Audit automatically audits AI assistant code plugins for security vulnerabilities, best practices, AI assistant.md compliance, and quality standards when user mentions audit plugin, security review…

MITAuto-check: notesSecurity

Install Plugin Auditor

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill plugin-auditor -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace plugin-auditor --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/plugin-auditor .claude/skills/plugin-auditor && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
plugin-auditor
GitHub stars
2.8k
Token cost
~1.5k tokens
SKILL.md length
579 words
Files
11 (incl. scripts, references, assets)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Audit automatically audits AI assistant code plugins for security vulnerabilities, best practices, AI assistant.md compliance, and quality standards when user mentions audit plugin, security review…

  • Works in 8 steps: Identify the target plugin path (e.g.,… → Run a security scan across all plugin… → Validate plugin structure and best… → …
  • Mentions audit plugin
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 3 more sections
  • Calls jq and pnpm

What it does

Plugin Auditor is an agent skill from jeremylongshore/tons-of-skills-marketplace. Audit automatically audits AI assistant code plugins for security vulnerabilities, best practices, AI assistant.md compliance, and quality standards when user mentions audit plugin, security review, or best practices check. specific to AI assistant-code-plugins repositor... Use when assessing security or running audits. Trigger with phrases like 'security scan', 'audit', or 'vulnerability'.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 13 other files, including scripts, reference files and assets (for example `assets/README.md`, `references/ARD.md` and `references/PRD.md`). Compatibility notes: Designed for Claude Code

It sits in Security, covering Security review and Hooks and plugins. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Mentions audit plugin
  • Security review
  • Best practices check
  • Assessing security

Example prompts

  • “security scan”
  • “vulnerability”
  • “/plugin-auditor”

Requirements

  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Grep, Bash(cmd:*)

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Identify the target plugin path (e.g., plugins/security/plugin-name/). Confirm the directory exists and contains .claude-plugin/plugin.json.
  2. Run a security scan across all plugin files (see ${CLAUDE_SKILL_DIR}/references/audit-categories.md for full pattern list)
  3. Validate plugin structure and best practices (see ${CLAUDE_SKILL_DIR}/references/audit-process.md)
  4. Check CLAUDE.md compliance
  5. Verify marketplace compliance
  6. Assess git hygiene: no committed node_modules/, .env files, large binaries, or merge conflict markers.
  7. For MCP plugins: validate package.json dependencies, TypeScript configuration, dist/ in .gitignore, and build scripts.
  8. Generate a scored audit report following the format in ${CLAUDE_SKILL_DIR}/references/audit-report-format.md, with per-category scores out…

What it can do on your machine

Read from SKILL.md and the folder at commit 23ea8d4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Bash(cmd:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/, which the agent can run.

    Shell commands in SKILL.md call:

    • jq
    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Plugin Auditor loads about 1.5k tokens when it runs, and up to ~6k if it reads all its reference files. Until then it costs about 102 tokens; SKILL.md has 579 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~102
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:53
    hygiene: no committed `node_modules/`, `.env` files, large binaries, or merge conflict markers.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit 23ea8d4, republished under its MIT licence (© jeremylongshore). 579 words, ~1,470 tokens.

Download SKILL.mdSave it as .claude/skills/plugin-auditor/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.
name
plugin-auditor
description
Audit automatically audits AI assistant code plugins for security vulnerabilities, best practices, AI assistant.md compliance, and quality standards when user mentions audit plugin, security review, or best practices check. specific to AI assistant-code-plugins repositor... Use when assessing security or running audits. Trigger with phrases like 'security scan', 'audit', or 'vulnerability'.
allowed-tools
Read, Grep, Bash(cmd:*)
compatibility
Designed for Claude Code
version
2.20.0
author
Jeremy Longshore <jeremy@intentsolutions.io>
license
MIT
tags
example, security, compliance, audit

Plugin Auditor

Overview

Audits Claude Code plugins for security vulnerabilities, best practices compliance, CLAUDE.md standards adherence, and marketplace readiness. Produces a scored audit report covering eight categories: security, best practices, CLAUDE.md compliance, marketplace compliance, git hygiene, MCP-specific checks, performance, and UX.

Prerequisites

  • Read access to the target plugin directory and repository-level .claude-plugin/marketplace.extended.json
  • jq installed for JSON schema validation
  • grep and find available on PATH for pattern scanning
  • Familiarity with the plugin structure defined in CLAUDE.md (.claude-plugin/plugin.json, README.md, LICENSE, component directories)

Instructions

  1. Identify the target plugin path (e.g., plugins/security/plugin-name/). Confirm the directory exists and contains .claude-plugin/plugin.json.
  2. Run a security scan across all plugin files (see ${CLAUDE_SKILL_DIR}/references/audit-categories.md for full pattern list):
    • Search for hardcoded secrets, API keys, AWS access keys (AKIA...), and private key headers.
    • Detect dangerous commands (rm -rf /, eval(), exec()) and command injection vectors.
    • Flag suspicious URLs (non-HTTPS, raw IP addresses) and obfuscated code (base64 decode, hex encoding).
  3. Validate plugin structure and best practices (see ${CLAUDE_SKILL_DIR}/references/audit-process.md):
    • Confirm required files exist: plugin.json, README.md, LICENSE.
    • Verify semantic versioning format in plugin.json.
    • Check that all .sh scripts have execute permissions.
    • Scan for TODO/TODO comments without linked issues and console.log() in production code.
  4. Check CLAUDE.md compliance:
    • Verify the plugin follows the directory structure specified in the repository CLAUDE.md.
    • Confirm plugin.json contains only allowed fields (name, version, description, author, repository, homepage, license, keywords).
    • Validate that hooks use ${CLAUDE_PLUGIN_ROOT} instead of hardcoded paths.
  5. Verify marketplace compliance:
    • Confirm the plugin has an entry in marketplace.extended.json with matching name, version, category, and source path.
    • Check for duplicate plugin names in the catalog.
  6. Assess git hygiene: no committed node_modules/, .env files, large binaries, or merge conflict markers.
  7. For MCP plugins: validate package.json dependencies, TypeScript configuration, dist/ in .gitignore, and build scripts.
  8. Generate a scored audit report following the format in ${CLAUDE_SKILL_DIR}/references/audit-report-format.md, with per-category scores out of 10 and an overall quality rating.

Output

A structured audit report containing:

  • Plugin identification (name, version, category, audit date)
  • Per-category results: passed checks, failed checks with fix commands, warnings with recommendations
  • Numeric quality scores: Security (x/10), Best Practices (x/10), Compliance (x/10), Documentation (x/10)
  • Overall score and rating (Excellent / Good / Needs Work / Failed)
  • Prioritized recommendations list with estimated fix time
Show full SKILL.md (215 more words)Show less

Error Handling

ErrorCauseSolution
Plugin directory not foundIncorrect path or plugin does not existVerify the path matches plugins/[category]/[name]/ structure
plugin.json missing or invalidFile absent or malformed JSONCreate from template or fix JSON syntax with jq empty .claude-plugin/plugin.json
Marketplace entry missingPlugin not yet added to catalogAdd entry to marketplace.extended.json and run pnpm run sync-marketplace
Version mismatch detectedplugin.json and marketplace.extended.json carry different versionsUpdate the stale file to match the authoritative version
Permission denied during scanRestricted file accessRequest read permissions on the plugin directory tree

Examples

Full audit before publishing: Trigger: "Audit the security-scanner plugin." Process: Run all eight audit categories against plugins/security/security-scanner/. Generate a comprehensive report with per-category scores. Report overall rating and prioritized fix list (see ${CLAUDE_SKILL_DIR}/references/examples.md).

Publish readiness check: Trigger: "Is this plugin safe to publish?" Process: Prioritize security audit (critical), then marketplace compliance and quality scoring. Produce a publish readiness assessment with pass/fail verdict.

Featured status review: Trigger: "Quality review before featured status." Process: Run full audit with elevated quality thresholds. Apply featured plugin requirements (higher documentation and test coverage standards). Recommend approve or reject.

Resources

  • ${CLAUDE_SKILL_DIR}/references/audit-categories.md -- all eight audit categories with specific checks
  • ${CLAUDE_SKILL_DIR}/references/audit-process.md -- step-by-step audit execution procedures
  • ${CLAUDE_SKILL_DIR}/references/audit-report-format.md -- report template with scoring rubric
  • ${CLAUDE_SKILL_DIR}/references/examples.md -- audit scenario walkthroughs
  • ${CLAUDE_SKILL_DIR}/references/errors.md -- error handling patterns

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 10 other files (scripts, references, assets) in skills/.curated/plugin-auditor of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • assets/README.md
  • references/ARD.md
  • references/PRD.md
  • references/README.md
  • references/audit-categories.md
  • references/audit-process.md
  • references/audit-report-format.md
  • references/errors.md
  • references/examples.md
  • scripts/README.md

Open the folder on GitHubat commit 23ea8d4

Compare with similar skills

Plugin Auditor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Plugin Auditor compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Plugin Auditor this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.5kAutomated safety check: NotesMIT
Auditing External Claude Pluginsbitwarden/ai-plugins154—~1.8kAutomated safety check: PassCustom licence
Openiap Workflowshyodotdev/openiap154—~766Automated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
Agentlas Security Scanagentlas-ai/Agentlas-OS1.6k1 repos~822Automated safety check: PassApache-2.0

Similar skills

  • Official

    Audits an external (third-party) Claude Code plugin pinned in this marketplace for security risk before it is vendored, and writes the report to a file for downstream posting.

    154 GitHub stars~1.8k tokensUpdated yesterday
    SecurityAuto-check passed
  • Openiap Workflows

    hyodotdev/openiap

    A skill your agent uses for OpenIAP monorepo work that should follow the repository's slash-command workflows when the user asks in natural language instead of typing a slash command, including…

    154 GitHub stars~766 tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 9 days ago
    SecurityAuto-check passed
  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Agentlas Security Scan

    agentlas-ai/Agentlas-OS

    A skill your agent uses when an agent folder must pass the Agentlas Cloud 2-stage security scan (static rules + BYOK LLM judgment) before private sync or public publish, or when asked to…

    1.6k GitHub starsUsed in 1 repo~822 tokens
    SecurityAuto-check passed
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated yesterday
    SecurityAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Analyzing Text With NLP

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to perform natural language processing and text analysis using the nlp-text-analyzer plugin.

    2.8k GitHub starsUsed in 1 repo~819 tokens
    Auto-check passed
  • Building Neural Networks

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill allows AI assistant to construct and configure neural network architectures using the neural-network-builder plugin.

    2.8k GitHub starsUsed in 1 repo~1k tokens
    Auto-check passed
  • Detecting Data Anomalies

    jeremylongshore/tons-of-skills-marketplace

    Process identify anomalies and outliers in datasets using machine learning algorithms.

    2.8k GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • Explaining Machine Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill enables AI assistant to provide interpretability and explainability for machine learning models.

    2.8k GitHub starsUsed in 1 repo~1k tokens
    Auto-check passed
  • Optimizing Prompts

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill optimizes prompts for large language models (llms) to reduce token usage, lower costs, and improve performance.

    2.8k GitHub starsUsed in 1 repo~1k tokens
    Auto-check passed

Categories

Questions about Plugin Auditor

What does Plugin Auditor do?

Audit automatically audits AI assistant code plugins for security vulnerabilities, best practices, AI assistant.md compliance, and quality standards when user mentions audit plugin, security review…. Plugin Auditor is an agent skill from jeremylongshore/tons-of-skills-marketplace.md compliance, and quality standards when user mentions audit plugin, security review, or best practices check.

When should I use Plugin Auditor?

Plugin Auditor fits situations like: mentions audit plugin; security review; best practices check; assessing security.

How do I install Plugin Auditor in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill plugin-auditor -a claude-code`. Or copy the skill folder (skills/.curated/plugin-auditor in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/plugin-auditor in your project. Claude Code loads it when a task matches its description.

How do I install Plugin Auditor in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill plugin-auditor -a codex`. Or copy the skill folder (skills/.curated/plugin-auditor in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/plugin-auditor in your project. Codex loads it when a task matches its description.

Can I use Plugin Auditor in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill plugin-auditor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/plugin-auditor, .gemini/skills/plugin-auditor, .github/skills/plugin-auditor and .opencode/skills/plugin-auditor in your project.

What does Plugin Auditor need to run?

Going by SKILL.md and its folder, Plugin Auditor needs the command-line tools its instructions call (jq and pnpm). Its frontmatter pre-approves these tools: Read, Grep, Bash(cmd:*). Compatibility (from SKILL.md): Designed for Claude Code.

Does Plugin Auditor access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Plugin Auditor safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Plugin Auditor use?

Plugin Auditor is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Plugin Auditor use?

About 1.5k tokens (SKILL.md is roughly 5.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.5k tokens, read only when the agent opens those files.

What are the alternatives to Plugin Auditor?

Skills that share tags, products or a category with Plugin Auditor: Auditing External Claude Plugins (bitwarden/ai-plugins, 154 stars), Openiap Workflows (hyodotdev/openiap, 154 stars), Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars) and Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Plugin Auditor?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,821 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 8, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.