skill-validator

Prüfen · 55
Im Registry indexiert

Validate SKILL.md files against the Agent Skills spec and Claude Code extensions. Run on new or modified skills before committing.

Verified installs0
Stars33
Version1.0.0
Qualität57/100 · Vielversprechend
Vertrauen55/100 · Do not auto-install
Audit70/100 · Prüfung nötig

Asset-Profil

Recherche und Wissensarbeit

Deep research, source comparison, literature review, RAG, knowledge search, and reports.

Bereich ansehen

Szenario

Recherche-Agents

I need my agent to research a topic, compare sources, and produce a concise report.

Agent-Fit

Claude Code + OpenAI Agents + CLI

Geeignet für Codex, Claude Code, Cursor, CLI oder benutzerdefinierte Agents.

Installieren

Bereit

npx skills add shipshitdev/skills --skill skill-validator

Wartung

Aktuell

2 Tage seit dem letzten Push

Risiko

Prüfung nötig

Lizenz ist unklar

GitHub-Qualität

33

57/100 Qualität · 63/100 Vertrauen

Abdeckungs-Tags

RechercheRecherche-Agentsagent-skill

Review-Notizen

Lizenz ist unklar · Permission surface may require sandboxing

Agent-Adoptionskarte

Vertrauen, Audit und Installationsbereitschaft auf einen Blick

Diese Werte kombinieren öffentliche Repository-Metadaten, OpenAgentSkill-Reviewsignale, Wartungsaktualität und Installationsbereitschaft. Sie helfen bei der Vorauswahl, ersetzen aber keine menschliche Prüfung.

Qualität

Vielversprechend
57

Useful candidate, but compare it with alternatives before adopting.

Vertrauen

Do not auto-install
55

Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.

Audit

Prüfung nötig
70

Maschinenlesbare Prüfung von Installationsbereitschaft, Sicherheitsmetadaten, Wartung und Akzeptanzrisiko.

OpenAgentSkill Trust Score v5

Menschliche Prüfung vor Installation

Choose a stronger alternative or inspect the source manually before any install attempt.

CodexClaude CodeCursorOpenAgentSkill CLI

Stars

33 GitHub-Stars

Repository-Aktivität

33 Stars und 3 Forks

Wartung

2 Tage seit dem letzten Push

Lizenz

Unbekannt

Installieren

npx skills add shipshitdev/skills --skill skill-validator

Installationssicherheit

Standard-Paket- oder Laufzeit-Installationspfad

Berechtigungsfläche

shell or command execution, filesystem or document access

Agent-Ergebnisse

Noch keine Agent-Ergebnisdaten

Dokumentation

Starker README/SKILL.md-Kontext

Risikoübersicht

Vor Produktion prüfen

  • Repository license is unknown, which may affect redistribution clarity.
  • Lizenz ist unklar
  • Low GitHub adoption signal
  • Quality score needs review

Installationsbereitschaft

Installationspfad verfügbar

  • Installationspfad ist verfügbar
  • Repository-Belege sind verfügbar
  • Lizenz ist unklar
  • Noch keine Agent-Proven-Ergebnisbelege

Agent-lesbare Metadaten

Maschinenlesbare Entscheidungsdaten für diesen Skill.

Nutze diesen Block oder das eingebettete JSON, um zu entscheiden, ob ein Agent diesen Skill installieren, eine Alternative wählen oder zuerst menschliche Prüfung anfordern soll.

JSON öffnen

Geeignete Aufgaben

  • Local desktop-Workflows
  • Claude-Code-Teams
  • builders willing to evaluate younger projects
  • Navigate local resources

Geeignete Agents

CodexClaude CodeCursorOpenAgentSkill CLIOpenAI AgentsCLI

Installationsentscheidung

Befehl
npx skills add shipshitdev/skills --skill skill-validator
Richtlinie
Prüfen
Menschliche Prüfung
Ja

Vertrauen und Risiko

Vertrauen
55/100
Audit
70/100
Risikoebene
Prüfung nötig

Ergebnis-Loop

Endpoint
/api/agent/outcome
Event-ID
resolve
Ergebnisse
5

Installationsbefehl

npx skills add shipshitdev/skills --skill skill-validator

Nicht verwenden, wenn

  • Teams, die ein vom Anbieter unterstütztes SLA benötigen
  • production agents without a repository review
  • Low GitHub adoption signal
  • Repository license is unknown, which may affect redistribution clarity.
  • No OpenAgentSkill engagement data yet

Agent-Sicherheit v2

38/100 · Automatische Installation vermeiden

ExperimentellPrüfen

Sparse or mixed signals. Useful for discovery, but not for autonomous installation.

Test manually in an isolated workspace and compare against safer alternatives.

Per API auflösen

Hoch

Shell- oder Befehlsausführung

Die Skill-Metadaten verweisen auf Terminal-, CLI-, Shell-, Subprozess- oder Befehlsausführungs-Workflows.

Mittel

Netzwerkzugriff

Die Skill ruft wahrscheinlich Remote-Seiten, APIs, Repositories oder externe Dienste ab.

Mittel

Dateisystemzugriff

Die Skill kann Projektdateien, Dokumente, generierte Artefakte oder den lokalen Arbeitsbereich lesen oder schreiben.

Mittel

Datenbankzugriff

Die Skill kann Schemata prüfen, Datenbanken abfragen oder mit persistenten Speichern arbeiten.

  • Hinweise auf Hochrisiko-Berechtigungen: Shell- oder Befehlsausführung
  • Lizenz ist unklar

Installationsziele

Diesen Skill im Agent-Workflow installieren

Über den öffentlichen Endpunkt erhältst du Befehl, Sicherheitscheckliste, Ziel-Prompts und kanonische Links.

skill install

OpenAgentSkill CLI

Resolve policy, run the source installer safely, and report a verified install receipt.

$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install shipshitdev-skill-validator

Agent-Auflösungsplan

Lass einen Agent die Eignung vor der Installation prüfen.

Die Resolve API liefert die beste Skill, Alternativen, Sicherheitsrichtlinien, Auditnotizen, Installationsziel und einen direkt nutzbaren Prompt.

Textplan öffnen

Agent sollte prüfen

  • Task fit and alternatives from Resolve API.
  • Audit score, trust score, and safety policy warnings.
  • Install target compatibility for Codex, Claude Code, Cursor, or CLI.

Prompt kopieren

Task: Use skill-validator in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20skill-validator%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/shipshitdev-skill-validator/install
Install command: npx skills add shipshitdev/skills --skill skill-validator
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.

Agent-Übergabe

Gib dem Agent den Installationspfad, nicht noch ein Verzeichnis.

Über den öffentlichen Endpunkt erhältst du Befehl, Sicherheitscheckliste, Ziel-Prompts und kanonische Links.

Installations-API öffnen

Agent-Prompt

Use skill-validator for this task. Review https://www.openagentskill.com/api/skills/shipshitdev-skill-validator/install, then install with: npx skills add shipshitdev/skills --skill skill-validator

Registry-Metadaten

Agent-lesbares Profil für die automatische Skill-Auswahl.

Die Registry API stellt Entscheidungs-, Vertrauens-, Audit-, Use-Case- und Installationssignale ohne UI-Scraping bereit.

Manifest öffnen

Agent-Fit

56/100

Local desktop

Plattformen

Claude Code, OpenAI Agents

Audit-Bericht

Prüfung nötig · 70/100

Maschinenlesbare Prüfung von Installationsbereitschaft, Sicherheitsmetadaten, Wartung und Akzeptanzrisiko.

Audit-Bericht ansehenEval-Bericht ansehen

Agent-Entscheidungspanel

Needs validation for Local desktop

Do a manual repository review before adding this to an agent workflow.

56
Bereitschaft
Prüfen
Phase

Rolle im Stack

Validierung nötig

Primäre Eignung

Local desktop

Vertrauenslabel

Manuelle Prüfung nötig

Installationspfad

Befehl bereit

Verwenden wenn

  • Local desktop-Workflows
  • Claude-Code-Teams
  • builders willing to evaluate younger projects

Evidenz

  • recent repository activity
  • install command or GitHub repo available
  • Qualitätsprofil 57/100

zuerst prüfen

  • Low GitHub adoption signal
  • Repository license is unknown, which may affect redistribution clarity.
  • No OpenAgentSkill engagement data yet

Implementierungspfad

  1. 1Installieren Sie es in einem Sandbox-Agent und führen Sie eine Local desktop-Aufgabe vollständig aus.
  2. 2Compare output quality, latency, and failure behavior against at least one alternative.
  3. 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.

Vertrauensprofil

Do not auto-install

Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.

55
OpenAgentSkill Trust Score

GitHub-Akzeptanz

Prüfen

33 GitHub-Stars

Star-/Fork-Aktivität

Prüfen

33 Stars und 3 Forks; Issue-Aktivität ist in den aktuellen Metadaten nicht verfügbar

Aktuelle Wartung

Bestanden

2 Tage seit dem letzten Push

Lizenzklarheit

Prüfen

Unbekannt

Positive Signale

  • KI-Prüfung genehmigt
  • Installationspfad ist verfügbar
  • Repository-Belege sind verfügbar
  • Kürzlich gewartetes Repository
  • Der Installationsbefehl weist kein offensichtliches Hochrisikomuster auf
  • Ergebniszyklus ist bereit, benötigt aber den ersten echten Agent-Lauf

Vor Installation prüfen

  • Repository license is unknown, which may affect redistribution clarity.
  • Lizenz ist unklar
  • Low GitHub adoption signal
  • Quality score needs review
  • Permission surface needs review: shell or command execution, filesystem or document access
  • GitHub adoption: 33 GitHub stars
  • Stars/forks activity: 33 stars, 3 forks; issue activity unavailable in current metadata
  • License clarity: Unknown
  • Permission surface: shell or command execution, filesystem or document access
  • Noch keine echten Agent-Ergebnisberichte
  • Vor unbeaufsichtigter Installation ist menschliche Prüfung erforderlich

Empfohlene Aktion

Choose a stronger alternative or inspect the source manually before any install attempt.

Qualitätsprofil

Vielversprechend Kandidat für Agent-Workflows

Useful candidate, but compare it with alternatives before adopting.

57
GitHub-Stars
33
Aktualität
vor 2 Tagen
Installationsbereit
Ja
Lizenz
Unbekannt
Vor Installation prüfen: Low GitHub adoption signal · Repository license is unknown, which may affect redistribution clarity.

Workflow-Eignung

Diese Skill in diesen Szenarien nutzen

Workflow-Eignung

Zum vollständigen Workflow hinzufügen

Alternativen-Shortlist

Vor Installation vergleichen

Similar skills that may fit this task.

Alle vergleichen

Übersicht

--- name: skill-validator description: | Validate SKILL.md files against the Agent Skills spec and Claude Code extensions. Run on new or modified skills before committing. metadata: internal: true version: "1.0.3" tags: "validation, skills, spec-compliance, quality" ---

# Skill Validator

Validate SKILL.md files against the Agent Skills specification and Claude Code extensions.

## When to Run

- After creating a new skill - After modifying a skill's SKILL.md frontmatter - Before committing skill changes - During periodic repo audits

## Validation Rules

### Required Fields (Agent Skills Spec)

Every SKILL.md must have YAML frontmatter with:

- `name` — kebab-case, matches directory name - `description` — 1-3 sentences, under 1024 chars, starts with verb or domain noun

### Metadata Block

`version` and `tags` must be inside `metadata:`, never top-level:

```yaml # CORRECT metadata: version: "1.0.0" tags: "react, performance, optimization"

# WRONG — top-level version version: 1.0.0

# WRONG — tags as YAML list metadata: tags: - react - performance ```

### Forbidden Fields

These are not part of any spec:

- `auto_activate` / `auto_trigger` — removed in 2026-04 migration - `risk` — not in Agent Skills or Claude Code specs

### Claude Code Extensions (Optional)

Valid extension fields (must match `allowed_fields` in `scripts/validate-skill-sync.sh`):

| Field | Purpose | |-------|---------| | `when_to_use` | Extra trigger phrases appended to `description` | | `disable-model-invocation` | Prevent auto-triggering (for destructive skills) | | `user-invocable` | `false` hides from the `/` menu | | `allowed-tools` | Auto-approve **allowlist** (not a sandbox — unlisted tools stay callable) | | `disallowed-tools` | Removes tools from the pool while active (the actual block mechanism) | | `argument-hint` | Autocomplete hint for expected arguments | | `compatibility` | Environment prerequisites (packages, network, target agent) | | `context` | `fork` for subagent isolation | | `agent` | Subagent type when `context: fork` | | `hooks` | Lifecycle hooks scoped to the skill | | `paths` | ⚠️ Broken upstream (#49835) — flag if present | | `shell` | `bash` (default) or `powershell` |

### Forbidden Fields (updated)

- `auto_activate` / `auto_trigger` — removed in 2026-04 migration - `risk` — not in any spec - `metadata.triggers` — duplicate activation metadata; put trigger phrases in `description` or `when_to_use` - `model` / `effort` — recognized by Claude Code but owned by app/session configuration, not public reusable skills - Any top-level field not in the tables above → "Unsupported top-level frontmatter field"

### Content Rules

- No hardcoded `/workspace/` paths - No tool names in instructions (say "search for" not "use Grep") - Imperative/infinitive style ("Configure X" not "You should configure X") - Code blocks use real backtick fences, not escaped `\`\`\`` - **No concrete model names** in body, `references/`, or `scripts/` — reject tier+version IDs (`claude-3-7-sonnet-20250219`, `claude-opus-4.5`, `gpt-5.5`), dated snapshots, and bare family names used as routing keys. Exception: orchestrator skills may name **capability tiers** in prose. See [skill-standards.md → Model references](../memory/system/skill-standards.md). - **No harness-owned execution parameters** in skills, commands, or routine templates. Apply [execution-boundary.md](../memory/system/execution-boundary.md). - **Routine templates** follow [routine-standards.md](../memory/system/routine-standards.md). Run `python3 scripts/audit-routines.py` to detect duplicate bodies and app-parameter leakage without printing prompt or configuration values. - **Provenance (derived skills only):** when `metadata.source` is set, `metadata.last_synced` and a README `## Upstream` section are required (enforced by `check_provenance()`). In-house skills need no provenance fields.

## Validation Process

1. Read the SKILL.md frontmatter 2. Check `name` matches parent directory name 3. Check `description` exists and is under 1024 chars 4. Check `description` plus `when_to_use` is under 1536 chars 5. Check `plugin.json` description is present and under 100 chars 6. Check `version`/`tags` are NOT top-level (must be inside `metadata:`) 7. Check for forbidden fields (`auto_activate`, `auto_trigger`, `risk`, `model`, `effort`, any field not in the extension tables) 8. Check for escaped backtick fences in content 9. Validate frontmatter value types: `allowed-tools` is a scalar, `metadata.version` and `metadata.tags` are quoted scalars, and `metadata` is a map 10. Reject duplicate `metadata.triggers`; keep activation guidance in `description` or `when_to_use` 11. Check for hardcoded paths (`/workspace/`, project-specific paths) 12. Grep body + `references/` + `scripts/` for concrete model names (`claude-*`, `gpt-*`, `sonnet`/`opus`/`haiku` used as IDs); allow only capability-tier prose in orchestrator skills 13. Warn when skills, commands, or templates set harness-owned execution parameters 14. Warn when a side-effecting skill lacks both `disable-model-invocation: true` and an explicit `Confirmation Required` gate 15. Check prose routing references across the body, excluding frontmatter and code fences, and flag missing local skills 16. Check provenance for derived skills: if `metadata.source` is set, require `metadata.last_synced` and a README `## Upstream` section 17. Run `bunx markdownlint-cli` on the file 18. Run `./scripts/validate-skill-sync.sh` for cross-validation

## Quick Validation Command

```bash # Single skill bunx markdownlint-cli skills/<name>/SKILL.md skills/<name>/references/*.md

# All skills bunx markdownlint-cli --ignore bundles --ignore dist "**/*.md"

# Sync validation ./scripts/validate-skill-sync.sh ```

Technische Details

Version
1.0.0
Lizenz
Unknown
Letzte Aktualisierung
23. Aug. 2026
Veröffentlicht
23. Aug. 2026

Entscheidungsübersicht

Validierung nötig

56
Bereit
Prüfen
Phase

recent repository activity

Audit

Installationsprüfung

Installations- und Adoptionsprüfung

70
Prüfung nötig
Sicherheit
66/100
Wartung
100/100
Installieren
92/100
Vollständiges Audit öffnenEval-Bericht ansehen

Von Agent belegte Evidenz

Von Agent belegte Evidenz

Ergebnisberichte nach Resolve, Prüfung, Installation und einem begrenzten Lauf.

0
Belegt
Needs first agent runAuto-Installation: zuerst prüfenLetzter: Unbekannt
Erfolgsrate
Letzter Fehler
Ergebnisse
0
Ausgabequalität
Fehlgeschlagen
0
Nicht relevant
0
Installationen
0
Durch Risiko blockiert
0
Einrichtung erforderlich
0
Produktion
0

Noch keine Agent-Ergebnisdaten. Der erste Lauf kann Erfolg, Einrichtungsbedarf, Risikoblockaden, Fehler oder Irrelevanz über /api/agent/outcome melden.

Installieren

Zum Agent-Workflow hinzufügen

Kostenlos und Open Source. Bericht vor der Installation in Produktions-Agents prüfen.

Wachstums-Loop

Share-Kit

X

Szenariobasierter Entwurf für skill-validator, bereit für einen manuellen X-Post.

Kuratorenhinweis
skill-validator: Validate SKILL.md files against the Agent Skills spec and Claude Code extensions. Run on new...

33 stars

https://www.openagentskill.com/skills/shipshitdev-skill-validator?ref=x
X-Entwurf öffnen
Optionale Antwort mit Installationsbefehl
Listing + install path for skill-validator:
https://www.openagentskill.com/skills/shipshitdev-skill-validator?ref=x

Install: npx skills add shipshitdev/skills --skill skill-validator
Antwortentwurf öffnen

Quelle des Eintrags

Registry-indexiert

Beanspruchbar

Dieser Eintrag wurde aus öffentlichen Quellen indexiert und ist erst nach Genehmigung eines Maintainer-Anspruchs offiziell.

Ersteller
shipshitdev
Indexiert von
OpenAgentSkill Community-Index

Die Zuordnung verlinkt auf das öffentliche Repository oder Creator-Profil. Creator können den Eintrag beanspruchen, um Eigentümersignale zu aktualisieren.

Diesen Skill beanspruchen

Eigentümeranspruch

Diesen Skill-Eintrag beanspruchen

Dieser Registry-indexiert-Eintrag wird shipshitdev zugeschrieben, ist aber noch nicht offiziell markiert. Beanspruche ihn, um ein verifiziertes Eigentümersignal hinzuzufügen und künftige Launch-, Installations- und Audit-Updates vertrauenswürdiger zu machen.

Creator-Backlink-Kit

Evidenz-Badges in deine README einfügen

Zeige den kanonischen Eintrag, aktuelle Vertrauens- und Audit-Signale sowie echte Agent-Proven-Evidenz dort, wo Entwickler das Repository bewerten.

[![Listed on OpenAgentSkill](https://www.openagentskill.com/api/badge/shipshitdev-skill-validator?metric=listed&label=Listed)](https://www.openagentskill.com/skills/shipshitdev-skill-validator)
[![OpenAgentSkill Trust](https://www.openagentskill.com/api/badge/shipshitdev-skill-validator?metric=trust&label=Trust)](https://www.openagentskill.com/skills/shipshitdev-skill-validator)
[![OpenAgentSkill Audit](https://www.openagentskill.com/api/badge/shipshitdev-skill-validator?metric=audit&label=Audit)](https://www.openagentskill.com/skills/shipshitdev-skill-validator/audit)
[![Agent Proven](https://www.openagentskill.com/api/badge/shipshitdev-skill-validator?metric=proven&label=Agent%20Proven)](https://www.openagentskill.com/skills/shipshitdev-skill-validator)

Autor

S

shipshitdev

@shipshitdev

Gesundheitssignale

GitHub-Stars
33
Qualitätswert
34/100
Letzter GitHub-Push
20. Aug. 2026
Framework-Hinweise
Unbekannt
OpenAgentSkill-Aufrufe
0
Installationskopien
0
Externe Klicks
0

Community-Signal

Teile mit, ob dieser Skill für deinen Agent-Workflow nützlich ist. Zusammengefasstes Feedback verbessert das Ranking im Laufe der Zeit.

Vertrauen & Sicherheit

Do not auto-install

55
  • GitHub-Akzeptanz33 GitHub-StarsPrüfen
  • Star-/Fork-Aktivität33 Stars und 3 Forks; Issue-Aktivität ist in den aktuellen Metadaten nicht verfügbarPrüfen
  • Aktuelle Wartung2 Tage seit dem letzten PushBestanden
  • LizenzklarheitUnbekanntPrüfen
  • README/SKILL.md-VollständigkeitMetadaten enthalten ausreichend Nutzungs- und Workflow-KontextBestanden
  • Abhängigkeits-/Laufzeitrisikocommand execution surface, database surfaceInfo