skill-lintSkill 创建预检、可靠性验收与格式审查工具。本技能应在用户创建、重大改造或审查Skill,需要识别旧版 Skill 的指令遵循不稳定、产出漂移、验证模态错配、约束漏检,或检查 Harness 契约、候选绑定证据、故障注入、目录结构、业务流和安全风险时使用。不要用于:代替业务领域验证器、代码审查、应用功能测试、通用编程任务。
Install via ClawdBot CLI:
clawdbot install cat-xierluo/skill-lintGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
rm -rf ~Calls external URL not in known-safe list
https://github.com/cat-xierluo/legal-skillsAI Analysis
The skill is a static format linter that analyzes local skill definitions; it does not execute user code or send data to external servers. The flagged external URL is the skill's public homepage, not an operational endpoint. The 'rm -rf ~' command is cited as a negative example in a security checklist, not as an instruction to be executed.
Audited Apr 17, 2026 · audit v1.0
Generated Oct 2, 2026
开发者或团队在把自研 Claude Code Skill 发布到公开 Marketplace 或公司内部技能库之前,使用本技能对目录结构、Frontmatter、引用一致性、LICENSE、CHANGELOG 和 version 做系统审查。SKILL.md 中明确规定了发布治理模块,能帮助发布者避免因格式或合规问题导致 Skill 被拒或加载失败。
企业在引入外部或第三方 Skill 时,使用本技能检查是否存在提示注入、隐藏执行、凭证泄露、数据外传、危险命令和可疑依赖。SKILL.md 中专门的安全评估章节会按凭证、危险执行、网络外联、MCP 和提示词安全逐项打分,输出可交付的安全报告。
当团队维护一个包含多个 Skill 的 monorepo 时,可用本技能做回归检查和批量治理审查。它能正确识别仓库类型、发现最小 Skill 单元,并抽样检查 Skill-like 文档,避免因根目录缺少 SKILL.md 而误判整个仓库不合格。
技术写作者、布道师或内部教练可用本技能的报告作为教学材料,报告中的「设计理念」字段能解释触发边界、上下文聚焦、自由度匹配等结构性建议背后的写作原理。这既完成了质量验收,也帮助团队提升 Skill 写作水平。
在将 AI Agent 技能投入生产前,团队使用本技能确认 Skill 是否声明评估范围、Hard Fail、benchmark 样例和输出验收标准。缺少这些内容虽不一定阻塞发布,但会被记录为质量风险,帮助团队提前建立回归测试基线。
基础审查规则和模板以 MIT 开源免费提供,吸引开发者使用;面向需要自定义发布策略、团队协作审查、私有规则库和审计日志的企业,提供付费订阅版本。开源生态为商业版导流,形成社区驱动的增长飞轮。
面向需要引入第三方 Skill 的企业,提供由专业审查员使用本技能执行的安全尽调和质量验收服务,输出正式质量意见报告。可结合 Git 提交历史审计、凭证泄露检测和权限评估,形成可交付的合规文档。
基于本技能的审查标准和分级体系,提供 Skill 质量认证计划,通过认证的技能可获得标识;同时为团队提供 Skill 写作与审查培训课程,教成员理解 Hard Fail、可评估性和业务流深度等标准。
💬 Integration Tip
本技能依赖 references 目录下的多个标准模块,建议先完善模板中缺失的引用文件,并在 CI 中集成 skill-lint 做自动回归审查,避免人工遗漏。
Scored Oct 2, 2026
Control desktop applications on Windows — launch, close, focus, resize, move windows, simulate keyboard/mouse input, manage processes, control VSCode, read clipboard, and capture screen info. Use when the user wants to interact with any running program, switch windows, type text, press shortcuts, open files in VSCode, manage running processes, or get system display information.
Conduct rigorous, adversarial code reviews with zero tolerance for mediocrity. Use when users ask to "critically review" my code or a PR, "critique my code", "find issues in my code", or "what's wrong with this code". Identifies security holes, lazy patterns, edge case failures, and bad practices across Python, R, JavaScript/TypeScript, SQL, and front-end code. Scrutinizes error handling, type safety, performance, accessibility, and code quality. Provides structured feedback with severity tiers (Blocking, Required, Suggestions) and specific, actionable recommendations.
Pragmatic coding standards for writing clean, maintainable code — naming, functions, structure, anti-patterns, and pre-edit safety checks. Use when writing new code, refactoring existing code, reviewing code quality, or establishing coding standards.
Claude Code integration for OpenClaw. This skill provides interfaces to: - Query Claude Code documentation from https://code.claude.com/docs - Manage subagents and coding tasks - Execute AI-assisted coding workflows - Access best practices and common workflows Use this skill when users want to: - Get help with coding tasks - Query Claude Code documentation - Manage AI-assisted development workflows - Execute complex programming tasks
Plan, draft, version, and refine written content with enforced versioning and quality audits.
Use when writing tests, creating test strategies, or building automation frameworks. Invoke for unit tests, integration tests, E2E, coverage analysis, performance testing, security testing.