Agent skill

Marketplace Health Check

by daymade in daymade/claude-code-skills

Runs a 6-dimension evidence-based health audit of this skills marketplace repo — code safety, docs/SSOT, security/PII, PR/issue triage, manifest integrity — via a parallel workflow, then verifies…

MITAuto-check passedDevelopment

Install Marketplace Health Check

skills CLI
$ npx skills add daymade/claude-code-skills --skill marketplace-health-check -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install daymade/claude-code-skills marketplace-health-check --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/daymade/claude-code-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/marketplace-health-check .claude/skills/marketplace-health-check && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
marketplace-health-check
GitHub stars
1.4k
Token cost
~2k tokens
SKILL.md length
954 words
Files
3 (incl. scripts, references)
Skills in repo
104
Repo updated
First seen
Licence
MIT

At a glance

Runs a 6-dimension evidence-based health audit of this skills marketplace repo — code safety, docs/SSOT, security/PII, PR/issue triage, manifest integrity — via a parallel workflow, then verifies…

  • Works in 3 steps: Scout the current scale (one quick pass,… → Launch the workflow → Counter-Review the serious findings…
  • 全面体检 / 检查仓库状态 / 审计一下仓库
  • SKILL.md covers Why a workflow — and why it…, How to run, Report format and Judgment principles, plus 2 more sections
  • Runs JavaScript scripts from its folder; calls gh, jq and git

What it does

Marketplace Health Check is an agent skill from daymade/claude-code-skills. Runs a 6-dimension evidence-based health audit of this skills marketplace repo — code safety, docs/SSOT, security/PII, PR/issue triage, manifest integrity — via a parallel workflow, then verifies findings by priority. Use for 全面体检 / 检查仓库状态 / 审计一下仓库, a pre-release sweep, or "is this repo OK" even without saying "workflow". Not for building marketplace.json (use marketplace-dev) or cache drift (use skill-governance).

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts and reference files (for example `references/health-check-methodology.md` and `scripts/repo-health-check.workflow.js`).

It sits in Development, covering Issue triage. The repository describes itself as: Professional Claude Code skills marketplace featuring production-ready skills for enhanced development workflows. The licence is MIT.

When your agent uses it

  • 全面体检 / 检查仓库状态 / 审计一下仓库
  • A pre-release sweep
  • Is this repo OK even without saying workflow

Example prompts

  • “is this repo OK”
  • “workflow”
  • “/marketplace-health-check”

Requirements

  • Node.js

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Scout the current scale (one quick pass, shared by all six agents)
  2. Launch the workflow
  3. Counter-Review the serious findings BEFORE reporting

What it can do on your machine

Read from SKILL.md and the folder at commit 0e52df5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • gh
    • jq
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Marketplace Health Check loads about 2k tokens when it runs, and up to ~3.8k if it reads all its reference files. Until then it costs about 111 tokens; SKILL.md has 954 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~111
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from daymade/claude-code-skills at commit 0e52df5, republished under its MIT licence (© daymade). 954 words, ~2,026 tokens.

Download SKILL.mdSave it as .claude/skills/marketplace-health-check/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
marketplace-health-check
description
Runs a 6-dimension evidence-based health audit of this skills marketplace repo — code safety, docs/SSOT, security/PII, PR/issue triage, manifest integrity — via a parallel workflow, then verifies findings by priority. Use for 全面体检 / 检查仓库状态 / 审计一下仓库, a pre-release sweep, or "is this repo OK" even without saying "workflow". Not for building marketplace.json (use marketplace-dev) or cache drift (use skill-governance).

Marketplace Health Check

Run a comprehensive, evidence-based health check of this Claude Code skills marketplace repo using a parallel fan-out Dynamic Workflow. Six independent inspectors cover, in parallel:

  1. Code & script safety — dangerous deletes, NO-FALLBACK secret leaks, hardcoded real paths, bare except, injection, missing shebangs
  2. Documentation / SSOT consistency — version coherence across marketplace.json / README×2 / CHANGELOG / git release, skill & plugin counts, broken references, derived-value drift
  3. Security / PII — keyword-free leaks gitleaks can't catch (real names, private domains), the .security-scan-passed marker gap, case-file audits
  4. Open-PR triage — classify every PR (worth-merging / needs-changes / decline-as-promotion)
  5. Open-issue triage — real bugs vs skill-requests vs promotion, plus the broken-install-command bug class
  6. Marketplace-manifest integrity — check_marketplace.sh + check_doc_skill_lists.py, orphans, suite registration

Then YOU verify the serious findings and report by priority. The bundled script (scripts/repo-health-check.workflow.js) is the proven, ready-to-run workflow; this file is how to run and interpret it.

Why a workflow — and why it MUST run inline

The six dimensions are independent, so fanning them out across six parallel agents is far faster than one agent sweeping serially, and each inspector stays focused on one concern with its own structured output.

This skill must run inline (no context: fork). It orchestrates parallel agents through the Workflow tool, and a forked subagent cannot spawn subagents or launch a workflow — running it forked would silently break the fan-out. The Workflow tool also requires explicit user opt-in; a user asking to "run the health check" IS that opt-in, so proceed.

How to run

Step 1 — Scout the current scale (one quick pass, shared by all six agents)

The workflow script takes an args object so all agents share one accurate snapshot instead of each re-discovering it. Gather:

bash
gh repo view --json nameWithOwner,stargazerCount,isPrivate | jq -c .
echo "skills: $(find . -name SKILL.md -not -path '*-workspace/*' | wc -l | tr -d ' ')"
echo "open PRs: $(gh pr list --state open --json number | jq length)"
echo "open issues: $(gh issue list --state open --json number | jq length)"
grep -A1 '"metadata"' .claude-plugin/marketplace.json | grep -oE '"version": "[^"]*"' | head -1
git rev-parse --short HEAD; gh release view --json tagName -q .tagName 2>/dev/null

Confirm isPrivate: false before treating PII as a publishing risk — the whole point is that this is a PUBLIC repo.

Step 2 — Launch the workflow

Read the bundled script and launch it inline via the script parameter (pass its contents, so there's no dependency on where the skill is installed):

Workflow({
  script: <full contents of scripts/repo-health-check.workflow.js>,
  args: { repo: "<owner/name>", scale: "<one-line summary from Step 1>" }
})

It runs the six inspectors in parallel (~15-20 min, ~400-500k output tokens — tell the user the cost up front) and returns { checks: [...] }, one structured result per dimension: health + summary + findings[] (each with severity / title / detail / location / recommendation) + stats.

While it runs you can do other useful prep, but don't start editing files the inspectors are reading.

Step 3 — Counter-Review the serious findings BEFORE reporting

Agent findings are HYPOTHESES, not conclusions. Never relay them verbatim. For every high/critical finding, verify it yourself with a quick command — grep the leaked value, sed -n the broken line, gh repo view the claimed state — confirming it's (a) real, (b) located where the agent says, and (c) not over-reach. This catches false alarms AND, just as important, agent recommendations that are actively wrong. (In the session this skill was distilled from, a security inspector recommended adding the real private domains into the public .gitleaks.toml — an anti-target move that had to be rejected; see the methodology reference.)

Filter every finding through four questions: probability (does it really happen?), cost (fix vs ignore), real scenario (does it bite in practice?), verifiable (can a 1-line command confirm or refute it?).

Show full SKILL.md (435 more words)Show less

Report format

Lead with the table, then layer by priority. Classify — don't dump:

  • One-line verdict + a 6-dimension health table (good / minor-issues / needs-attention / critical per dimension)
  • 🔴 Must-fix — each VERIFIED high/critical, with exact location + a concrete fix
  • 🟠 Backlog — PR/issue triage outcomes, scan-marker gaps (decisions, often outward-facing — flag that they affect external contributors)
  • 🟢 Optional — low/info nits, one line each
  • 💡 Key insights — the meta-findings worth surfacing (a structural blind spot in tooling, a recurring bug class)

Tag each surfaced item ✅ real / ⚠️ partly / ❌ false-alarm. Most raw agent output is noise; your job is to surface the real risks the owner didn't already know, not to forward 25 findings for them to sift.

Judgment principles

Apply these when interpreting findings and proposing fixes. Full reasoning + the real failure cases behind each are in references/health-check-methodology.md — read it before acting on PII or PR/issue findings.

  • Anti-target: never "fix" a PII leak by listing the real value in a public allowlist (e.g. the repo's own .gitleaks.toml) — a public list enumerating real assets is itself a leak. Sanitize the value in place; detection rules for real private values belong in the owner's private global guard, not in this public repo.
  • History note: sanitizing the working copy cleans the current version, but a pre-existing leak still sits in git history. Flag the history exposure honestly; a history rewrite (force-push) is a separate high-risk decision that affects every fork — never do it unprompted.
  • Scan marker = necessary-not-sufficient: a .security-scan-passed marker means "no known-format secret was found", NOT "sanitized". It is blind to keyword-free leaks, so pair it with a human/semantic read of any skill shipping real-data examples.
  • Mandatory version bump: any change to a skill's files requires bumping that skill's version in marketplace.json (and a CHANGELOG entry). External-contributor PRs almost always miss this — flag it, don't merge without it.
  • Promotion is declined by default: third-party directory / tool / marketplace promotion PRs and issues are declined — the repo is a personal curated marketplace, not an ecosystem directory. The decline-policy template is a reference doc at the repo root (outside this skill's bundle).

Bundled resources

  • scripts/repo-health-check.workflow.js — the six-inspector Dynamic Workflow. Run it via the Workflow tool's script param (Step 2). Edit it when you add/retire an inspector dimension.
  • references/health-check-methodology.md — the Counter-Review filter, reporting discipline, and the anti-target / history / scan-marker / decline rules, each with the real failure case that motivated it.

Next step

After delivering the report, the typical follow-ups are owner decisions, not automated actions — fixing the verified HIGHs (sanitize PII, correct broken commands), or triaging the PR/issue backlog. Surface them as options; don't auto-fix or auto-comment on PRs/issues without the user's go-ahead, since those are outward-facing and affect external contributors.

© daymade, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts, references) in marketplace-health-check of daymade/claude-code-skills.

  • SKILL.md
  • references/health-check-methodology.md
  • scripts/repo-health-check.workflow.js

Open the folder on GitHubat commit 0e52df5

Compare with similar skills

Marketplace Health Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Marketplace Health Check compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Marketplace Health Check this skilldaymade/claude-code-skills1.4k—~2kAutomated safety check: PassMIT
Review Triage Phaseprisma/orm48k—~995Automated safety check: PassApache-2.0
Triagearcee-ai/nac281—~2kAutomated safety check: PassApache-2.0
Harbor Issue and PR IntakeYeachan-Heo/oh-my-claudecode40k—~5.4kAutomated safety check: PassMIT
To Ticketsstevesolun/ctx588—~416Automated safety check: PassMIT
Setup Matt Pocock Skillsnodetool-ai/nodetool560—~589Automated safety check: PassAGPL-3.0

Similar skills

  • Official

    Runs the triage step of the review-framework loop: reads fetched PR review state, builds `review-actions.json`, validates it and renders `review-actions.md`.

    48k GitHub stars~995 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Triage

    arcee-ai/nac

    Triage a GitHub repository's open issues by finding exact duplicates, rejecting evidenceably off-base requests, requesting concrete clarification, applying only existing labels, and opening a linked…

    281 GitHub stars~2k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Harbor Issue and PR Intake

    Yeachan-Heo/oh-my-claudecode

    Triages incoming issues and pull requests for a maintainer: verifies claims, reuses past decisions and delivers a docket of open questions, and never merges.

    40k GitHub stars~5.4k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • To Tickets

    stevesolun/ctx

    Break a plan, spec, or conversation into dependency-aware, independently verifiable tickets.

    588 GitHub stars~416 tokensUpdated 7 days ago
    DevelopmentAuto-check passed
  • Setup Matt Pocock Skills

    nodetool-ai/nodetool

    Configure repository issue-tracker, triage-label, and domain-document conventions when setup or reconfiguration is requested.

    560 GitHub stars~589 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Wayfinder

    bestofjs/bestofjs

    Plan a huge chunk of work — more than one agent session can hold — as a shared map of decision tickets on your issue tracker, and resolve them one at a time until the way to the destination is clear.

    3.1k GitHub starsUsed in 21 repos~2.9k tokens
    DevelopmentAuto-check passed

More from daymade/claude-code-skills

All 104 skills in this repo
  • Video Comparer

    daymade/claude-code-skills

    This skill should be used when comparing two videos to analyze compression results or quality differences.

    1.5k GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check: notes
  • CLI Demo Generator

    daymade/claude-code-skills

    Generates professional animated CLI demos as GIFs using VHS terminal recordings.

    1.5k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Doc To Markdown

    daymade/claude-code-skills

    Converts DOCX/PDF/PPTX and saved HTML/HTM to high-quality Markdown with automatic post-processing.

    1.5k GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Interaction Design Board

    daymade/claude-code-skills

    Generates several distinct, clickable HTML interaction prototypes for one product surface into a Design Board and collects selection/remix feedback before implementation.

    1.5k GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Skill Creator

    daymade/claude-code-skills

    Creates, edits and benchmarks skills; supersedes the official skill-creator plugin, so when both are listed, use this one.

    1.5k GitHub stars~4.4k tokensUpdated today
    Auto-check passed
  • Auto Repo Setup

    daymade/claude-code-skills

    Diagnoses and repairs repository setup and guarded Git workflows for Claude Code or Codex — environment repair, startup sync, hook auditing, collaborator handoff.

    1.5k GitHub stars~2.9k tokensUpdated today
    Auto-check: notes

Questions about Marketplace Health Check

What does Marketplace Health Check do?

Runs a 6-dimension evidence-based health audit of this skills marketplace repo — code safety, docs/SSOT, security/PII, PR/issue triage, manifest integrity — via a parallel workflow, then verifies…. Marketplace Health Check is an agent skill from daymade/claude-code-skills. Runs a 6-dimension evidence-based health audit of this skills marketplace repo — code safety, docs/SSOT, security/PII, PR/issue triage, manifest integrity — via a parallel workflow, then verifies findings by priority.

When should I use Marketplace Health Check?

Marketplace Health Check fits situations like: 全面体检 / 检查仓库状态 / 审计一下仓库; A pre-release sweep; is this repo OK even without saying workflow.

How do I install Marketplace Health Check in Claude Code?

Run `npx skills add daymade/claude-code-skills --skill marketplace-health-check -a claude-code`. Or copy the skill folder (marketplace-health-check in daymade/claude-code-skills) into .claude/skills/marketplace-health-check in your project. Claude Code loads it when a task matches its description.

How do I install Marketplace Health Check in Codex?

Run `npx skills add daymade/claude-code-skills --skill marketplace-health-check -a codex`. Or copy the skill folder (marketplace-health-check in daymade/claude-code-skills) into .agents/skills/marketplace-health-check in your project. Codex loads it when a task matches its description.

Can I use Marketplace Health Check in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add daymade/claude-code-skills --skill marketplace-health-check -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/marketplace-health-check, .gemini/skills/marketplace-health-check, .github/skills/marketplace-health-check and .opencode/skills/marketplace-health-check in your project.

What does Marketplace Health Check need to run?

Going by SKILL.md and its folder, Marketplace Health Check needs JavaScript for the scripts in its folder and the command-line tools its instructions call (gh, jq and git). Our summary lists: Node.js.

Does Marketplace Health Check access the network?

SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Marketplace Health Check safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Marketplace Health Check use?

Marketplace Health Check is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Marketplace Health Check use?

About 2k tokens (SKILL.md is roughly 8.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.7k tokens, read only when the agent opens those files.

What are the alternatives to Marketplace Health Check?

Skills that share tags, products or a category with Marketplace Health Check: Review Triage Phase (prisma/orm, 48k stars), Triage (arcee-ai/nac, 281 stars), Harbor Issue and PR Intake (Yeachan-Heo/oh-my-claudecode, 40k stars) and To Tickets (stevesolun/ctx, 588 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Marketplace Health Check?

daymade (a GitHub user) maintains it in daymade/claude-code-skills, which has 1,448 GitHub stars. The repository holds 104 skills in this directory. The repository was last updated on October 10, 2026.

Source: daymade/claude-code-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.