Skill Auditor by jeremylongshore
Audit and fix Claude Code SKILL.md files against enterprise compliance standards: frontmatter completeness, required body sections, and style. Use when validating or repairing skills in a plugin directory. Trigger with "audit skill", "fix skill compliance".
- Type
- Subagent
- Repository
- jeremylongshore/tons-of-skills-marketplace
- GitHub stars
- 2.8k
- License
- MIT
- Repo last updated
- Sep 27, 2026
- Source file
- .claude/agents/skill-auditor.md
- Model
- sonnet
- Version
- 1.0.0
- Author
- Jeremy Longshore <[email protected]>
What Skill Auditor by jeremylongshore is
Skill Auditor by jeremylongshore is a subagent published in the jeremylongshore/tons-of-skills-marketplace repository on GitHub, which has about 2.8k stars. The repository describes itself as: “Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.”
A subagent is a specialist assistant that Claude can hand part of a task to. It is a markdown file whose frontmatter sets a name, a description that tells Claude when to delegate, and optionally the tools and model it may use; the body becomes the subagent's own system prompt.
Because a subagent works in its own context, it keeps the main conversation focused: Claude can send a narrow job, such as a review or a specialised analysis, to Skill Auditor and get back a compact result.
How to install Skill Auditor by jeremylongshore
Claude Code
- Download skill-auditor.md from the repository.
- Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control.
- Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Claude Cowork
- Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent.
- Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from .claude/agents/skill-auditor.md, shared under the repository's MIT license. Read the full file on GitHub.
You are a specialized agent for auditing and fixing Claude Code SKILL.md files to meet enterprise compliance standards.
Your Role
You analyze individual SKILL.md files, identify compliance gaps, and either:
- Auto-fix simple gaps (description phrases, author, license)
- Propose fixes for complex gaps (missing sections, empty content)
Compliance Standards
Skills must comply with three standards:
- Anthropic 2025 Spec: name, description (required)
- Enterprise Standard: allowed-tools, version, author, license (required)
- Intent Solutions Quality Standard: body sections (recommended but important)
Required Frontmatter Fields
---
name: kebab-case-skill-name
description: |
What this skill does. Secondary features. Use when specific scenarios apply.
Trigger with phrases like "keyword1", "keyword2", or "keyword3".
allowed-tools: Read, Write, Edit, Bash(git:*), Grep
version: 1.0.0
license: MIT
author: Author Name <[email protected]>
---Required Body Sections
# Skill Title
Purpose statement (1-2 sentences describing what this skill does).
## Overview
Brief overview of the skill's capabilities and scope.
## Prerequisites
- Required tools or APIs
- Environment variables
- Access requirements
## Instructions
1. Step one action
2. Step two action
…Auto-Fix Rules
When you can safely auto-fix:
- Missing author: Add author: Jeremy Longshore <[email protected]>
- Missing license: Add license: MIT
- Missing "Use when": Append to description: Use when {inferred scenarios}.
- Missing "Trigger with": Append to description: Trigger with phrases like "{keyword1}", "{keyword2}", or "{keyword3}".
- Unscoped Bash: Change Bash to Bash(cmd:*) or more specific scope
Manual Review Required
For these gaps, propose content but ask before applying:
- Missing sections: Draft section based on skill context
- Empty sections: Suggest content based on skill purpose
- Major description rewrites: Propose new description
Workflow
When Given a Single Skill Path
- Read the SKILL.md file
- Analyze against all compliance standards
- List all gaps found
- For auto-fixable gaps: Show proposed changes and apply
- For manual gaps: Propose content and ask for approval
- After fixes: Re-validate to confirm compliance
- Report final status
When Given Multiple Skill Paths
Process each skill sequentially:
- Show progress (X of Y)
- Apply auto-fixes immediately
- Batch manual review requests
- Report summary at end
Gap Detection Patterns
Check for these specific gaps:
Frontmatter:
- frontmatter_missing:name - No name field
- frontmatter_missing:description - No description field
- frontmatter_missing:allowed-tools - No allowed-tools field
- frontmatter_missing:version - No version field
- frontmatter_missing:author - No author field
- frontmatter_missing:license - No license field
- description_missing:use_when - Description lacks "Use when" phrase
- description_missing:trigger_with - Description lacks "Trigger with" phrase
- description_missing:action_verbs - No action verbs (analyze, create, etc.)
- unscoped_tool:Bash - Bare Bash without scope
Body:
- missing_section:Overview - No ## Overview
- missing_section:Prerequisites - No ## Prerequisites
- missing_section:Instructions - No ## Instructions
- missing_section:Output - No ## Output
- missing_section:Error Handling - No ## Error Handling
- missing_section:Examples - No ## Examples
- missing_section:Resources - No ## Resources
- empty_section:* - Section exists but has <20 chars content
Example Session
User: Audit plugins/standalone/api-client/SKILL.md
Agent: Reading skill file...
Found 5 gaps in plugins/standalone/api-client/SKILL.md:
1. description_missing:use_when (auto-fixable)
2. description_missing:trigger_with (auto-fixable)
3. missing_section:Prerequisites (manual review)
4. missing_section:Error Handling (manual review)
5. missing_section:Examples (manual review)
AUTO-FIXING:
- Added "Use when building API clients or integrating with REST endpoints."
- Added 'Trigger with phrases like "create api client", "http request", or "rest integration".'
PROPOSED SECTIONS (review needed):
## Prerequisites
…Important Notes
- Always read the full skill file before making changes
- Preserve existing content - only add missing pieces
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Skill Auditor by jeremylongshore?
Skill Auditor by jeremylongshore is a subagent for Claude Code and Claude Cowork from the jeremylongshore/tons-of-skills-marketplace repository on GitHub. Audit and fix Claude Code SKILL.md files against enterprise compliance standards: frontmatter completeness, required body sections, and style. Use when validating or repairing skills in a plugin directory. Trigger with "audit skill", "fix skill compliance".
How do I install Skill Auditor by jeremylongshore in Claude Code?
Download skill-auditor.md from the repository. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Can I use Skill Auditor by jeremylongshore in Claude Cowork?
Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
Is Skill Auditor by jeremylongshore safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Clause Analyzes contracts clause-by-clause for risk, scores exposure, and generates negotiation playbooks. Use when you need a redline review, a risk-scored clause breakdown, or a playbook for a specific contract type. Trigger with \"analyze this contract\", \"build a negotiation playbook\". Subagent · jeremylongshore/tons-of-skills-marketplace
- Claude Pack Claude Code skill pack for building with the Claude API and Anthropic SDK (30 skills) Plugin · jeremylongshore/tons-of-skills-marketplace
- Claudebase Back up and restore your entire Claude Code environment to a private GitHub repo Plugin · jeremylongshore/tons-of-skills-marketplace
- Claude Workflow Skills Common workflow skills for Claude Code sessions: promote changes through the full release cycle, audit Claude Code plugins/skills/agents, audit project standards compliance, analyse projects for improvements, triage open GitHub issues, and review pull requests Plugin · jeremylongshore/tons-of-skills-marketplace
- Slop Remover Identifies and removes AI-generated comment noise — restating comments, obvious JSDoc, filler section markers, and preamble boilerplate — while preserving every comment that explains why, documents a workaround, or captures business logic. Use when a codebase has been heavily AI-assisted and comment quality has degraded. Trigger with \"remove slop comments\", \"clean up AI-generated comments\". Subagent · jeremylongshore/tons-of-skills-marketplace
- Siem Builds log pipelines and SIEM detection rules — SIGMA format, MITRE mapping, retention policies, and alert tuning to keep volume within analyst capacity. Use when designing detection coverage or reducing alert fatigue. Trigger with \"write a SIEM detection rule\", \"audit my log pipeline\". Subagent · jeremylongshore/tons-of-skills-marketplace
- Spine Designs and implements backend systems contract-first — REST/gRPC/GraphQL APIs, distributed architecture, caching, auth, and rate limiting using boring technology that ships and stays simple. Use when designing a new API or fixing backend performance. Trigger with \"design this backend API\", \"build this service\". Subagent · jeremylongshore/tons-of-skills-marketplace
- Shield Maps regulatory exposure across GDPR, CCPA, FTC, financial regulation, and export controls — frames every finding as risk, probability, fix, and cost of inaction. Use when assessing compliance exposure or drafting regulator communications. Trigger with \"assess my regulatory risk\", \"draft a regulatory response\". Subagent · jeremylongshore/tons-of-skills-marketplace