Install
$ agentstack add skill-acaprino-claude-code-daodan-marketplace-audit ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
Marketplace Audit
Run a comprehensive structural validation of any Claude Code plugin marketplace. Works against any project that follows the standard .claude-plugin/marketplace.json + plugins// layout.
Audit steps
Step 1: Run the validation script
Execute the audit script to get a machine-readable report:
# Validate only
python "${CLAUDE_PLUGIN_ROOT}/skills/marketplace-audit/scripts/audit_marketplace.py"
# Validate and auto-fix color issues (invalid, missing, disharmonious)
python "${CLAUDE_PLUGIN_ROOT}/skills/marketplace-audit/scripts/audit_marketplace.py" --fix
The script resolves the target project root by walking up from the script location, or respects a --project-root flag if invoking it from a different marketplace than where the plugin is installed.
Step 2: Review findings
The script checks:
- File existence -- every path in marketplace.json
agents/skills/commandsarrays resolves to a real file or directory - Orphaned files -- agent
.mdfiles, skill directories, or command.mdfiles on disk not registered in any plugin - Frontmatter validation
- Agents: must have
name,description,model,color - Skills: must have
name,description - Commands: must have
description
- Color consistency and harmony
- All agents within a plugin should use the same color
- Warn when a single color is overused across too many plugins (threshold configurable)
- Report color distribution across all plugins
- Valid colors: red, blue, green, yellow, purple, orange, pink, cyan
- Use
--fixto auto-correct invalid or missing colors
- Naming conventions
- All names are kebab-case
- Agent filename matches frontmatter
namefield - Plugin directory name matches marketplace.json
namefield - Skill directory name matches frontmatter
namefield - Workflow command output directories match command filename (e.g.,
feature-e2e.mdtypically writes to.feature-e2e/) - No naming collisions between commands in different plugins
- No em dash characters anywhere (use hyphen
-or double hyphen--)
- Cross-reference consistency (project-specific, best-effort)
- If a git remote is configured, suggest that the marketplace
namealign with the repo name (warning only) - If a
CLAUDE.mdis present at the project root, suggest that its project header match the marketplace name (warning only) - These are advisory -- different marketplace maintainers have different conventions
- Marketplace.json schema
- Every plugin has:
name,source,description,version,author,license,keywords,category,strict - No duplicate plugin names
- Duplicate keywords across plugins (warning only -- may be intentional)
- Version sanity
- All versions are valid semver (
MAJOR.MINOR.PATCH) metadata.versionis present at the root
Step 3: Fix issues
Address findings by severity:
- CRITICAL: Missing referenced files, broken paths, missing required frontmatter fields, duplicate plugin names
- WARNING: Orphaned files, naming mismatches, overlapping keywords, color inconsistencies, git/CLAUDE.md alignment
- INFO: Suggestions for improvement, consolidation opportunities
Step 4: Evaluate color harmony
After the script passes, review the color distribution and evaluate semantic harmony:
- Read each plugin's description and category from marketplace.json
- Consider domain: similar domains should have visually related colors; distinct domains should contrast
- Guiding principles:
- Warm colors (red, orange, yellow, pink) for creative / outward-facing plugins
- Cool colors (blue, cyan, purple) for analytical / development plugins
- Neutral (green) for tooling / infrastructure
- If colors feel disharmonious, propose a new assignment with reasoning and apply after user confirmation
Step 5: Re-validate
Run the script again after fixes to confirm a clean audit.
Notes for marketplace maintainers
- This skill is marketplace-agnostic. It assumes the standard Claude Code plugin layout (
.claude-plugin/marketplace.json+plugins//) but makes no assumption about which plugins, authors, or upstream sources are specific to your marketplace. - Plugin categories, default author, upstream sources, and any project-specific conventions should be documented in your
CLAUDE.mdat the project root. The script and this skill respect those conventions but do not enforce a particular taxonomy.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: acaprino
- Source: acaprino/claude-code-daodan
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.