ci: add Tier-1 structural skill validator - #7
Merged
Merged
Conversation
Introduces a lightweight, zero-API-cost CI check that runs on every PR touching a SKILL.md or bundled Python script. ci/validate_skills.py — the validator: E001 frontmatter present and valid YAML E002 required field 'description' non-empty W001 recommended field 'name' missing W002 recommended field 'allowed-tools' missing W003 file exceeds 600 lines E003 hardcoded absolute home path (/home/<user>/ or /Users/<User>/) E004 secret-like assignment outside a code fence E005 Python syntax error (py_compile) E006 subprocess(shell=True) with non-literal first argument Errors cause a non-zero exit (PR fails); warnings are reported but do not block. Runs against every skill dir containing SKILL.md. tox.ini — local runner: `tox -e validate` (or `uv tool run tox -e validate`) for the same check locally before pushing. Deps: pyyaml only. .github/workflows/validate.yml — the CI workflow: Triggers on PRs/pushes touching skill files, ci/, or tox.ini. Installs tox + tox-uv, then delegates to `tox -e validate` — same command the developer runs locally. bisect-and-patch-git-annex/SKILL.md: Replace 20 occurrences of hardcoded /home/yoh/proj/* paths with $GIT_ANNEX_SRC and $CI_LOGS_DIR environment variables, and document them in a "Directories" prerequisite note. Portability fix surfaced by the new E003 check. Co-Authored-By: Claude Code 2.1.259 / Claude Sonnet 4.6 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
ci/validate_skills.py— zero-API-cost structural linter for all skillstox.ini— runtox -e validatelocally before pushing.github/workflows/validate.yml— sametox -e validatein CIbisect-and-patch-git-annex/SKILL.md— removes 20 hardcoded/home/yoh/proj/…paths found by the new linterWhat the validator checks
descriptionfield non-empty/home/<user>/or/Users/<User>/)py_compile)subprocess(shell=True)with non-literal command (injection risk)namefield missingallowed-toolsfield missingErrors block the PR. Warnings are reported only.
Local usage
Why no API key
All checks are pure static analysis: YAML parsing, regex,
py_compile,ast.walk.Tier 2 (cisco-ai-skill-scanner LLM scan on PRs) can be added later once a secret is wired in.
bisect-and-patch-git-annex fix
The linter caught 20 hardcoded
/home/yoh/proj/…paths — a portability violation per AGENTS.md.Replaced with
$GIT_ANNEX_SRC/$CI_LOGS_DIRenv vars throughout.Test plan
tox -e validateexits 0 on this branch