AgentStack
SKILL verified MIT Self-run

Audit Skill

skill-theagenticguy-agentic-plugins-audit-skill · by theagenticguy

>

No reviews yet
0 installs
15 views
0.0% view→install

Install

$ agentstack add skill-theagenticguy-agentic-plugins-audit-skill

✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

Are you the author of Audit Skill? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Contents

| Reference | When to load | | ------------------------------------ | --------------------------- | | ../../references/rubric.md | The scoring rubric (shared) | | ../../references/write-protocol.md | Write discipline | | templates/scorecard-skeleton.md | Output file shape |

Audit a skill

Score one skill against the 7-dimension rubric. The skill is the input; a scorecard Markdown file is the output.

How it works

  1. Resolve {{ skill }} to an absolute path. Accept either a directory path (skills/research) or a bare skill name (research) — glob for the matching SKILL.md.
  2. Read the rubric at ${CLAUDE_PLUGIN_ROOT}/references/rubric.md.
  3. Read the skill in full: SKILL.md, every file under references/, every file under templates/. The scorecard is grounded in what's in the files, not in the description alone. Reading is the primary work.
  4. If a prior /gardener audit exists at plugin-gardener/audit/, read its latest collisions.csv and clusters.csv for cross-reference context. Collisions involving this skill inform Dimension 1 (description quality) and Dimension 5 (proactive-label discipline) — check whether the description carries the right negative-keyword discriminators. For every collision row, open the sibling SKILL.md and verify by reading, not from the cosine alone.
  5. Write a scorecard to plugin-gardener/audit/ad-hoc/-.md using templates/scorecard-skeleton.md.
  6. Present the total, dimension scores, and top-3 recommended actions inline.

Apply the rubric dimension by dimension. Record a short rationale (1–2 sentences with a file:line citation from the files you read) for every criterion scoring under 3 points. The rationale is the value; the number is the aggregate.

On the role of embedding data: collisions and clusters from a prior /gardener run are binoculars, not the photograph. They point you at the right cross-references to open. Verify every flagged collision by reading both SKILL.md files — a high cosine is an invitation to investigate, not a verdict.

When to invoke

  • After authoring a new skill — baseline the score before committing.
  • After a monthly /gardener run flags a skill — re-score to confirm the issue.
  • After applying fixes — did the score improve?

What this does not do

  • Edit the skill.
  • Open a PR.
  • Change frontmatter.

The scorecard is the deliverable. Changes are the user's to apply.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.