All skills
moizibnyousaf avatar

/review-a-skill

@e605968

Use when evaluating whether a skill belongs in a library. Preview content, check frontmatter, validate structure, and decide whether to keep, curate, or remove.

Use this Skill: https://skilld.dev/gh/moizibnyousaf/ai-agent-skills/review-a-skill

This session only. Nothing lands on disk.

SKILL.md

≈44 tokens always: the name and description. ≈518 when used: this file.

Review A Skill

Goal

Evaluate a single skill's quality, relevance, and safety before it enters or stays in a library.

Guardrails

  • Always use --format json for machine-readable output in automated pipelines.
  • Always use --fields to limit output size when inspecting catalog entries.
  • Always use --dry-run before curating or removing a skill.
  • Never remove a skill without first checking if other skills depend on it via info --format json dependencies.

Workflow

  1. Preview the skill content to check for quality and safety.
npx ai-agent-skills preview <skill-name>

The preview command sanitizes content — if it flags sanitization, investigate before proceeding.

  1. Inspect the catalog entry for metadata completeness.
npx ai-agent-skills info <skill-name> --format json --fields name,description,tags,collections,dependencies
  1. Validate the skill's SKILL.md structure.
npx ai-agent-skills validate <skill-name>
  1. If the skill needs curation (notes, collections, verification):
npx ai-agent-skills curate <skill-name> --notes "Reviewed: solid patterns" --verify --dry-run
npx ai-agent-skills curate <skill-name> --notes "Reviewed: solid patterns" --verify
  1. If the skill should be removed:
npx ai-agent-skills curate <skill-name> --remove --dry-run
npx ai-agent-skills curate <skill-name> --remove --yes

Decision Criteria

  • Keep: Clear description, valid frontmatter, useful to the library's audience, no injection patterns.
  • Curate: Needs better whyHere, collection placement, or verification status.
  • Remove: Duplicate, outdated, broken source, or contains suspicious content.

Gotchas

  • The preview command only works for vendored (house) skills. Upstream skills show description and whyHere only.
  • The validate command checks frontmatter structure but not content quality — that requires human or agent judgment.
  • Removing a skill that other skills depend on will break the dependency graph. Always check dependencies.usedBy first.

Source: SKILL.md on GitHub

1 warning13d3 checks · Risk SAFE
  • Gen Agent Trust Hub13d

    The skill provides a workflow for reviewing and managing other agent skills using the platform's standard CLI utility. It includes safety-oriented instructions for auditing other skills and contains no malicious code.

  • Socket13d

    No alerts

  • Snyk13d

    Risk: MEDIUM · 1 issue

Signed by skilld at e605968. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub last week.

Activeupdated 6 months ago
category
workflow
version
4.1.0

README badge

README badge for moizibnyousaf/ai-agent-skills/review-a-skill