{"_id":"skill-check","_rev":"5-e151178fadfb2907aeb7c44eb928c87f","name":"skill-check","dist-tags":{"latest":"1.2.0"},"versions":{"0.1.0":{"name":"skill-check","version":"0.1.0","keywords":["skills","agent-skills","lint","validator","cli","sarif"],"license":"MIT","_id":"skill-check@0.1.0","maintainers":[{"name":"thedaviddias","email":"thedaviddias@gmail.com"}],"homepage":"https://github.com/thedaviddias/skill-check#readme","bugs":{"url":"https://github.com/thedaviddias/skill-check/issues"},"bin":{"skill-check":"bin/skill-check.js"},"dist":{"shasum":"e7183fd2e7bb9bf139f16cea4bc23fe83f872160","tarball":"https://registry.npmjs.org/skill-check/-/skill-check-0.1.0.tgz","fileCount":70,"integrity":"sha512-BcPnhV5fkNe4SbOnbE3PoXVQA/Alj0ckI/AyiwKkQOgVTd6gIZu07D6YH/mMUkp+F4T8HSXu2Le6xQ3JD7wa3w==","signatures":[{"sig":"MEYCIQCuHL8I6tUjz/062hJy2NiAaHpX8kBkb06JgyfBnh6ywAIhAO42rxg/RGOfT4rklzzZVM1HGnPTV9PxzWB8p2BqbcsY","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":132979},"type":"module","engines":{"node":">=20"},"gitHead":"181cb4f216bc91ddd63c148e05948cfb884237a9","private":false,"scripts":{"dev":"tsx src/cli/main.ts","lint":"biome check --no-errors-on-unmatched .","test":"vitest run","build":"tsc -p tsconfig.build.json","check":"tsx src/cli/main.ts check .","clean":"rm -rf dist coverage","format":"biome format --write .","report":"tsx src/cli/main.ts report .","prepack":"pnpm run clean && pnpm run build","prepare":"lefthook install","release":"semantic-release","check:fix":"tsx src/cli/main.ts check . --fix --no-security-scan","smoke:cli":"bash scripts/smoke-cli.sh","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","demo:readme":"bash scripts/readme-demo.sh","security-scan":"tsx src/cli/main.ts security-scan .","check:security":"tsx src/cli/main.ts check . --security-scan --allow-installs","release:dry-run":"semantic-release --dry-run"},"_npmUser":{"name":"thedaviddias","email":"thedaviddias@gmail.com"},"repository":{"url":"git+https://github.com/thedaviddias/skill-check.git","type":"git"},"_npmVersion":"11.6.1","description":"Linter for agent skill files","directories":{},"_nodeVersion":"24.10.0","dependencies":{"ora":"^9.3.0","yaml":"^2.8.2","boxen":"^8.0.1","listr2":"^10.1.0","commander":"^14.0.3","fast-glob":"^3.3.3","minimatch":"^10.2.2","cli-table3":"^0.6.5","picocolors":"^1.1.1","@clack/prompts":"^1.0.1"},"_hasShrinkwrap":false,"packageManager":"pnpm@10.30.1+sha512.3590e550d5384caa39bd5c7c739f72270234b2f6059e13018f975c313b1eb9fefcc09714048765d4d9efe961382c312e624572c0420762bdc5d5940cdf9be73a","devDependencies":{"tsx":"^4.21.0","vitest":"^4.0.18","lefthook":"^2.1.1","commitlint":"^20.4.2","typescript":"^5.9.3","@types/node":"^25.3.0","@biomejs/biome":"^2.4.4","semantic-release":"^25.0.3","@vitest/coverage-v8":"^4.0.18","@semantic-release/git":"^10.0.1","@semantic-release/changelog":"^6.0.3","@commitlint/config-conventional":"^20.4.2"},"_npmOperationalInternal":{"tmp":"tmp/skill-check_0.1.0_1771627524279_0.8872795174874177","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"skill-check","version":"0.1.1","keywords":["skills","agent-skills","lint","validator","cli","sarif"],"license":"MIT","_id":"skill-check@0.1.1","maintainers":[{"name":"thedaviddias","email":"thedaviddias@gmail.com"}],"homepage":"https://github.com/thedaviddias/skill-check#readme","bugs":{"url":"https://github.com/thedaviddias/skill-check/issues"},"bin":{"skill-check":"bin/skill-check.js"},"dist":{"shasum":"61c8c0457ea462d316598409c7c63c5cdc1739e6","tarball":"https://registry.npmjs.org/skill-check/-/skill-check-0.1.1.tgz","fileCount":70,"integrity":"sha512-xrfbxQ75FKm61T1sRWsXf4y183xhjPoFSL4wt7EZ3So2SM/5wA5VfGMN0OiZFqhQn7ljFDhXuA+T/AogqLLHEw==","signatures":[{"sig":"MEUCIDBWx0eOcYY4WgCZxphgCmKdji5K2TOJPvKCoKHs8/DPAiEAoVgyooPYHW7qKsOY5k6+rmHmG6UiWwxq2VquAUsKyNw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":132918},"type":"module","engines":{"node":">=20"},"gitHead":"96794629d22df4da5538d9f7f4631560bc156e53","private":false,"scripts":{"dev":"tsx src/cli/main.ts","lint":"biome check --no-errors-on-unmatched .","test":"vitest run","build":"tsc -p tsconfig.build.json","check":"tsx src/cli/main.ts check .","clean":"rm -rf dist coverage","format":"biome format --write .","report":"tsx src/cli/main.ts report .","prepack":"pnpm run clean && pnpm run build","prepare":"lefthook install","release":"semantic-release","check:fix":"tsx src/cli/main.ts check . --fix --no-security-scan","smoke:cli":"bash scripts/smoke-cli.sh","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","demo:readme":"bash scripts/readme-demo.sh","security-scan":"tsx src/cli/main.ts security-scan .","check:security":"tsx src/cli/main.ts check . --security-scan --allow-installs","release:dry-run":"semantic-release --dry-run"},"_npmUser":{"name":"thedaviddias","email":"thedaviddias@gmail.com"},"repository":{"url":"git+https://github.com/thedaviddias/skill-check.git","type":"git"},"_npmVersion":"11.6.1","description":"Linter for agent skill files","directories":{},"_nodeVersion":"24.10.0","dependencies":{"ora":"^9.3.0","yaml":"^2.8.2","boxen":"^8.0.1","listr2":"^10.1.0","commander":"^14.0.3","fast-glob":"^3.3.3","minimatch":"^10.2.2","cli-table3":"^0.6.5","picocolors":"^1.1.1","@clack/prompts":"^1.0.1"},"_hasShrinkwrap":false,"packageManager":"pnpm@10.30.1+sha512.3590e550d5384caa39bd5c7c739f72270234b2f6059e13018f975c313b1eb9fefcc09714048765d4d9efe961382c312e624572c0420762bdc5d5940cdf9be73a","devDependencies":{"tsx":"^4.21.0","vitest":"^4.0.18","lefthook":"^2.1.1","commitlint":"^20.4.2","typescript":"^5.9.3","@types/node":"^25.3.0","@biomejs/biome":"^2.4.4","semantic-release":"^25.0.3","@vitest/coverage-v8":"^4.0.18","@semantic-release/git":"^10.0.1","@semantic-release/changelog":"^6.0.3","@commitlint/config-conventional":"^20.4.2"},"_npmOperationalInternal":{"tmp":"tmp/skill-check_0.1.1_1771628823903_0.3500510141869342","host":"s3://npm-registry-packages-npm-production"}},"1.0.0":{"name":"skill-check","version":"1.0.0","keywords":["skills","agent-skills","lint","validator","cli","sarif"],"license":"MIT","_id":"skill-check@1.0.0","maintainers":[{"name":"thedaviddias","email":"thedaviddias@gmail.com"}],"homepage":"https://github.com/thedaviddias/skill-check#readme","bugs":{"url":"https://github.com/thedaviddias/skill-check/issues"},"bin":{"skill-check":"bin/skill-check.js"},"dist":{"shasum":"e75d73cb3adf9370c7f2aee0348c5c233ab7e9d0","tarball":"https://registry.npmjs.org/skill-check/-/skill-check-1.0.0.tgz","fileCount":78,"integrity":"sha512-OMAiMR/LeDgqAFK/IVYvaWcttwSd5TzVgMyChmK/pFdHR92oX3HHmE1XDc/Om8hmTI4qnbrwjRFJijFTFT77qw==","signatures":[{"sig":"MEUCIEvMA0V3ac2cGWq5rekk0PztFjp6K7dYLFsm+v0UdFBlAiEAwNWV9GXufhSqSnnm0hqq557izo285OvXYlUwxfikH/U=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/skill-check@1.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":186291},"type":"module","engines":{"node":">=20"},"gitHead":"89b2a239f4f8bbbf35e1b72e5cb00187d86cf49a","private":false,"scripts":{"dev":"tsx src/cli/main.ts","lint":"biome check --no-errors-on-unmatched .","test":"vitest run","build":"tsc -p tsconfig.build.json","check":"tsx src/cli/main.ts check .","clean":"rm -rf dist coverage","format":"biome format --write .","report":"tsx src/cli/main.ts report .","prepack":"pnpm run clean && pnpm run build","prepare":"lefthook install","release":"semantic-release","check:fix":"tsx src/cli/main.ts check . --fix --no-security-scan","smoke:cli":"bash scripts/smoke-cli.sh","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","demo:readme":"bash scripts/readme-demo.sh","security-scan":"tsx src/cli/main.ts security-scan .","check:security":"tsx src/cli/main.ts check . --security-scan --allow-installs","release:dry-run":"semantic-release --dry-run"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:1b9c1cf8-4f29-4466-8860-1ef044c122dc"}},"repository":{"url":"git+https://github.com/thedaviddias/skill-check.git","type":"git"},"_npmVersion":"11.10.1","description":"Linter for agent skill files","directories":{},"_nodeVersion":"24.10.0","dependencies":{"ora":"^9.3.0","yaml":"^2.8.2","boxen":"^8.0.1","listr2":"^10.1.0","commander":"^14.0.3","fast-glob":"^3.3.3","minimatch":"^10.2.2","cli-table3":"^0.6.5","picocolors":"^1.1.1","@clack/prompts":"^1.0.1","@resvg/resvg-js":"^2.6.2"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"packageManager":"pnpm@10.30.1+sha512.3590e550d5384caa39bd5c7c739f72270234b2f6059e13018f975c313b1eb9fefcc09714048765d4d9efe961382c312e624572c0420762bdc5d5940cdf9be73a","devDependencies":{"tsx":"^4.21.0","vitest":"^4.0.18","lefthook":"^2.1.1","commitlint":"^20.4.2","typescript":"^5.9.3","@types/node":"^25.3.0","@biomejs/biome":"^2.4.4","semantic-release":"^25.0.3","@vitest/coverage-v8":"^4.0.18","@semantic-release/git":"^10.0.1","@semantic-release/npm":"^13.1.4","@semantic-release/changelog":"^6.0.3","@commitlint/config-conventional":"^20.4.2"},"_npmOperationalInternal":{"tmp":"tmp/skill-check_1.0.0_1771647169213_0.5407416927097926","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"skill-check","version":"1.1.0","keywords":["skills","agent-skills","lint","validator","cli","sarif"],"license":"MIT","_id":"skill-check@1.1.0","maintainers":[{"name":"thedaviddias","email":"thedaviddias@gmail.com"}],"homepage":"https://github.com/thedaviddias/skill-check#readme","bugs":{"url":"https://github.com/thedaviddias/skill-check/issues"},"bin":{"skill-check":"bin/skill-check.js"},"dist":{"shasum":"18083252fd8977f1b21635611b5719e2990fd305","tarball":"https://registry.npmjs.org/skill-check/-/skill-check-1.1.0.tgz","fileCount":78,"integrity":"sha512-PuRKlvvhwWKnGQyhvcgQ19IXnMhIgS7OCO+oah6GVQJfVAbATY6nlJaaIEY5TCMUc6M1+lW7RXofFwiIuNBgvQ==","signatures":[{"sig":"MEYCIQDdOsER5Lfwhiy9nL/mxg+QK6PE1ecQPhXZB0HmEmMulQIhAPr/4OCwkVkVuRD+OSAOqb988MucumJIeq3Jr0NTqypk","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/skill-check@1.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":185880},"type":"module","engines":{"node":">=20"},"gitHead":"5306b3ddb85847da2fb3fa323f327b2d8ac94793","private":false,"scripts":{"dev":"tsx src/cli/main.ts","lint":"biome check --no-errors-on-unmatched .","test":"vitest run","build":"tsc -p tsconfig.build.json","check":"tsx src/cli/main.ts check .","clean":"rm -rf dist coverage","format":"biome format --write .","report":"tsx src/cli/main.ts report .","prepack":"pnpm run clean && pnpm run build","prepare":"lefthook install","release":"semantic-release","check:fix":"tsx src/cli/main.ts check . --fix --no-security-scan","smoke:cli":"bash scripts/smoke-cli.sh","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","demo:readme":"bash scripts/readme-demo.sh","security-scan":"tsx src/cli/main.ts security-scan .","check:security":"tsx src/cli/main.ts check . --security-scan --allow-installs","release:dry-run":"semantic-release --dry-run"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:1b9c1cf8-4f29-4466-8860-1ef044c122dc"}},"repository":{"url":"git+https://github.com/thedaviddias/skill-check.git","type":"git"},"_npmVersion":"11.10.1","description":"Linter for agent skill files","directories":{},"_nodeVersion":"24.10.0","dependencies":{"ora":"^9.3.0","yaml":"^2.8.2","boxen":"^8.0.1","listr2":"^10.1.0","commander":"^14.0.3","fast-glob":"^3.3.3","minimatch":"^10.2.2","cli-table3":"^0.6.5","picocolors":"^1.1.1","@clack/prompts":"^1.0.1","@resvg/resvg-js":"^2.6.2"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"packageManager":"pnpm@10.30.1+sha512.3590e550d5384caa39bd5c7c739f72270234b2f6059e13018f975c313b1eb9fefcc09714048765d4d9efe961382c312e624572c0420762bdc5d5940cdf9be73a","devDependencies":{"tsx":"^4.21.0","vitest":"^4.0.18","lefthook":"^2.1.1","commitlint":"^20.4.2","typescript":"^5.9.3","@types/node":"^25.3.0","@biomejs/biome":"^2.4.4","semantic-release":"^25.0.3","@vitest/coverage-v8":"^4.0.18","@semantic-release/git":"^10.0.1","@semantic-release/npm":"^13.1.4","@semantic-release/changelog":"^6.0.3","@commitlint/config-conventional":"^20.4.2"},"_npmOperationalInternal":{"tmp":"tmp/skill-check_1.1.0_1771649479200_0.8495812502841844","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"skill-check","version":"1.2.0","description":"Linter for agent skill files","type":"module","private":false,"bin":{"skill-check":"bin/skill-check.js"},"engines":{"node":">=20"},"scripts":{"clean":"rm -rf dist coverage","build":"tsc -p tsconfig.build.json","dev":"tsx src/cli/main.ts","check":"tsx src/cli/main.ts check .","check:fix":"tsx src/cli/main.ts check . --fix --no-security-scan","check:security":"tsx src/cli/main.ts check . --security-scan --allow-installs","security-scan":"tsx src/cli/main.ts security-scan .","demo:readme":"bash scripts/readme-demo.sh","release":"semantic-release","release:dry-run":"semantic-release --dry-run","smoke:cli":"bash scripts/smoke-cli.sh","report":"tsx src/cli/main.ts report .","lint":"biome check --no-errors-on-unmatched .","typecheck":"tsc -p tsconfig.json --noEmit","test":"vitest run","test:watch":"vitest","prepack":"pnpm run clean && pnpm run build","format":"biome format --write .","prepare":"lefthook install"},"keywords":["skills","agent-skills","lint","validator","cli","sarif"],"repository":{"type":"git","url":"git+https://github.com/thedaviddias/skill-check.git"},"license":"MIT","publishConfig":{"provenance":true,"access":"public"},"dependencies":{"@clack/prompts":"^1.0.1","@resvg/resvg-js":"^2.6.2","boxen":"^8.0.1","cli-table3":"^0.6.5","commander":"^14.0.3","fast-glob":"^3.3.3","listr2":"^10.1.0","minimatch":"^10.2.2","ora":"^9.3.0","picocolors":"^1.1.1","yaml":"^2.8.2"},"devDependencies":{"@biomejs/biome":"^2.4.4","@commitlint/config-conventional":"^20.4.2","@semantic-release/changelog":"^6.0.3","@semantic-release/git":"^10.0.1","@semantic-release/npm":"^13.1.4","@types/node":"^25.3.0","@vitest/coverage-v8":"^4.0.18","commitlint":"^20.4.2","lefthook":"^2.1.1","semantic-release":"^25.0.3","tsx":"^4.21.0","typescript":"^5.9.3","vitest":"^4.0.18"},"packageManager":"pnpm@10.30.1+sha512.3590e550d5384caa39bd5c7c739f72270234b2f6059e13018f975c313b1eb9fefcc09714048765d4d9efe961382c312e624572c0420762bdc5d5940cdf9be73a","gitHead":"a30839cf1583b720b0785d51b3b8b73a7cedacf1","_id":"skill-check@1.2.0","bugs":{"url":"https://github.com/thedaviddias/skill-check/issues"},"homepage":"https://github.com/thedaviddias/skill-check#readme","_nodeVersion":"24.10.0","_npmVersion":"11.10.1","dist":{"integrity":"sha512-Zx27SeqVholGmMw0l4dnAYF69DBygo7g1KwIkc6DsL3j6zDaHOLCwiqECNuAz7UtmT73G0XEr2kFVlUHlIdSQA==","shasum":"615e517bbfdc3a1756b8a4e7b9653176ffbc5842","tarball":"https://registry.npmjs.org/skill-check/-/skill-check-1.2.0.tgz","fileCount":78,"unpackedSize":192624,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/skill-check@1.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDvJY3zIHnvRnbt3QP4nfy7a+DuLO0eZO3POqJ/bNzFNgIgRCMrsGqGVNwR6ZbWvnUMFzWmQFn4/jkKMfXuwAwl/Zg="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:1b9c1cf8-4f29-4466-8860-1ef044c122dc"}},"directories":{},"maintainers":[{"name":"thedaviddias","email":"thedaviddias@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/skill-check_1.2.0_1771651601404_0.38956600297076593"},"_hasShrinkwrap":false}},"time":{"created":"2026-02-20T22:45:24.279Z","modified":"2026-02-21T05:26:41.906Z","0.1.0":"2026-02-20T22:45:24.470Z","0.1.1":"2026-02-20T23:07:04.045Z","1.0.0":"2026-02-21T04:12:49.363Z","1.1.0":"2026-02-21T04:51:19.354Z","1.2.0":"2026-02-21T05:26:41.572Z"},"bugs":{"url":"https://github.com/thedaviddias/skill-check/issues"},"license":"MIT","homepage":"https://github.com/thedaviddias/skill-check#readme","keywords":["skills","agent-skills","lint","validator","cli","sarif"],"repository":{"type":"git","url":"git+https://github.com/thedaviddias/skill-check.git"},"description":"Linter for agent skill files","maintainers":[{"name":"thedaviddias","email":"thedaviddias@gmail.com"}],"readme":"# skill-check\n\nLinter for agent skill files — validates SKILL.md files against the spec with extensible custom rules.\n\n![skill-check demo](docs/assets/skill-check-demo.gif)\n\n## Install\n\n```bash\nnpx skill-check .\n```\n\nGlobal install via curl:\n\n```bash\ncurl -fsSL https://raw.githubusercontent.com/thedaviddias/skill-check/main/scripts/install.sh | bash\n```\n\nInstall via Homebrew:\n\n```bash\nbrew tap thedaviddias/skill-check https://github.com/thedaviddias/skill-check\nbrew install skill-check\n```\n\n## Commands\n\n| Command | Description |\n|---|---|\n| `skill-check [path\\|github-url]` | Shorthand for `skill-check check [path\\|github-url]` |\n| `skill-check check [path\\|github-url]` | Run validation (and optional security scan) |\n| `skill-check split-body [path]` | Preview/apply section-based body split into `references/*.md` |\n| `skill-check new <name>` | Scaffold a new skill directory with SKILL.md template |\n| `skill-check watch [path]` | Watch local paths for changes and re-run validation on save |\n| `skill-check diff <a> <b>` | Compare diagnostics between two skill directories |\n| `skill-check report [path\\|github-url]` | Generate a markdown health report |\n| `skill-check rules [id]` | List all rules, or show detail for a specific rule |\n| `skill-check security-scan [path\\|github-url]` | Run security scan via agent-scan (mcp-scan) |\n| `skill-check init` | Create `skill-check.config.json` template |\n\n### check options\n\n| Flag | Description |\n|---|---|\n| `--fix` | Apply safe automatic fixes for supported findings |\n| `--fix --interactive` | Prompt before applying each fix (TTY only) |\n| `--baseline <path>` | Compare against a previous JSON run and show new/fixed counts |\n| `--format <fmt>` | Output format (see below) |\n| `--share` | Render a share card (text format only) |\n| `--share-out <path>` | Save a share image file (default: `./skill-check-share.png`) |\n| `--no-open` | Skip auto-opening HTML reports |\n| `--no-security-scan` | Skip the security scan |\n| `--security-scan-verbose` | Show full raw `agent-scan` output (default is compact summary) |\n| `--strict` | Treat warnings as errors |\n| `--lenient` | Relax selected strict rules |\n| `--fail-on-warning` | Exit non-zero when warnings exist |\n\n## Output Formats\n\n| Format | Description |\n|---|---|\n| `text` | Colorized terminal output with ASCII tables, severity badges, and quality scores (default) |\n| `json` | Machine-readable output including quality scores and optional baseline diff |\n| `sarif` | SARIF format for security tooling and GitHub Code Scanning |\n| `html` | Self-contained HTML report with scores, filtering, and dark mode |\n| `github` | `::error` / `::warning` annotations for GitHub Actions |\n\n**HTML reports** are written to `skill-check-report.html` (or `output.reportPath`). In an interactive terminal the report opens in your browser automatically; use `--no-open` to skip.\n\n**View locally:** `npx skill-check . --format html` or open the file directly: `open skill-check-report.html` (macOS).\n\nThe `text` formatter includes quality score bars per skill, colorized severity badges, and a share-friendly shield card with the exact runnable `npx skill-check ...` command (including GitHub URL targets when used).\nAn ASCII CLI banner is shown in interactive text mode; set `SKILL_CHECK_NO_BANNER=1` to disable it.\n\n## Quality Scores\n\nEvery `check` run computes a quality score (0-100) per skill based on five weighted categories:\n\n| Category | Weight | What it measures |\n|---|---|---|\n| Frontmatter | 30% | Required fields, naming, ordering |\n| Description | 30% | Length, \"Use when\" phrasing |\n| Body | 20% | Line/token limits |\n| Links | 10% | Broken local and reference links |\n| File | 10% | Trailing newlines, formatting |\n\nScores appear in `text`, `html`, and `json` output.\n\n## Duplicate Detection\n\nWhen multiple skills share the same `name` or identical `description`, `check` emits `duplicates.name` / `duplicates.description` warnings so agents can reliably differentiate skills.\n\n## Baseline Comparison\n\nSave a JSON run as a baseline and compare later:\n\n```bash\nnpx skill-check check . --format json --no-security-scan > baseline.json\n# ... make changes ...\nnpx skill-check check . --baseline baseline.json --no-security-scan\n```\n\nOutput shows how many diagnostics are new, fixed, or unchanged.\n\n## Quick Start\n\n```bash\npnpm install\npnpm run check\npnpm run report\n```\n\nGenerate real CLI outputs from multi-skill fixtures:\n\n```bash\npnpm run smoke:cli\n```\n\nSmoke output files are written to `reports/smoke/`.\nSmoke includes a real security scan run by default.\nSmoke also includes a real `--fix` run on a temp copy of the failing mixed fixture.\nYou can control smoke output colors with `SMOKE_COLOR=always|auto|never`.\nYou can set `SMOKE_SECURITY_SCAN=0` to skip security smoke and `SMOKE_SECURITY_SCAN_RUNNER=auto|local|uvx|pipx` to choose the runner (default: `pipx`).\nUse `SMOKE_SECURITY_SCAN_SKILLS=/path/to/skills` to override the skills path scanned in smoke mode.\n\nCreate config with guided setup:\n\n```bash\nnpx skill-check init --interactive\n```\n\n## Security Scan\n\n`skill-check` can validate repos or direct skills directories:\n\n```bash\nnpx skill-check /path/to/repo\nnpx skill-check check ~/.claude/skills\n```\n\n`check` runs the security scan by default.\nIf dependencies are missing, `skill-check` automatically installs scanner dependencies by default.\nUse `--no-installs` to hard-block automatic installs.\nBy default, `skill-check` prints a compact security summary; use `--security-scan-verbose` for full scanner details.\n\nRun security scan without UV by forcing `pipx`:\n\n```bash\nnpx skill-check security-scan . --security-scan-runner pipx\n```\n\nRun validation + security scan in one pipeline step with explicit runner:\n\n```bash\nnpx skill-check check . --security-scan-runner pipx\n```\n\nSkip security scan for local/offline linting:\n\n```bash\nnpx skill-check check . --no-security-scan\n```\n\nApply safe auto-fixes and then re-run validation:\n\n```bash\nnpx skill-check check . --fix --no-security-scan\n```\n\nInteractively choose which fixes to apply:\n\n```bash\nnpx skill-check check . --fix --interactive --no-security-scan\n```\n\nScaffold a new skill:\n\n```bash\nnpx skill-check new my-skill\n```\n\nWatch for changes during development:\n\n```bash\nnpx skill-check watch . --no-security-scan\n```\n\nCompare two skill directories:\n\n```bash\nnpx skill-check diff skills/ other-skills/\n```\n\nUse GitHub annotations in CI:\n\n```bash\nnpx skill-check check . --format github --no-security-scan\n```\n\nGenerate a screenshot-friendly social summary card:\n\n```bash\nnpx skill-check https://github.com/thedaviddias/skill-check --share --no-security-scan\n```\n\nBy default this also writes `skill-check-share.png` in your current directory.\nSet a custom output path with `--share-out path/to/card.png`.\n\nHard-block dependency installs:\n\n```bash\nnpx skill-check check . --no-installs\n```\n\n## Remote GitHub URLs\n\n`skill-check` supports scanning GitHub repos directly without a manual clone:\n\n```bash\nnpx skill-check https://github.com/thedaviddias/skill-check --no-security-scan\nnpx skill-check https://github.com/thedaviddias/skill-check/tree/main/skills --no-security-scan\n```\n\nRemote URL scanning behavior:\n\n- Creates an ephemeral shallow clone (`git clone --depth 1`) in a temp directory.\n- Cleans up the checkout automatically after the command finishes.\n- Shows remote preparation progress on stderr (spinner in TTY, `[remote]` status lines in non-TTY/CI).\n- Keeps security scan enabled by default (same as local path behavior).\n- Does not support `--fix` for URL targets (read-only workflow).\n- `watch` and `diff` are local-path only in this version.\n\n## Auto-fix Coverage\n\n`--fix` currently handles deterministic formatting/metadata issues:\n\n- `frontmatter.required`\n- `frontmatter.name_required`\n- `frontmatter.description_required`\n- `frontmatter.name_matches_directory`\n- `frontmatter.name_slug_format`\n- `frontmatter.field_order`\n- `description.use_when_phrase`\n- `description.min_recommended_length`\n- `file.trailing_newline_single`\n\nRules requiring human intent (content quality, max-length trimming, broken links, or oversized bodies) remain manual and are reported after fixes are applied.\n\nUse `--fix --interactive` for per-diagnostic approval prompts (requires TTY).\n\n## Split Oversized Skill Bodies\n\nWhen `body.max_lines` fails, use `split-body` to extract `##` sections into `references/*.md`.\n\nPreview first (no writes):\n\n```bash\nnpx skill-check split-body <skill-dir-or-file>\n```\n\nApply changes:\n\n```bash\nnpx skill-check split-body <skill-dir-or-file> --write\n```\n\nNotes:\n\n- Split is deterministic and section-based (`##` headings).\n- If a long body has no `##` headings, the command reports a blocked plan and explains what to add.\n- `split-body` is local-path only (no GitHub URL mutation flow in v1).\n- After writing, run `npx skill-check check <skill-dir-or-file> --no-security-scan`.\n- For editorial cleanup, use `docs/skills/split-into-references/SKILL.md` or [the published copy](https://github.com/thedaviddias/skill-check/blob/main/docs/skills/split-into-references/SKILL.md).\n\n## GitHub Action\n\nUse `skill-check` directly in workflows:\n\nMarketplace status: not listed in GitHub Marketplace yet.\nSupported usage today is direct repo tags (`uses: thedaviddias/skill-check@v1` or `@v1.x.y`).\nSee `docs/github-action-publishing.md` for the publication playbook.\n\n```yaml\nname: skill-check\n\non:\n  pull_request:\n  push:\n    branches: [main]\n\njobs:\n  validate:\n    runs-on: ubuntu-latest\n    steps:\n      - uses: actions/checkout@v4\n      - uses: thedaviddias/skill-check@v1\n        with:\n          path: .\n```\n\nUse `--format github` for inline annotations on PRs:\n\n```yaml\n      - run: npx skill-check check . --format github --no-security-scan\n```\n\nEnable security scan explicitly (default is disabled in the action):\n\n```yaml\nname: skill-check-security\n\non:\n  pull_request:\n\njobs:\n  validate:\n    runs-on: ubuntu-latest\n    steps:\n      - uses: actions/checkout@v4\n      - uses: thedaviddias/skill-check@v1\n        with:\n          path: .\n          security-scan: \"true\"\n          security-scan-install-policy: allow\n          security-scan-runner: pipx\n```\n\nEmit SARIF and upload to GitHub Code Scanning:\n\n```yaml\nname: skill-check-sarif\n\non:\n  pull_request:\n  push:\n    branches: [main]\n\npermissions:\n  contents: read\n  security-events: write\n\njobs:\n  validate:\n    runs-on: ubuntu-latest\n    steps:\n      - uses: actions/checkout@v4\n      - id: skillcheck\n        uses: thedaviddias/skill-check@v1\n        with:\n          path: .\n          format: sarif\n          sarif-file: reports/skill-check.sarif.json\n      - uses: github/codeql-action/upload-sarif@v3\n        with:\n          sarif_file: ${{ steps.skillcheck.outputs.sarif-file }}\n```\n\nThe action outputs:\n\n- `exit-code`: CLI exit code\n- `sarif-file`: absolute path to SARIF file when `format=sarif`\n- `command`: full command used for execution\n\n`format=sarif` cannot be combined with `security-scan=true` in the action because security scan output is not SARIF.\n\n## Action Release Checklist\n\n1. Ensure `main` contains the desired `action.yml` and `github-action/index.js`.\n2. Create and push an immutable version tag (example: `v1.2.0`).\n3. Move the major tag to the latest stable release (`v1` -> `v1.2.0` commit).\n4. Verify a workflow using `uses: thedaviddias/skill-check@v1` resolves the updated action.\n\n## Rules Reference\n\nRun `skill-check rules` to see all built-in rules with severity and fixable status.\nRun `skill-check rules <id>` for detail on a specific rule.\n\n| Rule | Default | Fixable |\n|---|---|---|\n| `frontmatter.required` | error | yes |\n| `frontmatter.name_required` | error | yes |\n| `frontmatter.description_required` | error | yes |\n| `frontmatter.name_matches_directory` | error | yes |\n| `frontmatter.name_slug_format` | error | yes |\n| `frontmatter.name_max_length` | error | no |\n| `frontmatter.field_order` | error | yes |\n| `frontmatter.unknown_fields` | warn | no |\n| `frontmatter.compatibility_max_length` | warn | no |\n| `frontmatter.metadata_string_values` | warn | no |\n| `frontmatter.allowed_tools_format` | warn | no |\n| `description.non_empty` | error | no |\n| `description.max_length` | error | no |\n| `description.use_when_phrase` | warn | yes |\n| `description.min_recommended_length` | warn | yes |\n| `body.max_lines` | error | no |\n| `body.max_tokens` | warn | no |\n| `file.trailing_newline_single` | warn | yes |\n| `links.local_markdown_resolves` | warn | no |\n| `links.references_resolve` | warn | no |\n| `duplicates.name` | warn | no |\n| `duplicates.description` | warn | no |\n\nAll rules emit actionable `suggestion` text to guide fixes.\n\n## Releasing\n\nReleases are automated with [semantic-release](https://github.com/semantic-release/semantic-release). Pushing to `main` (after CI passes) runs the release workflow: commits are analyzed for [Conventional Commits](https://www.conventionalcommits.org/) (`fix:`, `feat:`, `BREAKING CHANGE:`), the version is bumped, `CHANGELOG.md` is updated, the package is published to npm, and a GitHub release is created.\n\n- **Commit messages** are validated locally by [commitlint](https://commitlint.js.org/) (enforced by the `commit-msg` hook). Use `fix:`, `feat:`, `docs:`, `chore:`, etc.\n- **npm auth:** Use [npm Trusted Publishing (OIDC)](https://docs.npmjs.com/trusted-publishers) so you don’t need `NPM_TOKEN`. On [npmjs.com](https://www.npmjs.com/) go to the **skill-check** package → **Settings** → **Trusted publishing** → add a GitHub Actions publisher with workflow filename **`publish.yml`** (exact name, including extension). Then the workflow can publish without any npm token. Alternatively, set the `NPM_TOKEN` repository secret for token-based publish.\n\nTo simulate a release locally (without publishing): `pnpm run release:dry-run`. It will fail `verifyConditions` without `NPM_TOKEN` and `GITHUB_TOKEN`; in CI both are set.\n\n## Docs\n\n- `docs/quickstart.md`\n- `docs/github-action-publishing.md`\n- `docs/config.md`\n- `docs/rules.md`\n- `docs/plugins.md`\n- `docs/migration-from-agent-forge.md`\n","readmeFilename":"README.md"}