BREAKING CHANGES: - Remove -cskill suffix from all skill names (use standard kebab-case) - Simplify marketplace.json to only official fields (fixes Issue #5) - SKILL.md body must be <500 lines (progressive disclosure via references/) New features: - Cross-platform support for 8+ platforms (Claude Code, Copilot, Cursor, Windsurf, Cline, Codex CLI, Gemini CLI) - scripts/install-template.sh: Auto-detect platform installer with --dry-run - scripts/validate.py: Spec compliance checker for generated skills - scripts/security_scan.py: Security scanner for hardcoded keys and dangerous patterns - MIGRATION.md: v3.x to v4.0 migration guide - 6 new reference files for progressive disclosure from lean SKILL.md Key changes: - SKILL.md: 4,116 → 272 lines with spec-compliant YAML frontmatter - marketplace.json: Stripped to {name, plugins} only - article-to-prototype-cskill/ → article-to-prototype/ - stock-analyzer-cskill/ → stock-analyzer/ - Export system integrates validation + security scanning - README.md rewritten for all supported platforms - Phase 5 pipeline outputs SKILL.md-first, spec-compliant skills Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
1.4 KiB
1.4 KiB
SC-055: Validate Existing Skill Reports Specific Issues
Covers: FR-011, FR-012, Section 2.2 — Secondary flow: Validate existing skill with issues Type: Failure
Given
- An existing skill directory
broken-tool/with:- SKILL.md with
name: Broken_Tool(invalid format) - Description of 1500 characters (exceeds 1024 limit)
scripts/main.pycontainingAPI_KEY = "sk-secret123"- A
.envfile with database credentials
- SKILL.md with
When
- The user invokes: "Validate this skill: broken-tool/"
Then
- Spec validation fails with specific errors:
- Invalid name format (uppercase, underscore)
- Description exceeds 1024 characters
- Name does not match directory name
- Security scan reports findings:
- Hardcoded API key in scripts/main.py
- .env file with credentials
- Fix suggestions are provided for each issue
Verification Method
Method: Automated test
Steps:
- Create
broken-tool/with the described invalid files - Call
validate_skill("broken-tool/") - Assert
result.valid is False - Assert
result.errorshas >=3 entries (name format, description length, directory mismatch) - Assert
result.securityhas >=2 entries (hardcoded key, .env file)
Expected evidence: valid: False. Errors list includes name format, description length, and directory mismatch issues. Security list includes hardcoded key and .env file findings. Each finding includes a fix suggestion.