DELETE two non-escalation bullets (ADR-0049 "arm"/governance shapes) |
−508 |
| PMD-D-01 |
SKILL.md:192-217 |
REWRITE-AS-CONSTRUCT — sweep rationale, cross-seat producers, anecdote |
−380 |
| PMD-D-02 |
SKILL.md:507-528 |
REWRITE-AS-CONSTRUCT — the 8-card baseline printed and disclaimed |
−290 |
| PMD-D-04 |
SKILL.md:654-706 vs 826-857 |
REWRITE-AS-CONSTRUCT — four-axis frame stated twice |
−450 (MED) |
| PMD-E-04 |
SKILL.md:769-786 |
REWRITE-AS-CONSTRUCT — design spec of a lock script the customer does not have |
−250 |
| PMD-B-03 |
SKILL.md:346-357 |
DELETE sanitizer specimens; rules at 359-365 carry the decision |
−200 |
| PMD-B-02 |
SKILL.md:894-908 |
DELETE — the same report JSON printed twice |
−115 |
| PMD-D-03 |
SKILL.md:483-495 |
DELETE check-in anecdote; keep the two rules at 496-506 |
−170 (MED) |
| PMD-A-01 |
SKILL.md:10-14 |
DELETE the "report a platform bug" trigger from the description |
−30 |
| PMD-G-01 |
SKILL.md:557-559 vs 1051 |
DELETE — "the PM's own tooling PRs" contradicts "The PM writes no files" |
−25 |
Drift vs the internal contract (sync in this flight, paid by the deletions above)
- PMD-F-01
:455-457 "a lossless channel" — the internal contract requires the report TWICE, GitHub first, in both modes, first line the literal plaintext os-dev-report (⛔ not an HTML comment), because a container restart killed three devs mid-final-message. Also a falsehood: :456-457 is contradicted 17 lines later at :474-475.
- PMD-F-02 the template never asks the dev to re-check the issue's premises and the report has no
premise_still_valid; internally a no-PR report with premise_still_valid: false is a first-class deliverable.
- PMD-F-03
grep -c stash = 0, yet the template ships the exact topology the trap lives in (worktree-first + "parallel agents share ONE container"); both repos carry the ban at Prime-Directive level.
- PMD-F-04/F-05 the claim shape omits the
Session: line (branch-only identity under-determines in cloud mode); :367-369 asserts devs push early while the template pushes fourth — the reclaim predicate can fire against a live agent. Make the template push the empty branch first.
- Falsehood
:1036-1039 "the template enforces … a container-wide verification lock" — the template delegates the mechanism to the host project; should read requires.
Flight scope
IMPLEMENT (same-file, shrink-only): all rows above except PMD-B-01 and PMD-H-01; the four drift syncs (paid by PMD-E-02 / PMD-E-04 / PMD-B-02 as the auditor sized them); PMD-C-01 as delete + ≤250-token residue pointing at objectstack-platform SKILL.md:59-70; the description trigger edit (regenerate skills/README.md).
DEFER (pending #14296 items 1 and 4): PMD-B-01 (split the template into rules/dev-template.md), PMD-H-01 (evals).
Flight constraints (binding)
- ONE draft PR, first line
Fixes #<this card>; governed ⇒ stays draft; review requests are the seat's step.
- Token ratchet:
SKILL.md may not grow; additions paid by deletions in the same file; ⛔ re-wrap is not payment; ⛔ no ceiling raise; ⛔ no new files; ⛔ do not touch the ratchet script.
- ⛔ Never edit another package's files; frontmatter edits ⇒ regenerate
skills/README.md (pnpm --filter @objectstack/spec gen:skill-docs).
- Gates:
node scripts/check-skills-token-ratchet.mjs, pnpm check:skill-compatibility, pnpm check:skill-identifier-liveness, plus node scripts/pm/dispatch-gates.mjs --commands <changed paths>; record the head sha.
- PR body: per-item 落点 | before | after list keyed by finding id; token delta;
Clause-②: no (no contract surface).
Refs: #14292 · #14296 · #13597 (the internal corpus, separate audit).
Member card of the skills catalog optimization program #14292 (maintainer mandate 2026-09-02, verbatim: 「审核所有的 skills,进行全面的优化。」). Filed by the skills lane seat (session
session_01LraLgQVGq8egUwfYZpbYt1). Read-only audit at objectstackorigin/maina59f78d. The full findings table is the audit record: the dev posts it verbatim as the first comment on this card at claim time (seat scratchpadaudit/objectstack-pm-dispatch/findings.md)..claude/skills/pm-dispatch/**and.claude/agents/os-dev.mdare a separate corpus under audit #13597 — read them only as the comparison oracle, ⛔ never edit them in this flight, ⛔ never in the same PR.Audit summary
One file,
SKILL.md, 1,086 lines, 14,549 tokens, headroom 0 — 7.7% of the bundle, the 2nd-largest publishedSKILL.md, 1.75× the other process skill. Teaches no ObjectStack surface (0 TypeScript fences). Customer decision points covered: 5 (label state machine; safe claim; dispatch with a binding template; review-against-GitHub and land; escalate vs decide) ≈ 2,900 tokens per decision. Customer-inert or duplicated text measured at 4,445 tokens (30.6%) before any restructure. Verdict RESTRUCTURE: zero progressive disclosure, zero evals, two blocks duplicated inside the file (the report JSON at 869-882 / 894-908; the sanitizer trap at 346-365 / 884-888), a 2,376-token verbatim paste-block paid in every session, and a second job (upstream reporting) restating objectstack-platform:59-70.Top findings
SKILL.md:729-891,916-986rules/dev-template.md(DEFERRED, #14296 items 1+4)SKILL.md:916-986vs objectstack-platform:59-70SKILL.md:987-1033SKILL.md:416-452SKILL.md:591-618SKILL.md:192-217SKILL.md:507-528SKILL.md:654-706vs826-857SKILL.md:769-786SKILL.md:346-357SKILL.md:894-908SKILL.md:483-495SKILL.md:10-14SKILL.md:557-559vs1051Drift vs the internal contract (sync in this flight, paid by the deletions above)
:455-457"a lossless channel" — the internal contract requires the report TWICE, GitHub first, in both modes, first line the literal plaintextos-dev-report(⛔ not an HTML comment), because a container restart killed three devs mid-final-message. Also a falsehood::456-457is contradicted 17 lines later at:474-475.premise_still_valid; internally a no-PR report withpremise_still_valid: falseis a first-class deliverable.grep -c stash= 0, yet the template ships the exact topology the trap lives in (worktree-first + "parallel agents share ONE container"); both repos carry the ban at Prime-Directive level.Session:line (branch-only identity under-determines in cloud mode);:367-369asserts devs push early while the template pushes fourth — the reclaim predicate can fire against a live agent. Make the template push the empty branch first.:1036-1039"the template enforces … a container-wide verification lock" — the template delegates the mechanism to the host project; should readrequires.Flight scope
IMPLEMENT (same-file, shrink-only): all rows above except PMD-B-01 and PMD-H-01; the four drift syncs (paid by PMD-E-02 / PMD-E-04 / PMD-B-02 as the auditor sized them); PMD-C-01 as delete + ≤250-token residue pointing at objectstack-platform
SKILL.md:59-70; the description trigger edit (regenerateskills/README.md).DEFER (pending #14296 items 1 and 4): PMD-B-01 (split the template into
rules/dev-template.md), PMD-H-01 (evals).Flight constraints (binding)
Fixes #<this card>; governed ⇒ stays draft; review requests are the seat's step.SKILL.mdmay not grow; additions paid by deletions in the same file; ⛔ re-wrap is not payment; ⛔ no ceiling raise; ⛔ no new files; ⛔ do not touch the ratchet script.skills/README.md(pnpm --filter @objectstack/spec gen:skill-docs).node scripts/check-skills-token-ratchet.mjs,pnpm check:skill-compatibility,pnpm check:skill-identifier-liveness, plusnode scripts/pm/dispatch-gates.mjs --commands <changed paths>; record the head sha.Clause-②: no(no contract surface).Refs: #14292 · #14296 · #13597 (the internal corpus, separate audit).