Install
$ agentstack add skill-dmmulroy-anti-slop-install-anti-slop ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Install anti-slop
Install the bundled Oxlint plugin into the current repository and integrate it with the repository's existing lint setup. Preserve unrelated work and adapt to the project's package manager and configuration style.
Procedure
- Inspect the repository before changing it:
- Read its agent instructions.
- Check
git statusand preserve unrelated changes. - Identify the package manager from
packageManagerand lockfiles. - Find Oxlint configuration (
oxlint.config.*,.oxlintrc*, or a Vite+ config). - Check whether anti-slop files or rules already exist. Do not overwrite them without reviewing the diff.
- Copy the bundled plugin from this skill. Run from the target repository:
``bash node /scripts/install.mjs ``
This creates tools/oxlint/anti-slop/. Pass another relative destination as the first argument when the repository has an established tooling layout. The script refuses to replace an existing destination; only use --force after backing up and reviewing existing files.
- Install current compatible dependencies rather than trusting versions remembered by the agent:
- Query
npm view oxlint versionandnpm view @oxlint/plugins version. - Install the same current version of both packages with the repository's package manager.
oxlintis a development dependency. The copied source imports@oxlint/plugins, so install it as a development dependency for a local-only plugin.- Do not replace the package manager or rewrite unrelated dependency ranges.
- Register the plugin and enable all rules. For
oxlint.config.tsor.oxlintrc.json, add:
``ts jsPlugins: [ { name: "anti-slop", specifier: "./tools/oxlint/anti-slop/index.ts" }, ], ``
For Vite+, add that same entry to lint.jsPlugins. Merge it with existing entries instead of replacing them.
Enable these rules at "error":
``json { "anti-slop/no-chained-type-assertions": "error", "anti-slop/no-conditional-empty-object-spread": "error", "anti-slop/no-known-value-widening": "error", "anti-slop/no-module-mocking": "error", "anti-slop/no-object-parameters": "error", "anti-slop/no-reflect-apply": "error", "anti-slop/no-reflect-get": "error", "anti-slop/no-runtime-typeof": "error", "anti-slop/no-shape-in-symbol-names": "error", "anti-slop/no-unknown-parameters": "error", "anti-slop/no-unknown-returns": "error", "anti-slop/no-unknown-type-aliases": "error", "anti-slop/no-unsafe-dictionary-type": "error", "anti-slop/no-widen-then-assert": "error", "anti-slop/require-safety-comment-for-type-assertion": "error" } ``
- Run the repository's lint command and typecheck. If findings appear, report them and fix them only when the user asked for migration/cleanup. Do not suppress rules, weaken rule severity, add unsafe casts, or mechanically launder types to make lint pass.
- Review the final diff and clearly report:
- copied path,
- dependency versions installed,
- configuration changed,
- checks run and any remaining findings.
Migration guidance
When replacing an older local copy, compare its rules and diagnostics before overwriting. Keep project-specific rules in their own plugin; anti-slop is intentionally generic. Prefer inference, as const, satisfies, named owner contracts, and boundary parsing when resolving findings.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: dmmulroy
- Source: dmmulroy/anti-slop
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.