Validate automatically validates AI assistant code plugin structure, schemas, and compliance when user mentions validate plugin, check plugin, or plugin errors.

MITAuto-check passedAgent Workflows

Install Plugin Validator

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill plugin-validator -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace plugin-validator --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/plugin-validator .claude/skills/plugin-validator && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
plugin-validator
GitHub stars
2.8k
Token cost
~1.5k tokens
SKILL.md length
632 words
Files
11 (incl. scripts, references, assets)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Validate automatically validates AI assistant code plugin structure, schemas, and compliance when user mentions validate plugin, check plugin, or plugin errors.

  • Works in 11 steps: Identify the target plugin path from… → Validate required files exist (see… → Validate plugin.json schema → …
  • Mentions validate plugin
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 3 more sections
  • Runs Python scripts from its folder; calls jq and pnpm

What it does

Plugin Validator is an agent skill from jeremylongshore/tons-of-skills-marketplace. Validate automatically validates AI assistant code plugin structure, schemas, and compliance when user mentions validate plugin, check plugin, or plugin errors. runs comprehensive validation specific to AI assistant-code-plugins repository standards. Use when validating configurations or code. Trigger with phrases like 'validate', 'check', or 'verify'.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 13 other files, including scripts, reference files and assets (for example `assets/README.md`, `references/ARD.md` and `references/PRD.md`). Compatibility notes: Designed for Claude Code

It sits in Agent Workflows, covering Hooks and plugins. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Mentions validate plugin
  • Validating configurations
  • With phrases like validate

Example prompts

  • “validate”
  • “verify”
  • “/plugin-validator”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Grep, Bash(cmd:*)

Workflow steps

11 steps, taken from the first numbered list in SKILL.md.

  1. Identify the target plugin path from context or user request. Default to the current working directory if the path contains a…
  2. Validate required files exist (see ${CLAUDE_SKILL_DIR}/references/validation-checks.md)
  3. Validate plugin.json schema
  4. Validate frontmatter in all component files
  5. Validate directory structure matches the expected hierarchy (see ${CLAUDE_SKILL_DIR}/references/validation-checks.md for the complete…
  6. Check script permissions: find all .sh files and verify they have execute permission. Report any that lack it with a fix command.
  7. Run security scans: search for hardcoded secrets, AWS keys, private keys, dangerous commands, and suspicious URLs.
  8. Validate marketplace compliance
  9. Validate README content: confirm it contains installation, usage, and description sections.
  10. Check hook path variables: verify hooks use ${CLAUDE_PLUGIN_ROOT} instead of hardcoded absolute paths (/home/, /Users/).
  11. Compile results into a validation report following the format in ${CLAUDE_SKILL_DIR}/references/validation-report-format.md.

What it can do on your machine

Read from SKILL.md and the folder at commit 23ea8d4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Bash(cmd:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • jq
    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Plugin Validator loads about 1.5k tokens when it runs, and up to ~4.9k if it reads all its reference files. Until then it costs about 93 tokens; SKILL.md has 632 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~93
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit 23ea8d4, republished under its MIT licence (© jeremylongshore). 632 words, ~1,529 tokens.

Download SKILL.mdSave it as .claude/skills/plugin-validator/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.
name
plugin-validator
description
Validate automatically validates AI assistant code plugin structure, schemas, and compliance when user mentions validate plugin, check plugin, or plugin errors. runs comprehensive validation specific to AI assistant-code-plugins repository standards. Use when validating configurations or code. Trigger with phrases like 'validate', 'check', or 'verify'.
allowed-tools
Read, Grep, Bash(cmd:*)
compatibility
Designed for Claude Code
version
2.20.0
author
Jeremy Longshore <jeremy@intentsolutions.io>
license
MIT
tags
example, compliance, plugin-validator

Plugin Validator

Overview

Validates Claude Code plugin structure, JSON schemas, frontmatter format, security compliance, and marketplace catalog consistency. Runs the same checks as the CI pipeline to catch issues before committing.

Prerequisites

  • Read access to the target plugin directory and repository-level .claude-plugin/marketplace.extended.json
  • jq installed for JSON validation (jq empty <file>)
  • grep and find available on PATH for pattern scanning
  • ./scripts/validate-all-plugins.sh available at the repository root

Instructions

  1. Identify the target plugin path from context or user request. Default to the current working directory if the path contains a .claude-plugin/ subdirectory.
  2. Validate required files exist (see ${CLAUDE_SKILL_DIR}/references/validation-checks.md):
    • .claude-plugin/plugin.json present and valid JSON.
    • README.md present and non-empty.
    • LICENSE file present.
    • At least one component directory exists (commands/, agents/, skills/, hooks/, or mcp/).
  3. Validate plugin.json schema:
    • Confirm all required fields: name (kebab-case), version (semver x.y.z), description, author.name, author.email, license, keywords (array, minimum 2).
    • Reject any fields not in the allowed set (name, version, description, author, repository, homepage, license, keywords).
  4. Validate frontmatter in all component files:
    • Commands (commands/*.md): require name, description, model (one of sonnet, opus, haiku).
    • Agents (agents/*.md): require name, description, model.
    • Skills (skills/*/SKILL.md): require name, description; allowed-tools optional but validated against the allowed tools list if present.
  5. Validate directory structure matches the expected hierarchy (see ${CLAUDE_SKILL_DIR}/references/validation-checks.md for the complete structure diagram).
  6. Check script permissions: find all .sh files and verify they have execute permission. Report any that lack it with a fix command.
  7. Run security scans: search for hardcoded secrets, AWS keys, private keys, dangerous commands, and suspicious URLs.
  8. Validate marketplace compliance:
    • Confirm the plugin has an entry in marketplace.extended.json.
    • Verify version, name, category, and source path match between plugin.json and the catalog entry.
    • Check for duplicate plugin names.
  9. Validate README content: confirm it contains installation, usage, and description sections.
  10. Check hook path variables: verify hooks use ${CLAUDE_PLUGIN_ROOT} instead of hardcoded absolute paths (/home/, /Users/).
  11. Compile results into a validation report following the format in ${CLAUDE_SKILL_DIR}/references/validation-report-format.md.

Output

A structured validation report containing:

  • Total checks passed and failed (e.g., "8/10 PASSED")
  • Per-check results with pass/fail status
  • For each failure: the specific issue, file location, and a ready-to-run fix command
  • Warnings for non-critical issues (e.g., missing optional README sections)
  • Overall verdict: PASSED or FAILED with critical issue count
Show full SKILL.md (258 more words)Show less

Error Handling

ErrorCauseSolution
Plugin directory not foundIncorrect path providedVerify path matches plugins/[category]/[name]/ and the directory exists
jq parse error on JSONMalformed JSON in plugin.json or catalogRun jq empty <file> to locate the syntax error line
Frontmatter parse failureMissing --- delimiters or invalid YAMLEnsure YAML frontmatter is enclosed in --- lines with valid key-value pairs
Version mismatchplugin.json and marketplace.extended.json carry different versionsUpdate the stale version to match; run pnpm run sync-marketplace
Scripts not executable.sh files missing execute permissionRun chmod +x <script> for each flagged file
Disallowed fields in plugin.jsonExtra fields beyond the allowed setRemove disallowed fields; only name, version, description, author, repository, homepage, license, keywords are permitted

Examples

Validate a specific plugin: Trigger: "Validate the skills-powerkit plugin." Process: Run all 10 validation checks against plugins/community/skills-powerkit/. Identify 2 failures (script permissions, version mismatch). Provide fix commands: chmod +x scripts/*.sh and version update instruction. Report overall: FAILED (see ${CLAUDE_SKILL_DIR}/references/examples.md).

Pre-commit readiness check: Trigger: "Check if my plugin is ready to commit." Process: Detect the plugin from working directory context. Run comprehensive validation including marketplace compliance. Report PASSED or list blocking issues with fixes.

Debug CI failures: Trigger: "Why is my plugin failing CI?" Process: Run the same validation checks that CI executes (validate-all-plugins.sh). Identify the exact failure (e.g., disallowed field in plugin.json). Provide the fix command and verify the fix resolves the issue.

Resources

  • ${CLAUDE_SKILL_DIR}/references/validation-checks.md -- complete list of all 10 validation categories with specific checks
  • ${CLAUDE_SKILL_DIR}/references/validation-report-format.md -- report template with pass/fail formatting
  • ${CLAUDE_SKILL_DIR}/references/examples.md -- validation scenario walkthroughs
  • ${CLAUDE_SKILL_DIR}/references/errors.md -- error handling patterns

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 10 other files (scripts, references, assets) in skills/.curated/plugin-validator of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • assets/README.md
  • references/ARD.md
  • references/PRD.md
  • references/README.md
  • references/errors.md
  • references/examples.md
  • references/validation-checks.md
  • references/validation-report-format.md
  • scripts/README.md
  • scripts/validate_plugin_marketplace.py

Open the folder on GitHubat commit 23ea8d4

Compare with similar skills

Plugin Validator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Plugin Validator compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Plugin Validator this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.5kAutomated safety check: PassMIT
Hook Development for Claude Code Pluginsanthropics/claude-plugins-official38k11 repos~4.1kAutomated safety check: NotesApache-2.0
Claude Code Agent Developmentanthropics/claude-plugins-official38k8 repos~2.8kAutomated safety check: PassApache-2.0
Claude Code Skill Developer Guidediet103/claude-code-infrastructure-showcase10k11 repos~3.5kAutomated safety check: PassMIT
Plugin Settings Patternanthropics/claude-plugins-official38k7 repos~3kAutomated safety check: PassApache-2.0
MCP Integration for Pluginsanthropics/claude-plugins-official38k11 repos~3.1kAutomated safety check: PassApache-2.0

Similar skills

  • Hook Development for Claude Code Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to write Claude Code plugin hooks, both prompt-based checks and bash commands, for events such as PreToolUse, Stop and SessionStart.

    38k GitHub starsUsed in 11 repos~4.1k tokens
    Agent WorkflowsAuto-check: notes
  • Claude Code Agent Development

    anthropics/claude-plugins-official

    Official

    Explains how to write agents for Claude Code plugins: the markdown file with YAML frontmatter, trigger descriptions, model and color settings, and system prompt design.

    38k GitHub starsUsed in 8 repos~2.8k tokens
    Agent WorkflowsAuto-check passed
  • Claude Code Skill Developer Guide

    diet103/claude-code-infrastructure-showcase

    A guide to creating and managing Claude Code skills with auto-activation: skill-rules.json triggers, hooks, enforcement levels, YAML frontmatter and progressive disclosure.

    10k GitHub starsUsed in 11 repos~3.5k tokens
    Agent WorkflowsAuto-check passed
  • Plugin Settings Pattern

    anthropics/claude-plugins-official

    Official

    Shows how Claude Code plugins keep per-project settings and state in .claude/plugin-name.local.md files with YAML frontmatter and a markdown body.

    38k GitHub starsUsed in 7 repos~3k tokens
    Agent WorkflowsAuto-check passed
  • MCP Integration for Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.

    38k GitHub starsUsed in 11 repos~3.1k tokens
    Agent WorkflowsAuto-check passed
  • Claude Code Command Development

    anthropics/claude-plugins-official

    Official

    Explains how to write Claude Code slash commands: Markdown files with YAML frontmatter, arguments, file references, bash context and interactive prompts.

    38k GitHub starsUsed in 10 repos~4.8k tokens
    Agent WorkflowsAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Analyzing Text With NLP

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to perform natural language processing and text analysis using the nlp-text-analyzer plugin.

    2.8k GitHub starsUsed in 1 repo~819 tokens
    Auto-check passed
  • Building Neural Networks

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill allows AI assistant to construct and configure neural network architectures using the neural-network-builder plugin.

    2.8k GitHub starsUsed in 1 repo~1k tokens
    Auto-check passed
  • Detecting Data Anomalies

    jeremylongshore/tons-of-skills-marketplace

    Process identify anomalies and outliers in datasets using machine learning algorithms.

    2.8k GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • Explaining Machine Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill enables AI assistant to provide interpretability and explainability for machine learning models.

    2.8k GitHub starsUsed in 1 repo~1k tokens
    Auto-check passed
  • Optimizing Prompts

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill optimizes prompts for large language models (llms) to reduce token usage, lower costs, and improve performance.

    2.8k GitHub starsUsed in 1 repo~1k tokens
    Auto-check passed

Categories

Questions about Plugin Validator

What does Plugin Validator do?

Validate automatically validates AI assistant code plugin structure, schemas, and compliance when user mentions validate plugin, check plugin, or plugin errors. Plugin Validator is an agent skill from jeremylongshore/tons-of-skills-marketplace. Validate automatically validates AI assistant code plugin structure, schemas, and compliance when user mentions validate plugin, check plugin, or plugin errors.

When should I use Plugin Validator?

Plugin Validator fits situations like: mentions validate plugin; validating configurations; with phrases like validate.

How do I install Plugin Validator in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill plugin-validator -a claude-code`. Or copy the skill folder (skills/.curated/plugin-validator in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/plugin-validator in your project. Claude Code loads it when a task matches its description.

How do I install Plugin Validator in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill plugin-validator -a codex`. Or copy the skill folder (skills/.curated/plugin-validator in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/plugin-validator in your project. Codex loads it when a task matches its description.

Can I use Plugin Validator in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill plugin-validator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/plugin-validator, .gemini/skills/plugin-validator, .github/skills/plugin-validator and .opencode/skills/plugin-validator in your project.

What does Plugin Validator need to run?

Going by SKILL.md and its folder, Plugin Validator needs Python for the scripts in its folder and the command-line tools its instructions call (jq and pnpm). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Grep, Bash(cmd:*). Compatibility (from SKILL.md): Designed for Claude Code.

Does Plugin Validator access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Plugin Validator safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Plugin Validator use?

Plugin Validator is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Plugin Validator use?

About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.4k tokens, read only when the agent opens those files.

What are the alternatives to Plugin Validator?

Skills that share tags, products or a category with Plugin Validator: Hook Development for Claude Code Plugins (anthropics/claude-plugins-official, 38k stars), Claude Code Agent Development (anthropics/claude-plugins-official, 38k stars), Claude Code Skill Developer Guide (diet103/claude-code-infrastructure-showcase, 10k stars) and Plugin Settings Pattern (anthropics/claude-plugins-official, 38k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Plugin Validator?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,821 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 8, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.