Review Triage Phase
prisma/orm
Runs the triage step of the review-framework loop: reads fetched PR review state, builds `review-actions.json`, validates it and renders `review-actions.md`.
Runs a 6-dimension evidence-based health audit of this skills marketplace repo — code safety, docs/SSOT, security/PII, PR/issue triage, manifest integrity — via a parallel workflow, then verifies…
$ npx skills add daymade/claude-code-skills --skill marketplace-health-check -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install daymade/claude-code-skills marketplace-health-check --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/daymade/claude-code-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/marketplace-health-check .claude/skills/marketplace-health-check && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "marketplace-health-check" agent skill from https://github.com/daymade/claude-code-skills/tree/main/marketplace-health-check into .claude/skills/marketplace-health-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "marketplace-health-check", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/daymade/claude-code-skills/tree/main/marketplace-health-checkType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add daymade/claude-code-skills --skill marketplace-health-check -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install daymade/claude-code-skills marketplace-health-check --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/daymade/claude-code-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/marketplace-health-check .agents/skills/marketplace-health-check && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "marketplace-health-check" agent skill from https://github.com/daymade/claude-code-skills/tree/main/marketplace-health-check into .agents/skills/marketplace-health-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "marketplace-health-check", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add daymade/claude-code-skills --skill marketplace-health-check -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install daymade/claude-code-skills marketplace-health-check --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/daymade/claude-code-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/marketplace-health-check .cursor/skills/marketplace-health-check && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "marketplace-health-check" agent skill from https://github.com/daymade/claude-code-skills/tree/main/marketplace-health-check into .cursor/skills/marketplace-health-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "marketplace-health-check", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/daymade/claude-code-skills.git --path marketplace-health-check--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add daymade/claude-code-skills --skill marketplace-health-check -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install daymade/claude-code-skills marketplace-health-check --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/daymade/claude-code-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/marketplace-health-check .gemini/skills/marketplace-health-check && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "marketplace-health-check" agent skill from https://github.com/daymade/claude-code-skills/tree/main/marketplace-health-check into .gemini/skills/marketplace-health-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "marketplace-health-check", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install daymade/claude-code-skills marketplace-health-checkInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add daymade/claude-code-skills --skill marketplace-health-check -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/daymade/claude-code-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/marketplace-health-check .github/skills/marketplace-health-check && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "marketplace-health-check" agent skill from https://github.com/daymade/claude-code-skills/tree/main/marketplace-health-check into .github/skills/marketplace-health-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "marketplace-health-check", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add daymade/claude-code-skills --skill marketplace-health-check -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install daymade/claude-code-skills marketplace-health-check --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/daymade/claude-code-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/marketplace-health-check .opencode/skills/marketplace-health-check && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "marketplace-health-check" agent skill from https://github.com/daymade/claude-code-skills/tree/main/marketplace-health-check into .opencode/skills/marketplace-health-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "marketplace-health-check", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
marketplace-health-checkRuns a 6-dimension evidence-based health audit of this skills marketplace repo — code safety, docs/SSOT, security/PII, PR/issue triage, manifest integrity — via a parallel workflow, then verifies…
Marketplace Health Check is an agent skill from daymade/claude-code-skills. Runs a 6-dimension evidence-based health audit of this skills marketplace repo — code safety, docs/SSOT, security/PII, PR/issue triage, manifest integrity — via a parallel workflow, then verifies findings by priority. Use for 全面体检 / 检查仓库状态 / 审计一下仓库, a pre-release sweep, or "is this repo OK" even without saying "workflow". Not for building marketplace.json (use marketplace-dev) or cache drift (use skill-governance).
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts and reference files (for example `references/health-check-methodology.md` and `scripts/repo-health-check.workflow.js`).
It sits in Development, covering Issue triage. The repository describes itself as: Professional Claude Code skills marketplace featuring production-ready skills for enhanced development workflows. The licence is MIT.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 0e52df5. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (JavaScript), which the agent can run.
Shell commands in SKILL.md call:
ghjqgitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh and git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Marketplace Health Check loads about 2k tokens when it runs, and up to ~3.8k if it reads all its reference files. Until then it costs about 111 tokens; SKILL.md has 954 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from daymade/claude-code-skills at commit 0e52df5, republished under its MIT licence (© daymade). 954 words, ~2,026 tokens.
.claude/skills/marketplace-health-check/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Run a comprehensive, evidence-based health check of this Claude Code skills marketplace repo using a parallel fan-out Dynamic Workflow. Six independent inspectors cover, in parallel:
except, injection, missing shebangs.security-scan-passed marker gap, case-file auditscheck_marketplace.sh + check_doc_skill_lists.py, orphans, suite registrationThen YOU verify the serious findings and report by priority. The bundled script (scripts/repo-health-check.workflow.js) is the proven, ready-to-run workflow; this file is how to run and interpret it.
The six dimensions are independent, so fanning them out across six parallel agents is far faster than one agent sweeping serially, and each inspector stays focused on one concern with its own structured output.
This skill must run inline (no context: fork). It orchestrates parallel agents through the Workflow tool, and a forked subagent cannot spawn subagents or launch a workflow — running it forked would silently break the fan-out. The Workflow tool also requires explicit user opt-in; a user asking to "run the health check" IS that opt-in, so proceed.
The workflow script takes an args object so all agents share one accurate snapshot instead of each re-discovering it. Gather:
gh repo view --json nameWithOwner,stargazerCount,isPrivate | jq -c .
echo "skills: $(find . -name SKILL.md -not -path '*-workspace/*' | wc -l | tr -d ' ')"
echo "open PRs: $(gh pr list --state open --json number | jq length)"
echo "open issues: $(gh issue list --state open --json number | jq length)"
grep -A1 '"metadata"' .claude-plugin/marketplace.json | grep -oE '"version": "[^"]*"' | head -1
git rev-parse --short HEAD; gh release view --json tagName -q .tagName 2>/dev/nullConfirm isPrivate: false before treating PII as a publishing risk — the whole point is that this is a PUBLIC repo.
Read the bundled script and launch it inline via the script parameter (pass its contents, so there's no dependency on where the skill is installed):
Workflow({
script: <full contents of scripts/repo-health-check.workflow.js>,
args: { repo: "<owner/name>", scale: "<one-line summary from Step 1>" }
})It runs the six inspectors in parallel (~15-20 min, ~400-500k output tokens — tell the user the cost up front) and returns { checks: [...] }, one structured result per dimension: health + summary + findings[] (each with severity / title / detail / location / recommendation) + stats.
While it runs you can do other useful prep, but don't start editing files the inspectors are reading.
Agent findings are HYPOTHESES, not conclusions. Never relay them verbatim. For every high/critical finding, verify it yourself with a quick command — grep the leaked value, sed -n the broken line, gh repo view the claimed state — confirming it's (a) real, (b) located where the agent says, and (c) not over-reach. This catches false alarms AND, just as important, agent recommendations that are actively wrong. (In the session this skill was distilled from, a security inspector recommended adding the real private domains into the public .gitleaks.toml — an anti-target move that had to be rejected; see the methodology reference.)
Filter every finding through four questions: probability (does it really happen?), cost (fix vs ignore), real scenario (does it bite in practice?), verifiable (can a 1-line command confirm or refute it?).
Lead with the table, then layer by priority. Classify — don't dump:
Tag each surfaced item ✅ real / ⚠️ partly / ❌ false-alarm. Most raw agent output is noise; your job is to surface the real risks the owner didn't already know, not to forward 25 findings for them to sift.
Apply these when interpreting findings and proposing fixes. Full reasoning + the real failure cases behind each are in references/health-check-methodology.md — read it before acting on PII or PR/issue findings.
.gitleaks.toml) — a public list enumerating real assets is itself a leak. Sanitize the value in place; detection rules for real private values belong in the owner's private global guard, not in this public repo..security-scan-passed marker means "no known-format secret was found", NOT "sanitized". It is blind to keyword-free leaks, so pair it with a human/semantic read of any skill shipping real-data examples.version in marketplace.json (and a CHANGELOG entry). External-contributor PRs almost always miss this — flag it, don't merge without it.scripts/repo-health-check.workflow.js — the six-inspector Dynamic Workflow. Run it via the Workflow tool's script param (Step 2). Edit it when you add/retire an inspector dimension.references/health-check-methodology.md — the Counter-Review filter, reporting discipline, and the anti-target / history / scan-marker / decline rules, each with the real failure case that motivated it.After delivering the report, the typical follow-ups are owner decisions, not automated actions — fixing the verified HIGHs (sanitize PII, correct broken commands), or triaging the PR/issue backlog. Surface them as options; don't auto-fix or auto-comment on PRs/issues without the user's go-ahead, since those are outward-facing and affect external contributors.
© daymade, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (scripts, references) in marketplace-health-check of daymade/claude-code-skills.
Open the folder on GitHubat commit 0e52df5
Marketplace Health Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Marketplace Health Check this skilldaymade/claude-code-skills | 1.4k | — | ~2k | Automated safety check: Pass | MIT | |
| Review Triage Phaseprisma/orm | 48k | — | ~995 | Automated safety check: Pass | Apache-2.0 | |
| Triagearcee-ai/nac | 281 | — | ~2k | Automated safety check: Pass | Apache-2.0 | |
| Harbor Issue and PR IntakeYeachan-Heo/oh-my-claudecode | 40k | — | ~5.4k | Automated safety check: Pass | MIT | |
| To Ticketsstevesolun/ctx | 588 | — | ~416 | Automated safety check: Pass | MIT | |
| Setup Matt Pocock Skillsnodetool-ai/nodetool | 560 | — | ~589 | Automated safety check: Pass | AGPL-3.0 |
prisma/orm
Runs the triage step of the review-framework loop: reads fetched PR review state, builds `review-actions.json`, validates it and renders `review-actions.md`.
arcee-ai/nac
Triage a GitHub repository's open issues by finding exact duplicates, rejecting evidenceably off-base requests, requesting concrete clarification, applying only existing labels, and opening a linked…
Yeachan-Heo/oh-my-claudecode
Triages incoming issues and pull requests for a maintainer: verifies claims, reuses past decisions and delivers a docket of open questions, and never merges.
stevesolun/ctx
Break a plan, spec, or conversation into dependency-aware, independently verifiable tickets.
nodetool-ai/nodetool
Configure repository issue-tracker, triage-label, and domain-document conventions when setup or reconfiguration is requested.
bestofjs/bestofjs
Plan a huge chunk of work — more than one agent session can hold — as a shared map of decision tickets on your issue tracker, and resolve them one at a time until the way to the destination is clear.
daymade/claude-code-skills
This skill should be used when comparing two videos to analyze compression results or quality differences.
daymade/claude-code-skills
Generates professional animated CLI demos as GIFs using VHS terminal recordings.
daymade/claude-code-skills
Converts DOCX/PDF/PPTX and saved HTML/HTM to high-quality Markdown with automatic post-processing.
daymade/claude-code-skills
Generates several distinct, clickable HTML interaction prototypes for one product surface into a Design Board and collects selection/remix feedback before implementation.
daymade/claude-code-skills
Creates, edits and benchmarks skills; supersedes the official skill-creator plugin, so when both are listed, use this one.
daymade/claude-code-skills
Diagnoses and repairs repository setup and guarded Git workflows for Claude Code or Codex — environment repair, startup sync, hook auditing, collaborator handoff.
Categories
Runs a 6-dimension evidence-based health audit of this skills marketplace repo — code safety, docs/SSOT, security/PII, PR/issue triage, manifest integrity — via a parallel workflow, then verifies…. Marketplace Health Check is an agent skill from daymade/claude-code-skills. Runs a 6-dimension evidence-based health audit of this skills marketplace repo — code safety, docs/SSOT, security/PII, PR/issue triage, manifest integrity — via a parallel workflow, then verifies findings by priority.
Marketplace Health Check fits situations like: 全面体检 / 检查仓库状态 / 审计一下仓库; A pre-release sweep; is this repo OK even without saying workflow.
Run `npx skills add daymade/claude-code-skills --skill marketplace-health-check -a claude-code`. Or copy the skill folder (marketplace-health-check in daymade/claude-code-skills) into .claude/skills/marketplace-health-check in your project. Claude Code loads it when a task matches its description.
Run `npx skills add daymade/claude-code-skills --skill marketplace-health-check -a codex`. Or copy the skill folder (marketplace-health-check in daymade/claude-code-skills) into .agents/skills/marketplace-health-check in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add daymade/claude-code-skills --skill marketplace-health-check -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/marketplace-health-check, .gemini/skills/marketplace-health-check, .github/skills/marketplace-health-check and .opencode/skills/marketplace-health-check in your project.
Going by SKILL.md and its folder, Marketplace Health Check needs JavaScript for the scripts in its folder and the command-line tools its instructions call (gh, jq and git). Our summary lists: Node.js.
SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Marketplace Health Check is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 8.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.7k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Marketplace Health Check: Review Triage Phase (prisma/orm, 48k stars), Triage (arcee-ai/nac, 281 stars), Harbor Issue and PR Intake (Yeachan-Heo/oh-my-claudecode, 40k stars) and To Tickets (stevesolun/ctx, 588 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
daymade (a GitHub user) maintains it in daymade/claude-code-skills, which has 1,448 GitHub stars. The repository holds 104 skills in this directory. The repository was last updated on October 10, 2026.
Source: daymade/claude-code-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.