Skip to content

ci: add Tier-1 structural skill validator - #7

Merged
yarikoptic merged 1 commit into
masterfrom
ci-skill-validation
Sep 3, 2026
Merged

yarikoptic merged 1 commit into
masterfrom
ci-skill-validation

Conversation

@yarikoptic

@yarikoptic yarikoptic commented Sep 3, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Adds ci/validate_skills.py — zero-API-cost structural linter for all skills
  • Adds tox.ini — run tox -e validate locally before pushing
  • Adds .github/workflows/validate.yml — same tox -e validate in CI
  • Fixes bisect-and-patch-git-annex/SKILL.md — removes 20 hardcoded /home/yoh/proj/… paths found by the new linter

What the validator checks

Code Severity Check
E001 error YAML frontmatter present and parseable
E002 error description field non-empty
E003 error Hardcoded absolute home path (/home/<user>/ or /Users/<User>/)
E004 error Secret-like assignment outside a code fence
E005 error Python syntax error (py_compile)
E006 error subprocess(shell=True) with non-literal command (injection risk)
W001 warning name field missing
W002 warning allowed-tools field missing
W003 warning File exceeds 600 lines

Errors block the PR. Warnings are reported only.

Local usage

tox -e validate              # if tox is on PATH
uv tool run tox -e validate  # via uv (no install needed)

Why no API key

All checks are pure static analysis: YAML parsing, regex, py_compile, ast.walk.
Tier 2 (cisco-ai-skill-scanner LLM scan on PRs) can be added later once a secret is wired in.

bisect-and-patch-git-annex fix

The linter caught 20 hardcoded /home/yoh/proj/… paths — a portability violation per AGENTS.md.
Replaced with $GIT_ANNEX_SRC / $CI_LOGS_DIR env vars throughout.

Test plan

  • tox -e validate exits 0 on this branch
  • Introduce a deliberate E003 in a test → CI fails, warnings do not block

Introduces a lightweight, zero-API-cost CI check that runs on every PR
touching a SKILL.md or bundled Python script.

ci/validate_skills.py — the validator:
  E001  frontmatter present and valid YAML
  E002  required field 'description' non-empty
  W001  recommended field 'name' missing
  W002  recommended field 'allowed-tools' missing
  W003  file exceeds 600 lines
  E003  hardcoded absolute home path (/home/<user>/ or /Users/<User>/)
  E004  secret-like assignment outside a code fence
  E005  Python syntax error (py_compile)
  E006  subprocess(shell=True) with non-literal first argument

Errors cause a non-zero exit (PR fails); warnings are reported but do
not block.  Runs against every skill dir containing SKILL.md.

tox.ini — local runner:
  `tox -e validate` (or `uv tool run tox -e validate`) for the same
  check locally before pushing.  Deps: pyyaml only.

.github/workflows/validate.yml — the CI workflow:
  Triggers on PRs/pushes touching skill files, ci/, or tox.ini.
  Installs tox + tox-uv, then delegates to `tox -e validate` — same
  command the developer runs locally.

bisect-and-patch-git-annex/SKILL.md:
  Replace 20 occurrences of hardcoded /home/yoh/proj/* paths with
  $GIT_ANNEX_SRC and $CI_LOGS_DIR environment variables, and document
  them in a "Directories" prerequisite note.  Portability fix surfaced
  by the new E003 check.

Co-Authored-By: Claude Code 2.1.259 / Claude Sonnet 4.6 <noreply@anthropic.com>
@yarikoptic
yarikoptic merged commit 1a50470 into master Sep 3, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant