AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Skill Doctor

skill-paulrberg-agent-skills-skill-doctor · by PaulRBerg

Use to audit Agent Skills catalogs or installed skill roots: validate SKILL.md frontmatter, Codex openai.yaml metadata, README catalog coverage, cli-* version pins, and relative resource links; optionally apply conservative --fix-safe metadata repairs.

No reviews yet
0 installs
39 views
0.0% view→install

Install

$ agentstack add skill-paulrberg-agent-skills-skill-doctor

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-paulrberg-agent-skills-skill-doctor)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
2mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Skill Doctor? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Skill Doctor

Audit local Agent Skills catalogs and installed skill roots, then apply only narrow metadata repairs when requested.

Arguments

  • --root PATH: Scan this catalog or installed skill root. Repeatable. Default: current working directory.
  • --format text|json: Select report format. Default: text.
  • --fix-safe: Create missing agents/openai.yaml files or update mismatched policy.allow_implicit_invocation.
  • --include-shelved: Include shelved/*/SKILL.md in metadata checks. Shelved skills are never required in README.md.

Workflow

  1. Resolve the skill directory, then run the helper from that directory:

``sh uv run scripts/skill-doctor.py "$ARGUMENTS" ``

  1. Use JSON when another command or agent will consume the result:

``sh uv run scripts/skill-doctor.py --root . --format json ``

  1. Run safe fixes only after reading the findings:

``sh uv run scripts/skill-doctor.py --root . --fix-safe ``

  1. Re-run without --fix-safe after any manual edits.

Findings

  • Treat error findings as catalog defects that should block publishing or syncing.
  • Treat warning findings as review-required catalog hygiene issues.
  • Use path and line from JSON output for precise follow-up edits.

Safe Fix Policy

--fix-safe may only:

  • Create a missing agents/openai.yaml with policy.allow_implicit_invocation derived from SKILL.md.
  • Update an existing allow_implicit_invocation boolean when it disagrees with disable-model-invocation.

Do not use the helper to rewrite frontmatter order, descriptions, README rows, references/version.txt, or relative links. Make those edits manually and verify with a fresh audit.

Exit Codes

  • 0: Clean, or all requested safe fixes succeeded and no findings remain.
  • 1: Findings remain.
  • 2: Invalid arguments or unreadable environment.
  • 3: A requested safe fix failed.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.