创作者 · shipshitdev
最近更新 · 2026年8月23日
skill-validator
Validate SKILL.md files against the Agent Skills spec and Claude Code extensions. Run on new or modified skills before committing.
Do not auto-install
安装目标
Codex 安装提示词
Install the "skill-validator" agent skill from https://github.com/shipshitdev/skills/tree/master/.agents/skills/skill-validator. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Validate SKILL.md files against the Agent Skills spec and Claude Code extensions. Run on new or modified skills before committing. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"shipshitdev-skill-validator","task":"Install skill-validator","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.供给资产档案
研究与知识工作
Deep research, source comparison, literature review, RAG, knowledge search, and reports.
场景
研究 Agent
I need my agent to research a topic, compare sources, and produce a concise report.
适配 Agent
Claude Code + OpenAI Agents + CLI
适用于 Codex、Claude Code、Cursor、CLI 或自定义 Agent。
安装
就绪
npx skills add shipshitdev/skills --skill skill-validator
维护状态
新鲜
距上次推送 3 天
风险
需审查
许可证不清晰
GitHub 质量
33
57/100 质量 · 63/100 信任
覆盖标签
审查说明
许可证不清晰 · Permission surface may require sandboxing
Agent 采用评分卡
一眼查看信任、审计与安装准备度
这些分数综合公开仓库元数据、OpenAgentSkill 审查信号、维护新鲜度与安装准备度。它用于候选筛选,不替代人工审查。
质量
有潜力有用的候选项,但采用前应与替代方案比较。
信任
Do not auto-installTrust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
审计
需审查对安装准备度、安全元数据、维护情况与采用风险的机器可读审查。
OpenAgentSkill 信任评分 v5
安装前需人工审查
Choose a stronger alternative or inspect the source manually before any install attempt.
Stars
33 个 GitHub Stars
仓库活跃度
33 个 Star,3 个 Fork
维护状态
距上次推送 3 天
许可证
未知
安装
npx skills add shipshitdev/skills --skill skill-validator
安装安全性
标准软件包或运行时安装路径
权限范围
shell or command execution, filesystem or document access
Agent 结果
暂未有 Agent 结果数据
文档
README/SKILL.md 上下文充分
风险摘要
生产前审查
- Repository license is unknown, which may affect redistribution clarity.
- 许可证不清晰
- Low GitHub adoption signal
- Quality score needs review
安装准备度
安装路径可用
- 安装路径可用
- 仓库证据可用
- 许可证不清晰
- 暂无 Agent 验证结果证据
Agent 可读元数据
这个 Skill 的机器可读决策数据。
使用此区块或内嵌 JSON 判断 Agent 是否应安装该 Skill、选择替代方案,或先请求人工审查。
View technical data+
Agent 可读元数据
这个 Skill 的机器可读决策数据。
使用此区块或内嵌 JSON 判断 Agent 是否应安装该 Skill、选择替代方案,或先请求人工审查。
适用任务
- Local desktop 工作流
- Claude Code 团队
- builders willing to evaluate younger projects
- Navigate local resources
适用 Agent
安装决策
- 命令
- npx skills add shipshitdev/skills --skill skill-validator
- 策略
- 审查
- 人工审查
- 是
信任与风险
- 信任
- 55/100
- 审计
- 70/100
- 风险级别
- 需审查
结果闭环
- 端点
- /api/agent/outcome
- 事件 ID
- resolve
- 结果
- 5
不适用场景
- 需要厂商支持 SLA 的团队
- production agents without a repository review
- Low GitHub adoption signal
- Repository license is unknown, which may affect redistribution clarity.
- 高风险权限提示:Shell 或命令执行
替代 Skill
Last30days Skill
53.5K Stars
npx skills add mvanhorn/last30days-skill -g
替代 Skill
Academic Research Skills
38.4K Stars
npx skills add Imbad0202/academic-research-skills
替代 Skill
GPT Researcher
28.0K Stars
npx skills add assafelovic/gpt-researcher
替代 Skill
DeepResearch
19.8K Stars
npx skills add Alibaba-NLP/DeepResearch
Agent 安全 v2
38/100 · 避免自动安装
Sparse or mixed signals. Useful for discovery, but not for autonomous installation.
Test manually in an isolated workspace and compare against safer alternatives.
高
Shell 或命令执行
Skill 元数据引用了终端、CLI、Shell、子进程或命令执行工作流。
中
网络访问
Skill 可能访问远程页面、API、仓库或外部服务。
中
文件系统访问
Skill 可能读取或写入项目文件、文档、生成产物或本地工作区状态。
中
数据库访问
Skill 可能检查 Schema、查询数据库或处理持久化存储。
- 高风险权限提示:Shell 或命令执行
- 许可证不清晰
Agent 解析计划
让 Agent 在安装前验证匹配度。
Resolve API 返回首选 Skill、替代方案、安全策略、审计说明、安装目标和可直接执行的提示词,无需抓取此页面。
打开 JSON
/api/agent/resolve?task=Use%20skill-validator%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve 文本
/api/agent/resolve?task=Use%20skill-validator%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
安装交接
/api/skills/shipshitdev-skill-validator/install
Agent 应检查
- 从 Resolve API 检查任务匹配与替代方案。
- 检查审计评分、信任评分和安全策略警告。
- 检查 Codex、Claude Code、Cursor 或 CLI 的安装目标兼容性。
复制提示词
Task: Use skill-validator in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20skill-validator%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/shipshitdev-skill-validator/install
Install command: npx skills add shipshitdev/skills --skill skill-validator
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent 交接
把安装路径交给 Agent,而不是再给一个目录页。
通过公开安装端点获取命令、安全清单、目标提示词和该 Skill 的规范链接。
安装交接
/api/skills/shipshitdev-skill-validator/install
LLM 文本格式
/api/skills/shipshitdev-skill-validator/install?format=text
寻找替代方案
/api/skills/search?q=skill-validator&limit=3
Agent 提示词
Use skill-validator for this task. Review https://www.openagentskill.com/api/skills/shipshitdev-skill-validator/install, then install with: npx skills add shipshitdev/skills --skill skill-validatorRegistry 元数据
用于自动选择 Skill 的 Agent 可读档案。
本页通过 Registry API 提供相同的决策、信任、审计、场景和安装信号,让 Agent 无需抓取界面即可排序。
Manifest
/api/registry/manifest/shipshitdev-skill-validator
LLM 文本
/api/registry/manifest/shipshitdev-skill-validator?format=text
安装别名
/api/registry/install/shipshitdev-skill-validator
推荐
/api/registry/recommend?task=Use%20skill-validator%20in%20an%20agent%20workflow&limit=3
适配 Agent
Local desktop
平台
Claude Code, OpenAI Agents
Agent 决策面板
Needs validation for Local desktop
在将它加入 Agent 工作流前先人工审查仓库。
栈中角色
需要验证
主要匹配
Local desktop
信任标签
需要人工审查
安装路径
命令已就绪
适用场景
- Local desktop 工作流
- Claude Code 团队
- builders willing to evaluate younger projects
证据
- 仓库近期活跃
- 已提供安装命令或 GitHub 仓库
- 57/100 质量档案
- 2 个 OpenAgentSkill 交互事件
先审查
- Low GitHub adoption signal
- Repository license is unknown, which may affect redistribution clarity.
实施路径
- 1在沙盒 Agent 中安装它,并端到端完成一次Local desktop任务。
- 2Compare output quality, latency, and failure behavior against at least one alternative.
- 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.
信任档案
Do not auto-install
Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
GitHub 采用度
检查33 个 GitHub Stars
Star/Fork 活跃度
检查33 个 Star,3 个 Fork; 当前元数据中没有议题活跃度信息
近期维护
通过距上次推送 3 天
许可证清晰度
检查未知
积极信号
- AI 审查已通过
- 安装路径可用
- 仓库证据可用
- 近期维护的仓库
- 安装命令未发现明显高风险模式
- 结果闭环已就绪,但需要首次真实 Agent 运行
安装前审查
- Repository license is unknown, which may affect redistribution clarity.
- 许可证不清晰
- Low GitHub adoption signal
- Quality score needs review
- Permission surface needs review: shell or command execution, filesystem or document access
- GitHub adoption: 33 GitHub stars
- Stars/forks activity: 33 stars, 3 forks; issue activity unavailable in current metadata
- License clarity: Unknown
- Permission surface: shell or command execution, filesystem or document access
- 暂未有真实 Agent 结果报告
- 无人值守安装前需要人工审查
建议操作
Choose a stronger alternative or inspect the source manually before any install attempt.
质量档案
有潜力 适用于 Agent 工作流的候选
有用的候选项,但采用前应与替代方案比较。
工作流匹配
在这些场景使用此 Skill
Operate local tools
Local desktop
I need my agent to operate local files and desktop apps in a repeatable workflow.
Investigate faster
Research agents
I need my agent to research a topic, compare sources, and produce a concise report.
Operate web apps
Browser automation
I need my agent to control a browser, fill forms, and verify web app workflows.
工作流匹配
加入完整工作流
Find, compare, and synthesize
Research report agent
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Operate and verify web apps
Browser QA agent
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Turn skills into distribution
Content growth agent
A workflow for turning newly indexed skills into SEO briefs, social drafts, comparison pages, and reusable publishing workflows.
替代方案短名单
安装前对比
可能适合该任务的相近 Skill。
Last30days Skill
Research the last 30 days across Reddit, X, YouTube, Hacker News, Polymarket, GitHub, and the web, then synthesize a grounded brief for an AI agent.
Academic Research Skills
Academic Research Skills for Claude Code: research → write → review → revise → finalize
GPT Researcher
Run autonomous deep research over web and local sources
DeepResearch
Tongyi Deep Research, the Leading Open-source Deep Research Agent
概览
--- name: skill-validator description: | Validate SKILL.md files against the Agent Skills spec and Claude Code extensions. Run on new or modified skills before committing. metadata: internal: true version: "1.0.3" tags: "validation, skills, spec-compliance, quality" ---
# Skill Validator
Validate SKILL.md files against the Agent Skills specification and Claude Code extensions.
## When to Run
- After creating a new skill - After modifying a skill's SKILL.md frontmatter - Before committing skill changes - During periodic repo audits
## Validation Rules
### Required Fields (Agent Skills Spec)
Every SKILL.md must have YAML frontmatter with:
- `name` — kebab-case, matches directory name - `description` — 1-3 sentences, under 1024 chars, starts with verb or domain noun
### Metadata Block
`version` and `tags` must be inside `metadata:`, never top-level:
```yaml # CORRECT metadata: version: "1.0.0" tags: "react, performance, optimization"
# WRONG — top-level version version: 1.0.0
# WRONG — tags as YAML list metadata: tags: - react - performance ```
### Forbidden Fields
These are not part of any spec:
- `auto_activate` / `auto_trigger` — removed in 2026-04 migration - `risk` — not in Agent Skills or Claude Code specs
### Claude Code Extensions (Optional)
Valid extension fields (must match `allowed_fields` in `scripts/validate-skill-sync.sh`):
| Field | Purpose | |-------|---------| | `when_to_use` | Extra trigger phrases appended to `description` | | `disable-model-invocation` | Prevent auto-triggering (for destructive skills) | | `user-invocable` | `false` hides from the `/` menu | | `allowed-tools` | Auto-approve **allowlist** (not a sandbox — unlisted tools stay callable) | | `disallowed-tools` | Removes tools from the pool while active (the actual block mechanism) | | `argument-hint` | Autocomplete hint for expected arguments | | `compatibility` | Environment prerequisites (packages, network, target agent) | | `context` | `fork` for subagent isolation | | `agent` | Subagent type when `context: fork` | | `hooks` | Lifecycle hooks scoped to the skill | | `paths` | ⚠️ Broken upstream (#49835) — flag if present | | `shell` | `bash` (default) or `powershell` |
### Forbidden Fields (updated)
- `auto_activate` / `auto_trigger` — removed in 2026-04 migration - `risk` — not in any spec - `metadata.triggers` — duplicate activation metadata; put trigger phrases in `description` or `when_to_use` - `model` / `effort` — recognized by Claude Code but owned by app/session configuration, not public reusable skills - Any top-level field not in the tables above → "Unsupported top-level frontmatter field"
### Content Rules
- No hardcoded `/workspace/` paths - No tool names in instructions (say "search for" not "use Grep") - Imperative/infinitive style ("Configure X" not "You should configure X") - Code blocks use real backtick fences, not escaped `\`\`\`` - **No concrete model names** in body, `references/`, or `scripts/` — reject tier+version IDs (`claude-3-7-sonnet-20250219`, `claude-opus-4.5`, `gpt-5.5`), dated snapshots, and bare family names used as routing keys. Exception: orchestrator skills may name **capability tiers** in prose. See [skill-standards.md → Model references](../memory/system/skill-standards.md). - **No harness-owned execution parameters** in skills, commands, or routine templates. Apply [execution-boundary.md](../memory/system/execution-boundary.md). - **Routine templates** follow [routine-standards.md](../memory/system/routine-standards.md). Run `python3 scripts/audit-routines.py` to detect duplicate bodies and app-parameter leakage without printing prompt or configuration values. - **Provenance (derived skills only):** when `metadata.source` is set, `metadata.last_synced` and a README `## Upstream` section are required (enforced by `check_provenance()`). In-house skills need no provenance fields.
## Validation Process
1. Read the SKILL.md frontmatter 2. Check `name` matches parent directory name 3. Check `description` exists and is under 1024 chars 4. Check `description` plus `when_to_use` is under 1536 chars 5. Check `plugin.json` description is present and under 100 chars 6. Check `version`/`tags` are NOT top-level (must be inside `metadata:`) 7. Check for forbidden fields (`auto_activate`, `auto_trigger`, `risk`, `model`, `effort`, any field not in the extension tables) 8. Check for escaped backtick fences in content 9. Validate frontmatter value types: `allowed-tools` is a scalar, `metadata.version` and `metadata.tags` are quoted scalars, and `metadata` is a map 10. Reject duplicate `metadata.triggers`; keep activation guidance in `description` or `when_to_use` 11. Check for hardcoded paths (`/workspace/`, project-specific paths) 12. Grep body + `references/` + `scripts/` for concrete model names (`claude-*`, `gpt-*`, `sonnet`/`opus`/`haiku` used as IDs); allow only capability-tier prose in orchestrator skills 13. Warn when skills, commands, or templates set harness-owned execution parameters 14. Warn when a side-effecting skill lacks both `disable-model-invocation: true` and an explicit `Confirmation Required` gate 15. Check prose routing references across the body, excluding frontmatter and code fences, and flag missing local skills 16. Check provenance for derived skills: if `metadata.source` is set, require `metadata.last_synced` and a README `## Upstream` section 17. Run `bunx markdownlint-cli` on the file 18. Run `./scripts/validate-skill-sync.sh` for cross-validation
## Quick Validation Command
```bash # Single skill bunx markdownlint-cli skills/<name>/SKILL.md skills/<name>/references/*.md
# All skills bunx markdownlint-cli --ignore bundles --ignore dist "**/*.md"
# Sync validation ./scripts/validate-skill-sync.sh ```
技术详情
- 版本
- 1.0.0
- 许可证
- Unknown
- 最近更新
- 2026年8月23日
- 发布时间
- 2026年8月23日
决策摘要
需要验证
仓库近期活跃
Agent 验证证据
Agent 验证证据
来自解析、审查、安装和一次小范围运行后的结果报告。
- 成功率
- —
- 近期失败
- —
- 结果
- 0
- 输出质量
- —
- 失败
- 0
- 不相关
- 0
- 安装次数
- 0
- 风险拦截
- 0
- 需要配置
- 0
- 生产环境
- 0
暂时没有 Agent 结果数据。首次 Agent 执行可以通过 /api/agent/outcome 报告成功、需要设置、风险拦截、失败或不相关。
增长闭环
分享工具包
为 skill-validator 准备的场景化草稿,可手动发布到 X。
skill-validator: Validate SKILL.md files against the Agent Skills spec and Claude Code extensions. Run on new... 33 stars https://www.openagentskill.com/skills/shipshitdev-skill-validator?ref=x
可选:带安装命令的回复
Listing + install path for skill-validator: https://www.openagentskill.com/skills/shipshitdev-skill-validator?ref=x Install: npx skills add shipshitdev/skills --skill skill-validator
收录来源
Registry 收录
此列表来自公开来源,维护者认领获批前不会标记为官方。
- 创作者
- shipshitdev
- 收录方
- OpenAgentSkill 社区索引
归属链接指向公开仓库或创作者主页。创作者可认领列表以更新所有权信号。
认领此 Skill所有者认领
认领此 Skill 页面
这条 Registry 收录 列表归属于 shipshitdev,但尚未标记为官方。认领后可增加已验证所有者信号,使后续发布、安装和审计更新更值得信赖。
创作者外链工具包
将证据徽章加入你的 README
在开发者评估仓库的位置展示规范页面、当前信任与审计信号,以及真实的 Agent 验证证据。
[](https://www.openagentskill.com/skills/shipshitdev-skill-validator)
[](https://www.openagentskill.com/skills/shipshitdev-skill-validator)
[](https://www.openagentskill.com/skills/shipshitdev-skill-validator/audit)
[](https://www.openagentskill.com/skills/shipshitdev-skill-validator)作者
shipshitdev
@shipshitdev
健康信号
- GitHub Stars
- 33
- 质量评分
- 34/100
- 最近 GitHub 推送
- 2026年8月20日
- 框架提示
- 未知
- OpenAgentSkill 浏览量
- 2
- 复制安装命令
- 0
- 跳转点击
- 0
社区信号
告诉我们这个 Skill 是否对你的 Agent 工作流有帮助。汇总反馈会持续改善排序。
信任与安全
Do not auto-install
- GitHub 采用度33 个 GitHub Stars检查
- Star/Fork 活跃度33 个 Star,3 个 Fork; 当前元数据中没有议题活跃度信息检查
- 近期维护距上次推送 3 天通过
- 许可证清晰度未知检查
- README/SKILL.md 完整度元数据包含足够的用法与工作流上下文通过
- 依赖与运行时风险command execution surface, database surface信息
相关 Skill
Last30days Skill
Research the last 30 days across Reddit, X, YouTube, Hacker News, Polymarket, GitHub, and the web, then synthesize a grounded brief for an AI agent.
53.5K StarsAcademic Research Skills
Academic Research Skills for Claude Code: research → write → review → revise → finalize
38.4K StarsGPT Researcher
Run autonomous deep research over web and local sources
28.0K StarsDeepResearch
Tongyi Deep Research, the Leading Open-source Deep Research Agent
19.8K Stars