Understand a repository before deciding whether to adopt it.
First verify identity, license, maintenance evidence, release chain, and supply chain exposure. By default, do not clone, install, build, or run any code from the repository.
Five checkpoints that turn "looks good" into a verifiable judgement.
Each step uses only public metadata or user-supplied materials, and makes clear the evidence time, gaps, and confidence level of conclusions.
IDENTITY
Confirm repo identity
Pin the repo URL, organization, default branch, release page, and current observation time to prevent confusion from same-name projects or mirrors.
Deliverables
Identity card and observation snapshot
Confirmation point
Object is unique and source is traceable
LICENSE
Review license boundaries
Distinguish licenses for source code, models, data, fonts, sample assets, and generated content; don't use one LICENSE file to endorse all assets.
Deliverables
License matrix and unknowns
Confirmation point
No obvious license conflicts for intended use
MAINTENANCE
Assess maintenance quality
Observe release cadence, issue responsiveness, contributor concentration, changelogs, and security advisories; don't use a single star count as a proxy for maintenance evidence.
Deliverables
Maintenance evidence table
Confirmation point
Maintenance risk and dependency responsibility acceptable
SUPPLY CHAIN
Identify supply chain risks
Read-only checks of dependency locking, install hooks, binaries, download-and-execute behavior, credential requirements, and external service boundaries.
Deliverables
Risk and manual confirmation points
Confirmation point
High-risk capabilities blocked or isolated
DECISION
Form an adoption decision
Separate facts, inferences, unknowns, and recommendations; give pilot scope, stop conditions, and next review date.
Deliverables
Adopt, pilot, observe, or reject conclusion
Confirmation point
Conclusion reproducible by another reviewer
FIXED RELEASE
This is the pinned version to download
FORMWEFT clean-room original documentation Skill. MIT covers only this package's original documentation; it does not grant licenses for third-party repos, models, data, or assets, nor executes the code of the due-diligence target.
Not sure where to start? Copy a learning request.
You can download this reviewed version's resource package. If it includes SKILL.md, provide it and the related documentation to your AI tool; first read and check the materials and usage boundaries, and do not run anything automatically.
Prepare assets: start with fictional or de-identified examples.
Read the boundaries: confirm dependencies, inputs, outputs, and human checkpoints.
Review outputs: keep source and failure records before deciding to pilot.
You can also select the text to copy directly; read it first before executing.
This version has been reviewed.1.0.0
Written independently clean-room based on directory topics; no licensed Feishu original package copied or redistributed. The pinned ZIP has passed structural validation, offline static scanning, and per-file manual review; no scripts, dependencies, install hooks, mandatory network access, or automatic remote operations.
Maintainer
FORMWEFT
License
MIT
Source type
Clean-room original rebuild
Network permission
On-demand online
Local programs
None; if online verification is needed, the user must approve sites and scope
Review date
2026/09/05
Review scope
static
passed
skillValidator
passed
scripts
0
dependencies
0
network
optional
humanReview
completed
cleanRoom
completed
sourceTextReused
false
SHA-256 · current download package4e504fca44e4db0102418013427572a7ad4b987ed84d92d37f8772e7994562d3
Ready to bring open-source capabilities into your enterprise system?
Tell us the candidate repo, target process, data classification, deployment environment, and responsible person, and we can extend the read-only diligence into a controlled pilot and internal handover.