AgentStack
SKILL verified MIT Self-run

Shell Scripting

skill-sordi-ai-skill-everything-shell-scripting · by sordi-ai

Apply when writing or reviewing Bash or POSIX shell scripts — automation, CI steps, deploy scripts, or any shell-based tooling.

No reviews yet
0 installs
10 views
0.0% view→install

Install

$ agentstack add skill-sordi-ai-skill-everything-shell-scripting

✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

Are you the author of Shell Scripting? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Sub-Skill: Bash / POSIX Scripting

Purpose: Prevent silent failures, portability bugs, and security holes in shell scripts by enforcing safe defaults, clean structure, and ShellCheck compliance.


Rules

Safety & Error Handling

  1. Fail-fast header. Always begin every shell script with set -euo pipefail so that unset variables, failed commands, and pipeline errors abort execution immediately. Reference: ERR-2026-021
  1. Trap cleanup. Always register a trap 'cleanup' EXIT function to remove temp files and release locks even when the script exits early due to an error.
  1. Meaningful exit codes. Always exit with a non-zero code that reflects the failure category (e.g., exit 1 for usage errors, exit 2 for dependency missing); never exit with 0 on failure.
  1. No eval. Never use eval to construct or execute dynamic commands; prefer arrays or explicit argument lists to avoid injection vulnerabilities.

Variables & Quoting

  1. Quote every variable. Always double-quote variable expansions ("$var", "$@") to prevent word-splitting and glob expansion on values containing spaces or special characters.
  1. Declare locals. Always declare variables inside functions with local to prevent accidental global namespace pollution.
  1. Readonly constants. Use readonly for values that must not change after assignment (e.g., readonly SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)").

Portability & Compatibility

  1. POSIX shebang. Always start scripts with #!/usr/bin/env bash (or #!/bin/sh for strict POSIX); never rely on /bin/bash being present at a fixed path on all target systems.
  1. Portable syntax. Prefer POSIX-compatible constructs ([ ] over [[ ]], $(...) over backticks) when the script must run under /bin/sh; use Bash-specific features only when the shebang explicitly targets Bash.
  1. ShellCheck clean. Ensure every script passes shellcheck -S warning with zero warnings before committing; treat ShellCheck output as mandatory, not advisory.

Structure & Maintainability

  1. Use functions. Always decompose scripts longer than ~30 lines into named functions with a main entry point called at the bottom; avoid top-level imperative code scattered throughout the file.
  1. Argument parsing with getopts. Use getopts for option parsing in scripts that accept flags; never parse $1, $2 manually for flag-style arguments.
  1. Temp file handling. Always create temporary files with mktemp and store the path in a variable cleaned up by the EXIT trap; never hard-code paths like /tmp/myfile.

Logging & Idempotency

  1. Structured logging. Use a log() helper that prefixes output with a timestamp and level (INFO, WARN, ERROR) and routes errors to stderr (>&2); never mix diagnostic output into stdout used for data.
  1. Idempotent operations. Ensure scripts can be run multiple times without side effects — use guards like [ -d "$dir" ] || mkdir -p "$dir" and command -v tool >/dev/null 2>&1 || install_tool before acting.
  1. Heredocs for multi-line strings. Prefer heredocs (<<'EOF' ... EOF) over concatenated echo calls for multi-line output or embedded config; use the quoted form (<<'EOF') to suppress variable expansion when the content is literal.

See also

  • skills/code-quality/SKILL.md
  • skills/error-log/SKILL.md

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.