Back to skills
SKILL.md
Audit Plugin
ASecurityUse when the user asks to audit or validate a plugin, check its structure or .claude-plugin/plugin.json, review components, or confirm compliance. Also trigger after plugin components change. Audit the whole plugin here; use audit-skill for one skill.
- 7 stars
- 0 votes
- 0 copies
- 1 view
- Added September 2, 2026
Security analysis
100/100Pro scans all 20 files and shows the line behind each finding
npx -y skills add richfrem/agent-plugins-skills --skill audit-plugin --agent claude-codeAre you the author of Audit Plugin?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/richfrem-audit-plugin-agent-plugins-skills)---
name: audit-plugin
plugin: agent-scaffolders
description: >
Use when the user asks to audit or validate a plugin, check its structure or
.claude-plugin/plugin.json, review components, or confirm compliance. Also trigger
after plugin components change. Audit the whole plugin here; use audit-skill for one skill.
allowed-tools: Bash, Read, Write, Glob, Grep
---
# Audit Plugin (`audit-plugin`)
Performs comprehensive validation of a plugin against structure standards, naming conventions, and component requirements.
## Contents
- [Dependencies](#dependencies)
- [Constraints](#constraints)
- [Quick start](#quick-start)
- [Workflow](#workflow)
- [Verification](#verification)
- [References](#references)
## Dependencies
Requires Python 3.8+ and standard library modules.
## Constraints
- **File-level symlinks only**: Directory symlinks violate plugin architecture policy.
- **Hub-first asset layout**: Reusable scripts and references live in plugin root hub, symlinked into skills.
- **Portability**: No hardcoded paths (`/Users/`, `/home/`); use relative paths or `${CLAUDE_PLUGIN_ROOT}`.
- **Manifest schema**: `.claude-plugin/plugin.json` author field must be an object `{"name": "...", "email": "..."}`.
## Quick start
```bash
python3 scripts/audit_plugin_structure.py plugins/<plugin-name>
```
## Workflow
1. **Structure & Manifest**: Verify `.claude-plugin/plugin.json` exists with object author schema.
2. **Component Linting**: Validate agents, hooks (`validate_hook_schema.py`), and skills.
3. **Symlink Hygiene**: Verify spoke symlinks resolve cleanly to plugin root hubs.
4. **Contract Compliance**: Confirm `evals/evals.json` routing arrays use `should_trigger` boolean schema.
5. **Security Scan**: Verify zero hardcoded tokens, secrets, or machine-specific absolute paths.
## Verification
```bash
# Validate plugin structure compliance
python3 scripts/audit_plugin_structure.py plugins/<plugin-name>
# Audit marketplace source paths (if marketplace.json present)
python3 scripts/audit_marketplace_sources.py .
```
## References
- [audit-plugin-guide.md](references/audit-plugin-guide.md) — Comprehensive audit rules and error codes.
- [acceptance-criteria.md](references/acceptance-criteria.md) — Plugin validation acceptance criteria.
- [fallback-tree.md](references/fallback-tree.md) — Escalation protocol for structural audit failures.
Files in this skill
- SKILL.md
- acceptance-criteria.md
- assets/templates/README.md.jinja
- assets/templates/SKILL.md.jinja
- assets/templates/agent.md.jinja
- assets/templates/command.md.jinja
- assets/templates/execute.py.jinja
- evals/evals.json
- evals/results.tsv
- fallback-tree.md
- plugin.json
- references/ADRs/001_cross_plugin_script_dependencies.md
- references/ADRs/002_multi_skill_script_centralization.md
- references/ADRs/003_plugin_skill_resource_sharing_via_mirrored_folder_structure_and_file_level_symlinks.md
- references/ADRs/004_self_contained_plugins_no_cross_plugin_dependencies.md
- references/ADRs/005_plugin_separation_of_concerns_and_loose_coupling.md
- references/ADRs/006_python_native_plugin_bootstrap_installer.md
- references/acceptance-criteria.md
- references/fallback-tree.md
- references/hitl-interaction-design.md
Attribution
Comments
Loading comments…