Agent skill

Skill Contract Reviewer

by rohitg00 in rohitg00/ai-engineering-from-scratch

Validates an Agent Skill package against a portable contract with a Python checker, then picks the smallest set of instruction, capability or lifecycle primitives for the task.

MITAuto-check passedAgent Workflows

Install Skill Contract Reviewer

skills CLI
$ npx skills add rohitg00/ai-engineering-from-scratch --skill skill-contract-reviewer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install rohitg00/ai-engineering-from-scratch skill-contract-reviewer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/rohitg00/ai-engineering-from-scratch.git skills-src && mkdir -p .claude/skills && cp -r skills-src/phases/13-tools-and-protocols/22-skills-and-agent-sdks/outputs/skill-contract-reviewer .claude/skills/skill-contract-reviewer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
skill-contract-reviewer
GitHub stars
67k
Used in
1 other repo
Token cost
~450 tokens
SKILL.md length
208 words
Files
5 (incl. scripts, references, assets)
Skills in repo
16
Repo updated
First seen
Licence
MIT

At a glance

Validates an Agent Skill package against a portable contract with a Python checker, then picks the smallest set of instruction, capability or lifecycle primitives for the task.

  • Works in 7 steps: Set SKILL_ROOT to the absolute directory… → Set TARGET_ROOT to the absolute original… → Read $SKILL_ROOT/references/contract.md… → …
  • Checking that a new SKILL.md package meets the portable skill contract
  • Runs Python scripts from its folder; calls python3
  • Deciding whether a workflow should be a skill, a tool or a hook

What it does

Use this skill when a workflow is about to become a reusable agent artifact. The agent sets SKILL_ROOT to the installed skill's directory and TARGET_ROOT to the original workspace, resolves the proposed skill under it, and reads references/contract.md to validate the portable SKILL.md identity fields. It then reads references/decision-model.md to separate repository context, reusable method, external capability, lifecycle timing, deterministic logic and isolated delegation.

Before running anything it shows the exact resolved argument vector, then runs scripts/check_skill.py on the target skill and inspects the JSON report, fixing every error before discussing host-specific extensions. It compares the proposed artifact with assets/task-shapes.json and returns the smallest composable set of primitives. The output is the validation report, the selected primitives with one sentence of reasoning each, and execution evidence: script path, target path, working directory, argv and exit code, with anything the host cannot show marked unverified.

Two guardrails apply: runtime extensions must not be presented as part of the portable contract, and a valid skill is not permission to run scripts or access tools.

When your agent uses it

  • Checking that a new SKILL.md package meets the portable skill contract
  • Deciding whether a workflow should be a skill, a tool or a hook
  • Reviewing a skill before publishing it

Example prompts

  • “Validate the skill in ./skills/release-notes against the contract and list any errors.”
  • “Should this deploy checklist be a skill, a tool or a lifecycle hook? Review it.”
  • “Review my new skill folder before I publish it.”

Requirements

  • Python 3, for scripts/check_skill.py

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Set SKILL_ROOT to the absolute directory containing this installed
  2. Set TARGET_ROOT to the absolute original workspace working directory and
  3. Read $SKILL_ROOT/references/contract.md and validate the portable
  4. Read $SKILL_ROOT/references/decision-model.md and separate repository
  5. Before execution, show the exact resolved argument vector. Run
  6. Inspect the JSON report. Fix every error before discussing host-specific
  7. Compare the proposed artifact with

What it can do on your machine

Read from SKILL.md and the folder at commit 56c886c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Skill Contract Reviewer loads about 450 tokens when it runs, and up to ~975 if it reads all its reference files. Until then it costs about 37 tokens; SKILL.md has 208 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~37
When it runs · the whole SKILL.md, loaded when a task matches
~450
With references · SKILL.md plus every file in references/, read only if the agent opens them
~975

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from rohitg00/ai-engineering-from-scratch at commit 56c886c, republished under its MIT licence (© rohitg00). 208 words, ~450 tokens.

Download SKILL.mdSave it as .claude/skills/skill-contract-reviewer/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
skill-contract-reviewer
description
Validate an Agent Skill package and choose the right instruction, capability, or lifecycle primitive before implementation.
license
MIT
metadata.lesson
22

Skill contract reviewer

Use this skill when a workflow is about to become a reusable agent artifact.

  1. Set SKILL_ROOT to the absolute directory containing this installed SKILL.md. Do not assume the process working directory is the bundle.
  2. Set TARGET_ROOT to the absolute original workspace working directory and resolve the proposed skill directory under that root.
  3. Read $SKILL_ROOT/references/contract.md and validate the portable SKILL.md identity fields.
  4. Read $SKILL_ROOT/references/decision-model.md and separate repository context, reusable method, external capability, lifecycle timing, deterministic logic, and isolated delegation.
  5. Before execution, show the exact resolved argument vector. Run python3 "$SKILL_ROOT/scripts/check_skill.py" "$TARGET_SKILL", where TARGET_SKILL is the absolute proposed skill directory under TARGET_ROOT.
  6. Inspect the JSON report. Fix every error before discussing host-specific extensions.
  7. Compare the proposed artifact with $SKILL_ROOT/assets/task-shapes.json and return the smallest composable set of primitives.

Do not claim that a runtime extension is part of the portable contract. Do not treat a valid skill as permission to run scripts or access tools.

Return the validation report, the selected primitives, and one sentence explaining each selection. Include execution evidence with the resolved script path, resolved target path, cwd, exact argv, and exit code. If the host cannot expose one of those observations, mark it unverified instead of inventing it.

© rohitg00, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in phases/13-tools-and-protocols/22-skills-and-agent-sdks/outputs/skill-contract-reviewer of rohitg00/ai-engineering-from-scratch.

  • SKILL.md
  • assets/task-shapes.json
  • references/contract.md
  • references/decision-model.md
  • scripts/check_skill.py

Open the folder on GitHubat commit 56c886c

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in rohitg00/ai-engineering-from-scratch, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Skill Contract Reviewer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Skill Contract Reviewer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Skill Contract Reviewer this skillrohitg00/ai-engineering-from-scratch67k1 repos~450Automated safety check: PassMIT
Claude Code Skill Developer Guidediet103/claude-code-infrastructure-showcase10k11 repos~3.5kAutomated safety check: PassMIT
Claude Code Command Developmentanthropics/claude-plugins-official38k10 repos~4.8kAutomated safety check: PassApache-2.0
Claude Code Plugin Structureanthropics/claude-plugins-official38k10 repos~3.4kAutomated safety check: PassApache-2.0
SkillAnything Skill GeneratorAgentSkillOS/SkillAnything471—~1.9kAutomated safety check: PassMIT
DBS Skill Makerdontbesilent2025/dbskill11k—~1.2kAutomated safety check: PassCustom licence

Similar skills

  • Claude Code Skill Developer Guide

    diet103/claude-code-infrastructure-showcase

    A guide to creating and managing Claude Code skills with auto-activation: skill-rules.json triggers, hooks, enforcement levels, YAML frontmatter and progressive disclosure.

    10k GitHub starsUsed in 11 repos~3.5k tokens
    Agent WorkflowsAuto-check passed
  • Claude Code Command Development

    anthropics/claude-plugins-official

    Official

    Explains how to write Claude Code slash commands: Markdown files with YAML frontmatter, arguments, file references, bash context and interactive prompts.

    38k GitHub starsUsed in 10 repos~4.8k tokens
    Agent WorkflowsAuto-check passed
  • Claude Code Plugin Structure

    anthropics/claude-plugins-official

    Official

    Explains the directory layout, plugin.json manifest and component organization of a Claude Code plugin, including auto-discovery and portable paths.

    38k GitHub starsUsed in 10 repos~3.4k tokens
    Agent WorkflowsAuto-check passed
  • SkillAnything Skill Generator

    AgentSkillOS/SkillAnything

    Generates a complete agent skill for a target tool, API, library or workflow through a seven-phase pipeline that ends with testing, tuning and packaging for several platforms.

    471 GitHub stars~1.9k tokensUpdated 6 mo ago
    Agent WorkflowsAuto-check passed
  • DBS Skill Maker

    dontbesilent2025/dbskill

    Turns a problem you keep running into into a single installable, tested skill, and prepares a GitHub repository only when you ask to share it.

    11k GitHub stars~1.2k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Mistral Vibe Plugin Creator

    mistralai/mistral-vibe

    Official

    Shows how to build a Vibe plugin package in the Agent Plugins 1.0 format, with a plugin.json manifest and optional skills, MCP servers, hooks and other components.

    5.1k GitHub stars~3.1k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed

More from rohitg00/ai-engineering-from-scratch

All 16 skills in this repo
  • Skill Release Gate

    rohitg00/ai-engineering-from-scratch

    Evaluates an Agent Skill bundle before release for structure, trigger quality, artifact improvement, script correctness, safety, installed-tree integrity and host portability.

    67k GitHub stars~1k tokensUpdated today
    Auto-check passed
  • AI Engineering Placement Quiz

    rohitg00/ai-engineering-from-scratch

    Runs a 10-question quiz across five areas to place a learner in the AI Engineering from Scratch curriculum, so they skip what they already know.

    67k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • AI Engineering Project Tutor

    rohitg00/ai-engineering-from-scratch

    Tutors a learner through one stage of a hands-on AI engineering project per session: lesson, prediction, code, grader run and reflection, with hints but never full solutions.

    67k GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • AI Engineering Phase Quiz

    rohitg00/ai-engineering-from-scratch

    Quizzes you on a completed phase of the AI Engineering from Scratch course, taking a phase number or name and mapping it to that phase's directory.

    67k GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Claude Certification Tutor

    rohitg00/ai-engineering-from-scratch

    Guides a learner through one of four independent Claude certification tracks with onboarding, lessons, practice labs, mock exams and remediation.

    67k GitHub stars~3k tokensUpdated today
    Auto-check passed
  • AI Engineering Course Guide

    rohitg00/ai-engineering-from-scratch

    Routes a topic, question or bug to the exact lessons in the AI Engineering from Scratch curriculum and suggests the next command to run.

    67k GitHub stars~1.7k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Skill Contract Reviewer

What does Skill Contract Reviewer do?

Validates an Agent Skill package against a portable contract with a Python checker, then picks the smallest set of instruction, capability or lifecycle primitives for the task. Use this skill when a workflow is about to become a reusable agent artifact.md identity fields.

When should I use Skill Contract Reviewer?

Skill Contract Reviewer fits situations like: checking that a new SKILL.md package meets the portable skill contract; deciding whether a workflow should be a skill, a tool or a hook; reviewing a skill before publishing it.

How do I install Skill Contract Reviewer in Claude Code?

Run `npx skills add rohitg00/ai-engineering-from-scratch --skill skill-contract-reviewer -a claude-code`. Or copy the skill folder (phases/13-tools-and-protocols/22-skills-and-agent-sdks/outputs/skill-contract-reviewer in rohitg00/ai-engineering-from-scratch) into .claude/skills/skill-contract-reviewer in your project. Claude Code loads it when a task matches its description.

How do I install Skill Contract Reviewer in Codex?

Run `npx skills add rohitg00/ai-engineering-from-scratch --skill skill-contract-reviewer -a codex`. Or copy the skill folder (phases/13-tools-and-protocols/22-skills-and-agent-sdks/outputs/skill-contract-reviewer in rohitg00/ai-engineering-from-scratch) into .agents/skills/skill-contract-reviewer in your project. Codex loads it when a task matches its description.

Can I use Skill Contract Reviewer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rohitg00/ai-engineering-from-scratch --skill skill-contract-reviewer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/skill-contract-reviewer, .gemini/skills/skill-contract-reviewer, .github/skills/skill-contract-reviewer and .opencode/skills/skill-contract-reviewer in your project.

What does Skill Contract Reviewer need to run?

Going by SKILL.md and its folder, Skill Contract Reviewer needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3, for scripts/check_skill.py.

Does Skill Contract Reviewer access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Skill Contract Reviewer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Skill Contract Reviewer use?

Skill Contract Reviewer is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Skill Contract Reviewer use?

About 450 tokens (SKILL.md is roughly 1.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 525 tokens, read only when the agent opens those files.

What are the alternatives to Skill Contract Reviewer?

Skills that share tags, products or a category with Skill Contract Reviewer: Claude Code Skill Developer Guide (diet103/claude-code-infrastructure-showcase, 10k stars), Claude Code Command Development (anthropics/claude-plugins-official, 38k stars), Claude Code Plugin Structure (anthropics/claude-plugins-official, 38k stars) and SkillAnything Skill Generator (AgentSkillOS/SkillAnything, 471 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Skill Contract Reviewer?

rohitg00 (a GitHub user) maintains it in rohitg00/ai-engineering-from-scratch, which has 66,935 GitHub stars. The repository holds 16 skills in this directory. The repository was last updated on October 11, 2026.

Source: rohitg00/ai-engineering-from-scratch on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.