Agent skill

Shell Review

by athola in athola/claude-night-market

Audits shell scripts for correctness, portability, and common pitfalls.

MITAuto-check passedDevelopment

Install Shell Review

skills CLI
$ npx skills add athola/claude-night-market --skill shell-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install athola/claude-night-market shell-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/athola/claude-night-market.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/pensive/skills/shell-review .claude/skills/shell-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
shell-review
GitHub stars
341
Token cost
~1.1k tokens
SKILL.md length
264 words
Files
5
Skills in repo
154
Repo updated
First seen
Licence
MIT

At a glance

Audits shell scripts for correctness, portability, and common pitfalls.

  • Works in 6 steps: Map Context (shell-review:context-mapped) → Exit Code Audit… → Portability Check… → …
  • Reviewing shell scripts
  • SKILL.md covers Verification, Testing, Quick Start and When To Use, plus 6 more sections
  • Calls rg, shellcheck and pytest

What it does

Shell Review is an agent skill from athola/claude-night-market. Audits shell scripts for correctness, portability, and common pitfalls. Use when reviewing shell scripts or before committing shell changes.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files (for example `modules/exit-codes.md`, `modules/portability.md` and `modules/safety-patterns.md`).

It sits in Development, covering Shell scripting. The repository describes itself as: 23 Claude Code plugins: TDD enforcement hooks, git/PR workflows, spec-driven development, code review, project lifecycle, fix-from-error, maintenance automation, context… The licence is MIT.

When your agent uses it

  • Reviewing shell scripts
  • Before committing shell changes

Example prompts

  • “Use the shell-review skill to audit shell scripts for correctness, portability, and common pitfalls”
  • “/shell-review”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Map Context (shell-review:context-mapped)
  2. Exit Code Audit (shell-review:exit-codes-checked)
  3. Portability Check (shell-review:portability-checked)
  4. Safety Patterns (shell-review:safety-patterns-verified)
  5. Structure Patterns (shell-review:structure-checked)
  6. Evidence Log (shell-review:evidence-logged)

What it can do on your machine

Read from SKILL.md and the folder at commit 9f3eb00. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • rg
    • shellcheck
    • pytest

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Shell Review loads about 1.1k tokens when it runs. Until then it costs about 38 tokens; SKILL.md has 264 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~38
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from athola/claude-night-market at commit 9f3eb00, republished under its MIT licence (© athola). 264 words, ~1,071 tokens.

Download SKILL.mdSave it as .claude/skills/shell-review/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
shell-review
description
Audits shell scripts for correctness, portability, and common pitfalls. Use when reviewing shell scripts or before committing shell changes.
globs
**/*.sh
alwaysApply
false Use when reviewing shell scripts, CI scripts, hook scripts, wrapper scripts. Do not use when creating new scripts - use attune:workflow-setup.
category
build
tags
shell, bash, posix, scripting, ci, hooks
complexity
intermediate
model_hint
standard
estimated_tokens
200
progressive_loading
true
dependencies
imbue:proof-of-work, imbue:review-core, imbue:structured-output
modules
modules/exit-codes.md, modules/portability.md, modules/safety-patterns.md, modules/structure-patterns.md

Shell Script Review

Audit shell scripts for correctness, safety, and portability.

Verification

After review, run shellcheck <script> to verify fixes address identified issues.

Testing

Run pytest plugins/pensive/tests/skills/test_shell_review.py -v to validate review patterns.

Quick Start

bash
/shell-review path/to/script.sh

When To Use

  • CI/CD pipeline scripts
  • Git hook scripts
  • Wrapper scripts (run-*.sh)
  • Build automation scripts
  • Pre-commit hook implementations

When NOT To Use

  • Non-shell scripts (Python, JS, etc.)
  • One-liner commands that don't need review

Required TodoWrite Items

  1. shell-review:context-mapped
  2. shell-review:exit-codes-checked
  3. shell-review:portability-checked
  4. shell-review:safety-patterns-verified
  5. shell-review:structure-checked
  6. shell-review:evidence-logged
  7. shell-review:findings-verified

Workflow

Step 1: Map Context (shell-review:context-mapped)

Identify shell scripts:

bash
# Find shell scripts
find . -not -path "*/.venv/*" -not -path "*/__pycache__/*" \
  -not -path "*/node_modules/*" -not -path "*/.git/*" \
  -name "*.sh" -type f | head -20
# Check shebangs
rg -l "^#!/" scripts/ hooks/ 2>/dev/null | head -10
# fallback: grep -l "^#!/" scripts/ hooks/ 2>/dev/null | head -10

Document:

  • Script purpose and trigger context
  • Integration points (make, pre-commit, CI)
  • Expected inputs and outputs
Step 2: Exit Code Audit (shell-review:exit-codes-checked)

@include modules/exit-codes.md

Step 3: Portability Check (shell-review:portability-checked)

@include modules/portability.md

Step 4: Safety Patterns (shell-review:safety-patterns-verified)

@include modules/safety-patterns.md

Step 5: Structure Patterns (shell-review:structure-checked)

@include modules/structure-patterns.md

Step 6: Evidence Log (shell-review:evidence-logged)

Use imbue:proof-of-work to record findings with file:line references.

Summarize:

  • Critical issues (failures masked, security risks)
  • Major issues (portability, maintainability)
  • Minor issues (style, documentation)

Output Format

markdown
## Summary
Shell script review findings

## Scripts Reviewed
- [list with line counts]

## Exit Code Issues
### [E1] Pipeline masks failure
- Location: script.sh:42
- Anchor: `verbatim source text at file:line`
- Pattern: `cmd | grep` loses exit code
- Fix: Use pipefail or capture separately

## Portability Issues
[cross-platform concerns]

## Safety Issues
[unquoted variables, missing set flags]

## Recommendation
Approve / Approve with actions / Block

Verify Findings Are Grounded (shell-review:findings-verified)

Write findings to .review/findings.json, run the citation verifier (Skill(imbue:review-core) Step 5), and drop or label UNVERIFIED any the verifier rejects.

Exit Criteria

  • Exit code propagation verified (pipelines checked for pipefail or capture-and-check)
  • Portability issues documented (Bash-isms in #!/bin/sh scripts flagged)
  • Safety patterns verified (no echo, braced vars, :? expansion, cd in subshells, no basename/dirname)
  • Structure patterns verified (library/executable distinction, main call, preamble, depcheck, shfmt formatting)
  • Evidence logged with file:line references via imbue:proof-of-work
  • Every reported finding carries a Location + verbatim Anchor confirmed by citation_verifier.py (exit 0), or unverified findings were dropped or labeled UNVERIFIED

© athola, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files in plugins/pensive/skills/shell-review of athola/claude-night-market.

  • SKILL.md
  • modules/exit-codes.md
  • modules/portability.md
  • modules/safety-patterns.md
  • modules/structure-patterns.md

Open the folder on GitHubat commit 9f3eb00

Compare with similar skills

Shell Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Shell Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Shell Review this skillathola/claude-night-market341—~1.1kAutomated safety check: PassMIT
Mole Bug Patternstw93/Mole70k—~2kAutomated safety check: PassGPL-3.0
CLI DeveloperJeffallan/claude-skills12k1 repos~1.2kAutomated safety check: PassMIT
JSON Processing with jqcharmbracelet/crush29k—~746Automated safety check: PassCustom licence
Crush Shell Builtinscharmbracelet/crush29k—~790Automated safety check: PassCustom licence
Shellm Architecture Referencelaude-institute/headlong1.2k—~2kAutomated safety check: NotesApache-2.0

Similar skills

  • A catalog of recurring bug shapes in the Mole Mac cleaner, used to review safety-sensitive diffs for deletion safety, unbounded commands, shell traps and weak tests.

    70k GitHub stars~2k tokensUpdated today
    DevelopmentAuto-check passed
  • CLI Developer

    Jeffallan/claude-skills

    Walks through designing, building and polishing a command-line tool: user workflow and command hierarchy, implementation in commander, click, typer or cobra, completions and cross-platform testing.

    12k GitHub starsUsed in 1 repo~1.2k tokens
    DevelopmentAuto-check passed
  • JSON Processing with jq

    charmbracelet/crush

    Explains the jq command built into Crush for querying, filtering and reshaping JSON, including its supported flags and where it differs from standard jq.

    29k GitHub stars~746 tokensUpdated today
    DevelopmentAuto-check passed
  • Crush Shell Builtins

    charmbracelet/crush

    Explains how to add a new in-process builtin command to Crush's embedded POSIX shell, so it is intercepted before reaching the OS, with context polling and exit-status rules.

    29k GitHub stars~790 tokensUpdated today
    DevelopmentAuto-check passed
  • Shellm Architecture Reference

    laude-institute/headlong

    Explains how shellm's bash-based recursive LLM shell fits together - its core engine, identity system, memory, skills and trajectory log.

    1.2k GitHub stars~2k tokensUpdated 2 days ago
    DevelopmentAuto-check: notes
  • Cpp

    crazyguitar/cppcheatsheet

    Comprehensive C/C++ programming reference covering everything from C11-C23 and C++11-C++23, system programming, CUDA GPU computing, debugging tools, Rust interop, and advanced topics.

    290 GitHub stars~1.8k tokensUpdated 2 days ago
    DevelopmentAuto-check passed

More from athola/claude-night-market

All 154 skills in this repo
  • Night Market Diagnostics Toolkit

    athola/claude-night-market

    Run and interpret repo diagnostic scripts (ratchets, validators, token stats).

    341 GitHub stars~3.4k tokensUpdated 3 days ago
    Auto-check passed
  • Skills Eval

    athola/claude-night-market

    Evaluate Claude skill quality through auditing. An agent skill from athola/claude-night-market.

    341 GitHub stars~1.6k tokensUpdated 3 days ago
    Auto-check passed
  • Agent Teams

    athola/claude-night-market

    Coordinates Claude agent teams via filesystem protocol. An agent skill from athola/claude-night-market.

    341 GitHub stars~2.5k tokensUpdated 3 days ago
    Auto-check passed
  • Delegation Core

    athola/claude-night-market

    Delegates execution to eight CLIs (Gemini, Qwen, MiniMax, GLM, Muse, Codex, OpenCode, Glimmer).

    341 GitHub stars~2.5k tokensUpdated 3 days ago
    Auto-check passed
  • Elegant Code

    athola/claude-night-market

    Guide minimal code via a decision ladder with full safety, edge, and negative-case coverage.

    341 GitHub stars~2.1k tokensUpdated 3 days ago
    Auto-check passed
  • Skill Library Mission

    athola/claude-night-market

    Build a project skill library in .claude/skills/ via discovery, parallel authoring, and review.

    341 GitHub stars~1.6k tokensUpdated 3 days ago
    Auto-check passed

Categories

Questions about Shell Review

What does Shell Review do?

Audits shell scripts for correctness, portability, and common pitfalls. Shell Review is an agent skill from athola/claude-night-market. Audits shell scripts for correctness, portability, and common pitfalls.

When should I use Shell Review?

Shell Review fits situations like: reviewing shell scripts; before committing shell changes.

How do I install Shell Review in Claude Code?

Run `npx skills add athola/claude-night-market --skill shell-review -a claude-code`. Or copy the skill folder (plugins/pensive/skills/shell-review in athola/claude-night-market) into .claude/skills/shell-review in your project. Claude Code loads it when a task matches its description.

How do I install Shell Review in Codex?

Run `npx skills add athola/claude-night-market --skill shell-review -a codex`. Or copy the skill folder (plugins/pensive/skills/shell-review in athola/claude-night-market) into .agents/skills/shell-review in your project. Codex loads it when a task matches its description.

Can I use Shell Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add athola/claude-night-market --skill shell-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/shell-review, .gemini/skills/shell-review, .github/skills/shell-review and .opencode/skills/shell-review in your project.

What does Shell Review need to run?

Going by SKILL.md and its folder, Shell Review needs the command-line tools its instructions call (rg, shellcheck and pytest).

Does Shell Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Shell Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Shell Review use?

Shell Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Shell Review use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Shell Review?

Skills that share tags, products or a category with Shell Review: Mole Bug Patterns (tw93/Mole, 70k stars), CLI Developer (Jeffallan/claude-skills, 12k stars), JSON Processing with jq (charmbracelet/crush, 29k stars) and Crush Shell Builtins (charmbracelet/crush, 29k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Shell Review?

athola (a GitHub user) maintains it in athola/claude-night-market, which has 341 GitHub stars. The repository holds 154 skills in this directory. The repository was last updated on October 6, 2026.

Source: athola/claude-night-market on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.