skill-check

Security Community
Interpretation is structured for decision-making; original keeps the upstream SKILL.md unchanged.

Decide Fit First

  • Core job: Use when the user wants to validate, lint, or audit agent skill files (SKILL.md). Use when they say "validate these skills," "ch…
  • Best fit: Use it when the task has reusable inputs, steps, and validation criteria rather than a one-off answer.
  • Avoid forcing it: If the source lacks commands, platform support, or external-service evidence, keep those fields unknown instead of guessing.

Design Intent

  • Structure: The skill is organized around “Installation”, “When to use”, “Local validation”, “GitHub repo validation”, showing how the author expects the agent to judge fit, collect context, and produce verifiable output.
  • Trigger evidence: Prioritize the author’s wording around when to use it, what context to collect, and what output shape to produce.
  • Evidence boundary: Author text states facts, repository files prove commands and paths, and Fluxly only adds fit, limits, and usage judgment.

How To Use It

  • Inputs: Provide target material, scope, expected result, forbidden changes, and validation method.
  • Invocation: Name skill-check directly; if the source includes slash commands, start with the command and then add task context.
  • Validation: Start small and check whether the result follows “Installation / When to use / Local validation” before expanding.

Boundaries And Review

  • Dependencies: It usually needs no extra API key, so start with a small validation task.
  • Permissions: Declared permissions include read / write; ask the agent to state file, command, and rollback boundaries before acting.
  • Quality bar: A useful result names the deliverable, evidence, and next action. Generic prose means the task needs tighter context.
Fluxly profile Author and license come from source; runtime, permissions, and network are Fluxly detections or estimates
Fluxly category
Security
Author-declared agents
No explicit declaration found; this is not inferred or tested compatibility
Static check
83 / 100 · heuristic scan, not runtime safety proof
Author / version / license
@thedaviddias · no license declared
Fluxly token estimate
Lean
Fluxly setup estimate
Plug-and-play
External API key
No requirement detected
Detected OS requirements
macOS · Linux · Windows
Runtime requirements
Node.js
Detected file/system behavior
  • Read-only
  • Write / modify
Detected network behavior
External requests
Install commands
None (reference only)

Profile is derived at build time from SKILL.md and install vectors. Subject to drift from author intent.

Heads up: 未限定 allowed-tools,默认拥有全部工具权限。; 检出高风险片段:pipe_curl_to_shell

Output preview skill-check.preview
# Interpreting results

- **error** — spec or rule violation; should be fixed.
- **warn** — recommendation; may be acceptable depending on context.
- **suggestion** — every diagnostic includes an actionable suggestion text.
- **quality score** — 0-100 per skill, weighted across frontmatter (30%), description (30%), body (20%), links (10%), file (10%).
- **duplicates** — `duplicates.name` / `duplicates.description` warnings when multiple skills share the same name or description.
- Exit code 0 means no errors; non-zero means validation failed or security scan found issues.

Discussion

Powered by GitHub Discussions. Sign in with GitHub to comment, react, or subscribe.