Agent skill

Plugin Review

by athola in athola/claude-night-market

Review plugin quality with tiered checks and dependency scoping.

MITAuto-check passedTesting & QA

Install Plugin Review

skills CLI
$ npx skills add athola/claude-night-market --skill plugin-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install athola/claude-night-market plugin-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/athola/claude-night-market.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/abstract/skills/plugin-review .claude/skills/plugin-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
plugin-review
GitHub stars
342
Token cost
~1k tokens
SKILL.md length
370 words
Files
5
Skills in repo
160
Repo updated
First seen
Licence
MIT

At a glance

Review plugin quality with tiered checks and dependency scoping.

  • Works in 4 steps: Detect scope: parse --tier flag, find… → Plan: build check matrix (tier x plugin… → Execute: run checks per tier definition → …
  • PR and pre-release audits
  • SKILL.md covers Overview, When NOT To Use, Tiers and Orchestration, plus 7 more sections
  • Calls git

What it does

Plugin Review is an agent skill from athola/claude-night-market. Review plugin quality with tiered checks and dependency scoping. Use for PR and pre-release audits.

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files (for example `modules/dependency-detection.md`, `modules/tier-branch.md` and `modules/tier-pr.md`).

It sits in Testing & QA, covering Quality gates. It works with Git. The repository describes itself as: 23 Claude Code plugins: TDD enforcement hooks, git/PR workflows, spec-driven development, code review, project lifecycle, fix-from-error, maintenance automation, context… The licence is MIT.

When your agent uses it

  • PR and pre-release audits
  • Tasks that involve Quality gates

Example prompts

  • “/plugin-review”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Detect scope: parse --tier flag, find affected
  2. Plan: build check matrix (tier x plugin x role)
  3. Execute: run checks per tier definition
  4. Report: per-plugin table, aggregate verdict

What it can do on your machine

Read from SKILL.md and the folder at commit 9f3eb00. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Plugin Review loads about 1k tokens when it runs. Until then it costs about 28 tokens; SKILL.md has 370 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~28
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from athola/claude-night-market at commit 9f3eb00, republished under its MIT licence (© athola). 370 words, ~1,008 tokens.

Download SKILL.mdSave it as .claude/skills/plugin-review/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
plugin-review
description
Review plugin quality with tiered checks and dependency scoping. Use for PR and pre-release audits.
alwaysApply
false
category
plugin-management
tags
review, quality, validation, testing, architecture
dependencies
skills-eval, hooks-eval, rules-eval
tools
validate_plugin.py, skill_analyzer.py
progressive_loading
true
model_hint
standard

Plugin Review

Overview

Tiered quality review of plugins with dependency-aware scoping.

When NOT To Use

  • Reviewing one skill rather than a plugin (use abstract:skills-eval)
  • Reviewing hooks (use abstract:hooks-eval)
  • Tracing Skill() references across plugins (use abstract:skill-graph-audit)

Tiers

TierTriggerScopeDepthDuration
branchDefaultAffected and relatedQuick gates~2 min
prBefore mergeAffected and relatedStandard~5 min
releaseBefore version bumpAll 17 pluginsFull~15 min

Orchestration

  1. Detect scope: parse --tier flag, find affected plugins from git diff, resolve related plugins from docs/plugin-dependencies.json
  2. Plan: build check matrix (tier x plugin x role)
  3. Execute: run checks per tier definition
  4. Report: per-plugin table, aggregate verdict

Scope Detection

Affected plugins: git diff main --name-only filtered to plugins/*/.

Related plugins: load docs/plugin-dependencies.json, look up each affected plugin's reverse index to find dependents. Mark as "related" (lighter checks).

If --tier release or no git diff available, scope to all plugins.

Module Loading

  • Always: this SKILL.md (orchestration logic)
  • branch tier: load modules/tier-branch.md
  • pr tier: load modules/tier-branch.md then modules/tier-pr.md
  • release tier: load all tier modules plus modules/tier-release.md
  • When resolving deps: load modules/dependency-detection.md

Verdict

ResultMeaning
PASSAll checks green
PASS-WITH-WARNINGSNon-blocking issues
FAILBlocking issues found

Output Format

Plugin Review (<tier> tier)
Affected: <list>
Related:  <list> (<reason>)

Plugin          test  lint  type  reg   verdict
<name>          PASS  PASS  PASS  PASS  PASS
...

Verdict: <PASS|PASS-WITH-WARNINGS|FAIL> (N/N plugins healthy)

PR and release tiers add scorecard sections.

Show full SKILL.md (165 more words)Show less

Quality Gate Mode

The --quality-gate flag enables CI/CD integration with exit codes that distinguish warnings from failures:

  • 0: all quality gates passed
  • 1: warnings present but gates passed (non-blocking)
  • 2: quality gate failures (blocking)
  • 3: critical issues found (blocking)

Use --fail-on warning to treat warnings as blocking.

Configuration

Place a .plugin-review.yaml file in the plugin root to customize thresholds and focus areas:

yaml
plugin_review:
  quality_gates:
    structure_min: 80
    skills_min: 75
    hooks_min: 70
    tokens_max_total: 50000
    bloat_max_percentage: 15
  focus_areas:
    - skills
    - hooks
    - tokens
  exclude_patterns:
    - "*/legacy/*"
    - "*/deprecated/*"
  severity_overrides:
    missing_description: warning
    large_file: info

See the /plugin-review command reference for full usage examples.

Exit Criteria

  • The output includes a per-plugin table with columns: test, lint, type, reg, verdict, and an aggregate PASS / PASS-WITH-WARNINGS / FAIL verdict.
  • Scope detection identifies affected plugins via git diff main --name-only filtered to plugins/*/; if git diff is unavailable, the skill falls back to all-plugin scope and states this explicitly.
  • Any plugin scoring below the structure_min (default 80) or skills_min (default 75) threshold is listed as a FAIL, not a warning.
  • --quality-gate mode returns exit code 2 for blocking failures and exit code 1 for non-blocking warnings, distinguishable by the calling CI step.

© athola, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files in plugins/abstract/skills/plugin-review of athola/claude-night-market.

  • SKILL.md
  • modules/dependency-detection.md
  • modules/tier-branch.md
  • modules/tier-pr.md
  • modules/tier-release.md

Open the folder on GitHubat commit 9f3eb00

Compare with similar skills

Plugin Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Plugin Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Plugin Review this skillathola/claude-night-market342—~1kAutomated safety check: PassMIT
Verify Tests Catch the Bugdotnet/maui23k—~2.7kAutomated safety check: PassMIT
Codewhale Release QA Sweepcodewhale-hq/Codewhale41k—~1.4kAutomated safety check: PassMIT
Land The Planedralgorhythm/claude-agentic-framework124—~1.2kAutomated safety check: PassNone
Quality Gatesandymai/brepjs114—~3.2kAutomated safety check: PassApache-2.0
Block No Verify Hookwshobson/agents40k—~1.9kAutomated safety check: NotesMIT

Similar skills

  • Official

    Confirms that newly added tests actually fail without the fix, auto-detecting UI, device, unit or XAML tests and running the matching runner.

    23k GitHub stars~2.7k tokensUpdated today
    Testing & QAAuto-check passed
  • Codewhale Release QA Sweep

    codewhale-hq/Codewhale

    Runs Codewhale's automated verification gates in order on the real release branch, then exercises three manual TUI scenarios in a live terminal before anyone can call release work done.

    41k GitHub stars~1.4k tokensUpdated today
    Testing & QAAuto-check passed
  • Land The Plane

    dralgorhythm/claude-agentic-framework

    Lands in-flight work: quality gates, atomic commit, rebase, push, verified remote sync, then handoff — a user-invoked finish-line workflow.

    124 GitHub stars~1.2k tokensUpdated 2 mo ago
    Testing & QAAuto-check passed
  • Quality Gates

    andymai/brepjs

    This skill should be used when a local brepjs quality gate or npm run validate step fails and the specific rule's fix or escape hatch is needed — ESLint errors like "no-explicit-any" or "Direct .oc…

    114 GitHub stars~3.2k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Block No Verify Hook

    wshobson/agents

    Configure a PreToolUse hook to prevent AI agents from skipping git pre-commit hooks with --no-verify and other bypass flags.

    40k GitHub stars~1.9k tokensUpdated 2 days ago
    Testing & QAAuto-check: notes
  • Check Gates

    openshift-eng/ai-helpers

    Repeatedly validate and fix a Jira implementation until tests, lint, builds, requirements, production readiness, and repository cleanliness all pass.

    120 GitHub stars~818 tokensUpdated yesterday
    Testing & QAAuto-check passed

More from athola/claude-night-market

All 160 skills in this repo
  • Night Market Diagnostics Toolkit

    athola/claude-night-market

    Run and interpret repo diagnostic scripts (ratchets, validators, token stats).

    342 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Skills Eval

    athola/claude-night-market

    Evaluate Claude skill quality through auditing. An agent skill from athola/claude-night-market.

    342 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Agent Teams

    athola/claude-night-market

    Coordinates Claude agent teams via filesystem protocol. An agent skill from athola/claude-night-market.

    342 GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Delegation Core

    athola/claude-night-market

    Delegates execution to eight CLIs (Gemini, Qwen, MiniMax, GLM, Muse, Codex, OpenCode, Glimmer).

    342 GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Elegant Code

    athola/claude-night-market

    Guide minimal code via a decision ladder with full safety, edge, and negative-case coverage.

    342 GitHub stars~2.1k tokensUpdated yesterday
    Auto-check passed
  • Skill Library Mission

    athola/claude-night-market

    Build a project skill library in .claude/skills/ via discovery, parallel authoring, and review.

    342 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Plugin Review

What does Plugin Review do?

Review plugin quality with tiered checks and dependency scoping. Plugin Review is an agent skill from athola/claude-night-market. Review plugin quality with tiered checks and dependency scoping.

When should I use Plugin Review?

Plugin Review fits situations like: PR and pre-release audits; tasks that involve Quality gates.

How do I install Plugin Review in Claude Code?

Run `npx skills add athola/claude-night-market --skill plugin-review -a claude-code`. Or copy the skill folder (plugins/abstract/skills/plugin-review in athola/claude-night-market) into .claude/skills/plugin-review in your project. Claude Code loads it when a task matches its description.

How do I install Plugin Review in Codex?

Run `npx skills add athola/claude-night-market --skill plugin-review -a codex`. Or copy the skill folder (plugins/abstract/skills/plugin-review in athola/claude-night-market) into .agents/skills/plugin-review in your project. Codex loads it when a task matches its description.

Can I use Plugin Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add athola/claude-night-market --skill plugin-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/plugin-review, .gemini/skills/plugin-review, .github/skills/plugin-review and .opencode/skills/plugin-review in your project.

What does Plugin Review need to run?

Going by SKILL.md and its folder, Plugin Review needs the command-line tools its instructions call (git).

Does Plugin Review access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Plugin Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Plugin Review use?

Plugin Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Plugin Review use?

About 1k tokens (SKILL.md is roughly 4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Plugin Review?

Skills that share tags, products or a category with Plugin Review: Verify Tests Catch the Bug (dotnet/maui, 23k stars), Codewhale Release QA Sweep (codewhale-hq/Codewhale, 41k stars), Land The Plane (dralgorhythm/claude-agentic-framework, 124 stars) and Quality Gates (andymai/brepjs, 114 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Plugin Review?

athola (a GitHub user) maintains it in athola/claude-night-market, which has 342 GitHub stars. The repository holds 160 skills in this directory. The repository was last updated on October 6, 2026.

Source: athola/claude-night-market on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.