Skip to content
Back to skills

Prerequisites

ASecurity

Read-only report of external tools the enabled plugin fleet declares, and which of them are missing. Use when a hook says a formatter or CLI is missing, or when asking whether this machine has what the enabled plugins need. Never installs.

  • 20 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 29, 2026
ai-agentsgoshellbashnodegit

Works with

  • claude code
  • cli
  • mcp

Security analysis

A92/100
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro scans all 4 files and shows the line behind each finding

Scanned October 4, 2026

npx -y skills add melodic-software/claude-code-plugins --skill prerequisites --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Prerequisites?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Prerequisites
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/melodic-software-prerequisites/badge)](https://www.skillsdirectory.com/skills/melodic-software-prerequisites)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
description: "Read-only report of external tools the enabled plugin fleet declares, and which of them are missing. Use when a hook says a formatter or CLI is missing, or when asking whether this machine has what the enabled plugins need. Never installs."
user-invocable: true
disable-model-invocation: false
metadata:
  workflow-stage: operator
  summary: Report external tools the enabled fleet declares missing. Never installs.
  cadence: weekly
---

## Purpose

Answer "does this host have what the enabled plugins need?" Read `prerequisites.json` in each enabled plugin, resolve each declared dependency with the shared Node checker, and print one table. Do not install, download, or run `npx`.

**Claim:** the fleet check lives here, not as a `deps` action on `plugins` and not as a machine-health category. `plugins` brings marketplace versions current and is `disable-model-invocation: true`. This question is read-only and model-invocable. Each plugin that needs an external dependency declares it in `prerequisites.json` at the plugin root, in the schema `docs/conventions/prerequisites/` owns, which this skill and the per-plugin check both read. **Basis:** [skills](https://code.claude.com/docs/en/skills), `disable-model-invocation` ("Set to `true` to prevent Claude from automatically loading this skill. ... Default: `false`."), fetched 2026-09-28. **As of:** 2026-09-28. **Recheck:** a Claude Code release adds a manifest field for external binaries, or `plugins` becomes model-invocable for a read-only action.

## Run

```bash
node "${CLAUDE_SKILL_DIR}/scripts/check-prerequisites.mjs"
```

The table columns are plugin, id, kind, need, status, the check skill, and the install hints. `missing=N present=M` is the last line. The status is `present`, `missing`, `outdated` (below its version floor), `unverified` (the version could not be read) or `agent-check` (an MCP server only the agent can see). Exit 1 means a required entry is missing or below its floor, and a missing optional entry leaves exit 0. Exit 2 means no plugin roots could be read, the listing was not JSON, or a `prerequisites.json` fails the schema.

With no arguments and a `claude` executable on PATH, the script reads the enabled set and each `installPath` from `claude plugin list --json`. That output lists installs across every project, so it keeps user and managed rows, and project or local rows only when their `projectPath` is the current project (`CLAUDE_PROJECT_DIR`, else the git toplevel); an id resolves by its most specific scope, so user-enabled and project-disabled is disabled. When `claude` is absent or prints nothing, it merges `enabledPlugins` from the settings files instead: the user settings in `~/.claude` (`CLAUDE_CONFIG_DIR` overrides that directory) and the project's `.claude/settings.json` and `settings.local.json`. A file holding any non-Boolean `enabledPlugins` value contributes none of its keys, and the managed scope is not read there. Output that is not a JSON list stops the run with exit 2 instead. Only when none of that state exists does it scan `plugins/*/prerequisites.json` in the current repository; a state with nothing enabled prints an empty table.

**Claim:** `claude plugin list --json` returns one row per install with `id`, `scope`, `enabled`, `installPath` and, for project and local rows, `projectPath`, and an id's most specific scope decides whether it is enabled. **Basis:** the `plugin list --json` output observed on Claude Code 2.1.284 (user and project rows only; a managed row was not observed), and the `enabledPlugins` precedence managed > `--settings` > local > project > user recorded in [scope-semantics.md](../plugins/context/scope-semantics.md) from the [settings](https://code.claude.com/docs/en/settings) page. **As of:** 2026-09-29. **Recheck:** a release note changes `plugin list --json` fields or its scope values, or the settings page changes the `enabledPlugins` precedence.

## Next

- A formatter or linter binary is missing: /actionlint:check, /bash-format:check, /biome-format:check, /go-format:check, /markdown-format:check, /powershell-format:check, /ruff-format:check or /typos-format:check
- Record the whole machine's facts and identity domains, not only binaries: /harness-ops:machine-profile
- The fleet's versions, a different question: /harness-ops:plugins audit

## Gotchas

Node is the only runtime this skill needs; the checker is `lib/prerequisites.mjs`, generated from the repository's canonical copy. A plugin whose `prerequisites.json` is still in the retired `tools` shape fails the schema and exits 2.

A missing row is a report, not an install. Do not run `npx`, `npm install`, or `go install` from this skill.

The table's `check` column names the skill for that row. When that skill is model-invocable, run it. When it is a setup skill (a `:setup check` command), it is human-only, so the model cannot invoke it and can only relay the command: tell the user to type it and show the row's install command. Install nothing unless the user asked.

Files in this skill

  • SKILL.md2.5 KB
  • evals/evals.json2.1 KB
  • scripts/check-prerequisites.sh5.7 KB
  • scripts/check-prerequisites.test.sh3.6 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…