Agent skill

Bash Script Validator

by akin-ozer in akin-ozer/cc-devops-skills

Validate, lint, audit, or fix bash/shell/.sh scripts via ShellCheck.

Apache-2.0Auto-check passedDevelopment

Install Bash Script Validator

skills CLI
$ npx skills add akin-ozer/cc-devops-skills --skill bash-script-validator -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install akin-ozer/cc-devops-skills bash-script-validator --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/akin-ozer/cc-devops-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/devops-skills-plugin/skills/bash-script-validator .claude/skills/bash-script-validator && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
bash-script-validator
GitHub stars
319
Token cost
~1.9k tokens
SKILL.md length
825 words
Files
17 (incl. scripts)
Skills in repo
30
Repo updated
First seen
Licence
Apache-2.0

At a glance

Validate, lint, audit, or fix bash/shell/.sh scripts via ShellCheck.

  • Works in 5 steps: Preflight → Run Baseline Validation (Default Path) → Load Only Needed References → …
  • Tasks that involve Shell scripting
  • SKILL.md covers Overview, Trigger Guidance, Deterministic Execution Model and Fallback Behavior, plus 6 more sections
  • Runs Shell scripts from its folder; calls bash and sh

What it does

Bash Script Validator is an agent skill from akin-ozer/cc-devops-skills. Validate, lint, audit, or fix bash/shell/.sh scripts via ShellCheck.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 19 other files, including scripts (for example `docs/awk-reference.md`, `docs/bash-reference.md` and `docs/common-mistakes.md`).

It sits in Development, covering Shell scripting and Linting and formatting. It works with Bash. The repository describes itself as: DevOps skills for Claude Code and Codex. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Shell scripting
  • Tasks that involve Linting and formatting

Example prompts

  • “/bash-script-validator”

Requirements

  • Python 3
  • A Bash shell

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Preflight
  2. Run Baseline Validation (Default Path)
  3. Load Only Needed References
  4. Provide or Apply Fixes
  5. Rerun Policy (Mandatory After Changes)

What it can do on your machine

Read from SKILL.md and the folder at commit 276af75. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 4 files in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • bash
    • sh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Bash Script Validator loads about 1.9k tokens when it runs. Until then it costs about 23 tokens; SKILL.md has 825 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~23
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from akin-ozer/cc-devops-skills at commit 276af75, republished under its Apache-2.0 licence (© akin-ozer). 825 words, ~1,911 tokens.

Download SKILL.mdSave it as .claude/skills/bash-script-validator/SKILL.md (or your agent's skills folder). This skill also uses 16 other files; get the full folder from GitHub.
name
bash-script-validator
description
Validate, lint, audit, or fix bash/shell/.sh scripts via ShellCheck.

Bash Script Validator

Overview

This skill validates Bash and POSIX shell scripts with layered checks:

  1. Syntax validation (bash -n or sh -n)
  2. ShellCheck static analysis (system binary or wrapper fallback)
  3. Custom security, portability, and optimization checks

Use the default flow below, then branch to fallbacks only when the environment is constrained.

Trigger Guidance

Use this skill when the request includes script quality, linting, syntax checking, or shell portability work.

Trigger Phrases
  • "Validate this bash script"
  • "Lint this .sh file"
  • "Find security issues in this shell script"
  • "Why does this script fail ShellCheck?"
  • "Make this script POSIX compliant"
  • "Review this shell script before CI"
Non-Trigger Examples
  • General Linux command questions with no script file
  • Kubernetes, Terraform, or pipeline validation tasks that do not involve shell scripts
  • Pure prose editing tasks

Deterministic Execution Model

Run commands from this skill directory:

bash
cd devops-skills-plugin/skills/bash-script-validator
Step 1: Preflight
  1. Confirm target path exists and is readable.
  2. Confirm bash is available.
  3. Determine whether fixes can be applied directly (write access) or only suggested (read-only).
Step 2: Run Baseline Validation (Default Path)
bash
bash scripts/validate.sh <script-path>

For deterministic stage behavior, set the ShellCheck provider explicitly:

bash
# Modes: auto (default), system, wrapper, disabled
VALIDATOR_SHELLCHECK_MODE=system bash scripts/validate.sh <script-path>

Record:

  • Detected shell type
  • Exit code (0 clean, 1 warnings, 2 errors)
  • All reported issue lines and ShellCheck codes (SC####) when present
Step 3: Load Only Needed References

Progressive disclosure by issue type:

  • ShellCheck code explanations: docs/shellcheck-reference.md
  • General fix patterns and security mistakes: docs/common-mistakes.md
  • Bash-only behavior: docs/bash-reference.md
  • POSIX portability or bashism fixes: docs/shell-reference.md
  • Text-processing optimization issues: docs/grep-reference.md, docs/awk-reference.md, docs/sed-reference.md, docs/regex-reference.md (only when directly relevant)
Step 4: Provide or Apply Fixes

For each issue, include:

  1. Exact location from validator output (line number and snippet)
  2. Root cause
  3. Corrected code
  4. Why the change is safer or more portable
  5. Subsection-level citation (format below)

If the request includes patching files and write access is available, apply fixes in small batches grouped by issue type.

Step 5: Rerun Policy (Mandatory After Changes)

After each batch of edits, rerun the validator:

bash
bash scripts/validate.sh <script-path>

Rerun loop rules:

  1. Continue until no new errors are introduced.
  2. If warnings remain by design, document why they are intentionally accepted.
  3. If constraints prevent full resolution, report unresolved items with a clear next action.
  4. Always report the latest rerun exit code and remaining issue count.

Fallback Behavior

Use these branches only when the default flow cannot run as-is.

ConstraintFallback actionReporting requirement
shellcheck missing, wrapper availableLet scripts/validate.sh use scripts/shellcheck_wrapper.sh --cache automaticallyState that wrapper mode was used
shellcheck and wrapper unavailableRun syntax + custom checks only (validator does this)Explicitly call out reduced coverage and missing ShellCheck analysis
Python unavailable for wrapperSkip wrapper path, keep syntax + custom checksState why ShellCheck could not run
Target file is read-onlyProvide precise patch suggestions without editingMark response as "advisory only"
Target file missing or unreadableStop and request a valid file pathDo not fabricate results
Binary/non-text inputStop validationReport unsupported input type
Show full SKILL.md (345 more words)Show less

Citation Guidance for Fixes

Use subsection-level citations for every non-trivial fix.

Required citation format:

text
Reference: docs/<file>.md -> <Section> -> <Subsection>

Examples:

  • Reference: docs/common-mistakes.md -> 1. Unquoted Variables -> Solution
  • Reference: docs/shellcheck-reference.md -> SC2164: Use || exit After cd
  • Reference: docs/shell-reference.md -> POSIX Best Practices -> 5. Avoid Bashisms

Citation rules:

  1. Cite the most specific section that justifies the fix.
  2. For ShellCheck findings, include both the SC#### code and the matching section.
  3. If no exact subsection exists, cite the closest section and state that the fix is inferred from that guidance.

Response Template

Use this structure for deterministic output:

  • Validation Results
  • Command: bash scripts/validate.sh <script-path>
  • Detected shell: <shell>
  • Exit code: <code>
  • Summary: <errors> errors, <warnings> warnings, <info> info
  • Issue: <short label> (Line <n>)
  • Problem:
    bash
    <problematic snippet>
  • Fix:
    bash
    <corrected snippet>
  • Why: <short explanation>
  • Reference: docs/<file>.md -> <Section> -> <Subsection>
  • Rerun command: bash scripts/validate.sh <script-path>
  • Exit code after fixes: <code>
  • Remaining issues: <count or none>

Example Flows

Fully Automated Environment
bash
# 1) Baseline validation
bash scripts/validate.sh examples/bad-bash.sh

# 2) Apply fixes to target script
# 3) Rerun validation
bash scripts/validate.sh examples/bad-bash.sh

Expected behavior: full syntax + ShellCheck + custom-check coverage, with iterative reruns until stable.

Deterministic CI Gate
bash
# Requires a system shellcheck binary.
bash scripts/run_ci_checks.sh

This runner enforces VALIDATOR_REQUIRE_SHELLCHECK=1 and VALIDATOR_SHELLCHECK_MODE=system so CI fails if the ShellCheck stage is skipped or unavailable.

Constrained Environment (No ShellCheck Runtime)
bash
# shellcheck unavailable and wrapper cannot run
bash scripts/validate.sh examples/bad-shell.sh

Expected behavior: syntax + custom checks still run. Report reduced coverage and list what must be revalidated once ShellCheck is available.

Validator Script Details

Scripts
  • scripts/validate.sh: primary validator entrypoint
  • scripts/shellcheck_wrapper.sh: optional ShellCheck fallback using a cached Python virtual environment
Detection and Ordering

Validation order in scripts/validate.sh:

  1. File checks (exists/readable/text)
  2. Shebang-based shell detection
  3. Syntax check
  4. ShellCheck (or fallback/skip behavior)
  5. Custom checks
  6. Summary with exit code
Exit Codes
  • 0: no issues found
  • 1: warnings found
  • 2: errors found

References

Load only what is needed:

  • docs/bash-reference.md
  • docs/shell-reference.md
  • docs/shellcheck-reference.md
  • docs/common-mistakes.md
  • docs/grep-reference.md
  • docs/awk-reference.md
  • docs/sed-reference.md
  • docs/regex-reference.md

Done Criteria

This skill update is complete when all are true:

  1. Trigger guidance is explicit (positive and non-trigger examples).
  2. Default workflow is deterministic and ordered.
  3. Fallback behavior is explicit for missing tooling and constrained environments.
  4. Fix explanations include subsection-level citations.
  5. Post-fix rerun policy is mandatory and reported with exit codes.
  6. Documentation supports both fully automated and constrained execution paths.

© akin-ozer, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 16 other files (scripts) in devops-skills-plugin/skills/bash-script-validator of akin-ozer/cc-devops-skills.

  • SKILL.md
  • docs/awk-reference.md
  • docs/bash-reference.md
  • docs/common-mistakes.md
  • docs/grep-reference.md
  • docs/regex-reference.md
  • docs/sed-reference.md
  • docs/shell-reference.md
  • docs/shellcheck-reference.md
  • examples/bad-bash.sh
  • examples/bad-shell.sh
  • examples/good-bash.sh
  • examples/good-shell.sh
  • scripts/run_ci_checks.sh
  • scripts/shellcheck_wrapper.sh
  • scripts/test_validate.sh
  • scripts/validate.sh

Open the folder on GitHubat commit 276af75

Compare with similar skills

Bash Script Validator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Bash Script Validator compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Bash Script Validator this skillakin-ozer/cc-devops-skills319—~1.9kAutomated safety check: PassApache-2.0
ShellCheck Configurationwshobson/agents40k10 repos~403Automated safety check: PassMIT
Writing Bash Scriptsarchibate/dotfiles-opencode107—~413Automated safety check: PassNone
Linting Shell Scriptsagntcy/coffeeAgntcy112—~548Automated safety check: PassApache-2.0
Mole Bug Patternstw93/Mole69k—~2kAutomated safety check: PassGPL-3.0
CLI DeveloperJeffallan/claude-skills12k1 repos~1.2kAutomated safety check: PassMIT

Similar skills

  • Master ShellCheck static analysis configuration and usage for shell script quality. Use when setting up linting infrastructure, fixing code issues, or…

    40k GitHub starsUsed in 10 repos~403 tokens
    DevelopmentAuto-check passed
  • Writing Bash Scripts

    archibate/dotfiles-opencode

    Create and refactor Bash scripts following conventions (strict mode, fct naming, quoting).

    107 GitHub stars~413 tokensUpdated 5 mo ago
    DevelopmentAuto-check passed
  • Linting Shell Scripts

    agntcy/coffeeAgntcy

    Runs task shell:lint (shellcheck + shfmt) against every shell script in the repo and fixes what it reports.

    112 GitHub stars~548 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • A catalog of recurring bug shapes in the Mole Mac cleaner, used to review safety-sensitive diffs for deletion safety, unbounded commands, shell traps and weak tests.

    69k GitHub stars~2k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • CLI Developer

    Jeffallan/claude-skills

    Walks through designing, building and polishing a command-line tool: user workflow and command hierarchy, implementation in commander, click, typer or cobra, completions and cross-platform testing.

    12k GitHub starsUsed in 1 repo~1.2k tokens
    DevelopmentAuto-check passed
  • JSON Processing with jq

    charmbracelet/crush

    Explains the jq command built into Crush for querying, filtering and reshaping JSON, including its supported flags and where it differs from standard jq.

    29k GitHub stars~746 tokensUpdated yesterday
    DevelopmentAuto-check passed

More from akin-ozer/cc-devops-skills

All 30 skills in this repo
  • GitHub Actions Generator

    akin-ozer/cc-devops-skills

    Create, generate, or scaffold GitHub Actions workflows, action.yml, or .github/workflows CI/CD pipelines.

    319 GitHub stars~3.1k tokensUpdated 2 mo ago
    Auto-check passed
  • Helm Generator

    akin-ozer/cc-devops-skills

    Create, scaffold, or generate Helm charts, Chart.yaml, values.yaml, templates, helpers.

    319 GitHub stars~2.9k tokensUpdated 2 mo ago
    Auto-check passed
  • Jenkinsfile Generator

    akin-ozer/cc-devops-skills

    Generate/create/scaffold Jenkinsfile — declarative, scripted, shared library, CI/CD pipelines.

    319 GitHub stars~3.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Dockerfile Validator

    akin-ozer/cc-devops-skills

    Validate, lint, audit, or scan a Dockerfile for security and best practices.

    319 GitHub stars~2.3k tokensUpdated 2 mo ago
    Auto-check passed
  • GitHub Actions Validator

    akin-ozer/cc-devops-skills

    Validate, lint, audit, fix GitHub Actions workflows (.github/workflows).

    319 GitHub stars~4.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Jenkinsfile Validator

    akin-ozer/cc-devops-skills

    Validate, lint, audit, or check Jenkinsfiles and shared libraries.

    319 GitHub stars~2.7k tokensUpdated 2 mo ago
    Auto-check passed

Works with

Categories

Questions about Bash Script Validator

What does Bash Script Validator do?

Validate, lint, audit, or fix bash/shell/.sh scripts via ShellCheck. Bash Script Validator is an agent skill from akin-ozer/cc-devops-skills.sh scripts via ShellCheck.

When should I use Bash Script Validator?

Bash Script Validator fits situations like: tasks that involve Shell scripting; tasks that involve Linting and formatting.

How do I install Bash Script Validator in Claude Code?

Run `npx skills add akin-ozer/cc-devops-skills --skill bash-script-validator -a claude-code`. Or copy the skill folder (devops-skills-plugin/skills/bash-script-validator in akin-ozer/cc-devops-skills) into .claude/skills/bash-script-validator in your project. Claude Code loads it when a task matches its description.

How do I install Bash Script Validator in Codex?

Run `npx skills add akin-ozer/cc-devops-skills --skill bash-script-validator -a codex`. Or copy the skill folder (devops-skills-plugin/skills/bash-script-validator in akin-ozer/cc-devops-skills) into .agents/skills/bash-script-validator in your project. Codex loads it when a task matches its description.

Can I use Bash Script Validator in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add akin-ozer/cc-devops-skills --skill bash-script-validator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bash-script-validator, .gemini/skills/bash-script-validator, .github/skills/bash-script-validator and .opencode/skills/bash-script-validator in your project.

What does Bash Script Validator need to run?

Going by SKILL.md and its folder, Bash Script Validator needs a shell for the scripts in its folder and the command-line tools its instructions call (bash and sh). Our summary lists: Python 3; A Bash shell.

Does Bash Script Validator access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Bash Script Validator safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Bash Script Validator use?

Bash Script Validator is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Bash Script Validator use?

About 1.9k tokens (SKILL.md is roughly 7.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Bash Script Validator?

Skills that share tags, products or a category with Bash Script Validator: ShellCheck Configuration (wshobson/agents, 40k stars), Writing Bash Scripts (archibate/dotfiles-opencode, 107 stars), Linting Shell Scripts (agntcy/coffeeAgntcy, 112 stars) and Mole Bug Patterns (tw93/Mole, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Bash Script Validator?

akin-ozer (a GitHub user) maintains it in akin-ozer/cc-devops-skills, which has 319 GitHub stars. The repository holds 30 skills in this directory. The repository was last updated on July 26, 2026.

Source: akin-ozer/cc-devops-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.