Skip to content
Back to skills

Setup

ASecurity

Verify that markdownlint-cli2, the lint gate /docs-hygiene:compress requires, resolves and runs for this repository. Use when: 'set up docs-hygiene', 'is docs-hygiene ready', 'compress stopped because markdownlint-cli2 is missing', or before the first compress run. Check-only: verifies, reports the remediation, installs nothing. Re-runnable and safe.

  • 13 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 12, 2026
ai-agentsgoshellbashnode

Works with

  • claude code
  • cli

Security analysis

A92/100
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro scans all 7 files and shows the line behind each finding

Scanned October 4, 2026

npx -y skills add melodic-software/claude-code-plugins --skill setup --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Setup?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Setup
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/melodic-software-setup-7e2f47e5/badge)](https://www.skillsdirectory.com/skills/melodic-software-setup-7e2f47e5)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
description: "Verify that markdownlint-cli2, the lint gate /docs-hygiene:compress requires, resolves and runs for this repository. Use when: 'set up docs-hygiene', 'is docs-hygiene ready', 'compress stopped because markdownlint-cli2 is missing', or before the first compress run. Check-only: verifies, reports the remediation, installs nothing. Re-runnable and safe."
argument-hint: "[check]"
user-invocable: true
disable-model-invocation: true
shell: bash
---

## Purpose

Check-only setup under the Check-only carve-out (`docs/plugin-philosophy.md`, "Setup is explicit
and repeatable", in the marketplace repository). This plugin owns no consumer-project configuration
and declares no plugin options, so there is no artifact `apply` could write. Its one external
prerequisite is `markdownlint-cli2`, which `/docs-hygiene:compress` runs as its post-edit ship gate
and stops without. `check` resolves the binary, runs it, and reports the remediation. Installing is the
operator's.

Action routing: no argument or `check` runs the check. Non-interactive, never prompts.

## `check` (read-only)

Report a PASS/FAIL table with one remediation line per FAIL. Modify nothing.

1. **Resolve `markdownlint-cli2`** the way `compress` does: first `command -v markdownlint-cli2`
   (on `PATH`), then `node_modules/.bin/markdownlint-cli2` under the repository root. Report which
   one resolved. FAIL when neither does.
2. **Run it.** Execute the resolved binary with `--version`. A shim can resolve and still be broken
   (a missing Node interpreter, a dangling target), so resolution without a clean exit is FAIL, with
   the error text in the remediation line.

Remediation for a FAIL: install it explicitly, `npm install --save-dev markdownlint-cli2` in the
repository or a global install, then rerun `check`. Without it `/docs-hygiene:compress` stops at its
entry point before touching a file. No other skill in this plugin needs the binary.

## Next

`/docs-hygiene:compress`

## Gotchas

- **A missing binary is not a lint failure.** `compress` never ships unverified output, so absence
  stops it; `check` is how to see why before that happens.
- **Never install on the operator's behalf.** This skill runs no `npm`, no `npx`, and no download.

## What this skill does NOT do

- Run `markdownlint-cli2` over repository files. The only execution is the `--version` liveness probe.
- Check the consuming repository's markdownlint configuration. Which rules a repository adopts is its
  own decision.
- Write the plugin cache, Claude Code user settings, or `pluginConfigs`.

Files in this skill

  • SKILL.md6.8 KB
  • evals/evals.json3.7 KB
  • scripts/setup-apply.sh4.3 KB
  • scripts/setup-apply.test.sh5.4 KB
  • scripts/setup-check.sh9.4 KB
  • scripts/setup-check.test.sh6.1 KB
  • templates/docs-hygiene.json1.7 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…