Agent skill

Validate Plugin

by ruvnet in ruvnet/ruflo

Validate a Claude Code plugin structure, frontmatter, and MCP tool references

MITAuto-check: notesAgent Workflows

Install Validate Plugin

skills CLI
$ npx skills add ruvnet/ruflo --skill validate-plugin -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ruvnet/ruflo validate-plugin --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ruvnet/ruflo.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/ruflo-plugin-creator/skills/validate-plugin .claude/skills/validate-plugin && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
validate-plugin
GitHub stars
74k
Token cost
~511 tokens
SKILL.md length
227 words
Files
1
Skills in repo
264
Repo updated
First seen
Licence
MIT

At a glance

Validate a Claude Code plugin structure, frontmatter, and MCP tool references

  • Works in 10 steps: Directory structure —… → plugin.json schema — required fields… → Skills auto-discovery — every… → …
  • Tasks that involve Hooks and plugins
  • SKILL.md covers When to use, Checks performed and Steps
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Validate Plugin is an agent skill from ruvnet/ruflo. Validate a Claude Code plugin structure, frontmatter, and MCP tool references

Its SKILL.md is about 510 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows, covering Hooks and plugins and MCP servers. The repository describes itself as: 🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory…. The licence is MIT.

When your agent uses it

  • Tasks that involve Hooks and plugins
  • Tasks that involve MCP servers

Example prompts

  • “/validate-plugin”

Requirements

  • Pre-approved tools (allowed-tools): mcp__plugin_ruflo-core_ruflo__transfer_plugin-info, Bash, Read, Glob, Grep

Workflow steps

10 steps, taken from the first numbered list in SKILL.md.

  1. Directory structure — .claude-plugin/plugin.json exists at plugin root
  2. plugin.json schema — required fields present (name, description, version)
  3. Skills auto-discovery — every skills//SKILL.md is a valid skill (Claude Code auto-discovers from directory; plugin.json MUST NOT list a…
  4. Commands auto-discovery — every commands/.md is a valid command (auto-discovered; no commands array in plugin.json)
  5. Agents auto-discovery — every agents/.md is a valid agent (auto-discovered; no agents array in plugin.json)
  6. No legacy arrays in plugin.json — presence of skills, commands, or agents arrays in plugin.json is a validation error (they cause Claude…
  7. SKILL.md frontmatter — each skill has name, description, and allowed-tools (no wildcards)
  8. Agent frontmatter — each agent has name, description, and model
  9. No files in wrong locations — skills/commands/agents not inside .claude-plugin/
  10. MCP tool references — tools in allowed-tools are valid mcpplugin_ruflo-core_ruflo* identifiers

What it can do on your machine

Read from SKILL.md and the folder at commit de590e1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • mcp__plugin_ruflo-core_ruflo__transfer_plugin-info
    • Bash
    • Read
    • Glob
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Validate Plugin loads about 511 tokens when it runs. Until then it costs about 23 tokens; SKILL.md has 227 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~23
When it runs · the whole SKILL.md, loaded when a task matches
~511

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: mcp__plugin_ruflo-core_ruflo__transfer_plugin-info, Bash, Read, Glob, Grep

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ruvnet/ruflo at commit de590e1, republished under its MIT licence (© ruvnet). 227 words, ~511 tokens.

Download SKILL.mdSave it as .claude/skills/validate-plugin/SKILL.md (or your agent's skills folder).
name
validate-plugin
description
Validate a Claude Code plugin structure, frontmatter, and MCP tool references
allowed-tools
mcp__plugin_ruflo-core_ruflo__transfer_plugin-info, Bash, Read, Glob, Grep
argument-hint
[plugin-path]

Validate Plugin

Validate that a plugin follows the correct Claude Code plugin format.

When to use

After creating or modifying a plugin, run validation to catch structural issues before publishing.

Checks performed

  1. Directory structure — .claude-plugin/plugin.json exists at plugin root
  2. plugin.json schema — required fields present (name, description, version)
  3. Skills auto-discovery — every skills/<name>/SKILL.md is a valid skill (Claude Code auto-discovers from directory; plugin.json MUST NOT list a skills array)
  4. Commands auto-discovery — every commands/<name>.md is a valid command (auto-discovered; no commands array in plugin.json)
  5. Agents auto-discovery — every agents/<name>.md is a valid agent (auto-discovered; no agents array in plugin.json)
  6. No legacy arrays in plugin.json — presence of skills, commands, or agents arrays in plugin.json is a validation error (they cause Claude Code to reject the plugin)
  7. SKILL.md frontmatter — each skill has name, description, and allowed-tools (no wildcards)
  8. Agent frontmatter — each agent has name, description, and model
  9. No files in wrong locations — skills/commands/agents not inside .claude-plugin/
  10. MCP tool references — tools in allowed-tools are valid mcp__plugin_ruflo-core_ruflo__* identifiers

Steps

  1. Read the plugin's plugin.json and assert no skills / commands / agents arrays present
  2. Glob skills/*/SKILL.md, commands/*.md, agents/*.md and validate each frontmatter
  3. For each SKILL.md, verify frontmatter has required fields and allowed-tools has no wildcards
  4. For each agent .md, verify frontmatter has required fields
  5. Report pass/fail for each check with actionable fix suggestions

© ruvnet, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/ruflo-plugin-creator/skills/validate-plugin of ruvnet/ruflo.

Open the folder on GitHubat commit de590e1

Compare with similar skills

Validate Plugin next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Validate Plugin compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Validate Plugin this skillruvnet/ruflo74k—~511Automated safety check: NotesMIT
MCP Integration for Pluginsanthropics/claude-plugins-official37k11 repos~3.1kAutomated safety check: PassApache-2.0
Crush Configurationcharmbracelet/crush29k—~3.7kAutomated safety check: PassCustom licence
OpenpetsOpenPetsHQ/openpets1.3k—~2.1kAutomated safety check: PassMIT
Claude Automation Recommenderanthropics/claude-plugins-official37k3 repos~2.7kAutomated safety check: NotesApache-2.0
Mistral Vibe Plugin Creatormistralai/mistral-vibe5.1k—~3.1kAutomated safety check: PassApache-2.0

Similar skills

  • MCP Integration for Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.

    37k GitHub starsUsed in 11 repos~3.1k tokens
    Agent WorkflowsAuto-check passed
  • Crush Configuration

    charmbracelet/crush

    Explains how to configure the Crush coding agent with crushrc or crush.json, covering providers, models, LSPs, MCP servers, hooks, permissions and config precedence.

    29k GitHub stars~3.7k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Openpets

    OpenPetsHQ/openpets

    A skill your agent uses whenever the user wants to build, extend, debug, test, validate, locally load, package, or publish an OpenPets plugin; work with the OpenPets Plugin SDK v3, plugin manifest…

    1.3k GitHub stars~2.1k tokensUpdated 9 days ago
    Agent WorkflowsAuto-check passed
  • Claude Automation Recommender

    anthropics/claude-plugins-official

    Official

    Scans a codebase and suggests which Claude Code hooks, subagents, skills, plugins and MCP servers fit its stack, without changing any files.

    37k GitHub starsUsed in 3 repos~2.7k tokens
    Agent WorkflowsAuto-check: notes
  • Mistral Vibe Plugin Creator

    mistralai/mistral-vibe

    Official

    Shows how to build a Vibe plugin package in the Agent Plugins 1.0 format, with a plugin.json manifest and optional skills, MCP servers, hooks and other components.

    5.1k GitHub stars~3.1k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Audits a project's agent configuration, instruction drift, hooks, MCP and AI maintainability, then reports prioritized findings with evidence and next actions.

    7.2k GitHub stars~5.2k tokensUpdated today
    Agent WorkflowsAuto-check: notes

More from ruvnet/ruflo

All 264 skills in this repo
  • Stores, searches, and retrieves successful patterns with HNSW-indexed semantic search so agents can reuse past solutions instead of relearning them.

    74k GitHub starsUsed in 2 repos~830 tokens
    Auto-check passed
  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    Auto-check passed
  • Applies the SPARC method (specification, pseudocode, architecture, refinement, completion) with 17 specialized modes and multi-agent orchestration, from research to deployment.

    74k GitHub starsUsed in 2 repos~829 tokens
    Auto-check passed
  • Coordinates a hierarchical swarm of specialized agents through the claude-flow CLI for work that spans several files or modules at once.

    74k GitHub starsUsed in 2 repos~779 tokens
    Auto-check passed
  • Sets up and drives Ruflo, an npm-installed orchestration layer for multi-agent swarms, persistent memory, routing, hooks and its MCP tool catalog.

    74k GitHub starsUsed in 1 repo~975 tokens
    Auto-check passed
  • Agent Coordination

    ruvnet/ruflo

    Reference for spawning, listing, monitoring and stopping agents with claude-flow commands, with agent type families, routing codes and coordination tips.

    74k GitHub starsUsed in 2 repos~519 tokens
    Auto-check passed

Categories

Questions about Validate Plugin

What does Validate Plugin do?

Validate a Claude Code plugin structure, frontmatter, and MCP tool references. Validate Plugin is an agent skill from ruvnet/ruflo.

When should I use Validate Plugin?

Validate Plugin fits situations like: tasks that involve Hooks and plugins; tasks that involve MCP servers.

How do I install Validate Plugin in Claude Code?

Run `npx skills add ruvnet/ruflo --skill validate-plugin -a claude-code`. Or copy the skill folder (plugins/ruflo-plugin-creator/skills/validate-plugin in ruvnet/ruflo) into .claude/skills/validate-plugin in your project. Claude Code loads it when a task matches its description.

How do I install Validate Plugin in Codex?

Run `npx skills add ruvnet/ruflo --skill validate-plugin -a codex`. Or copy the skill folder (plugins/ruflo-plugin-creator/skills/validate-plugin in ruvnet/ruflo) into .agents/skills/validate-plugin in your project. Codex loads it when a task matches its description.

Can I use Validate Plugin in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ruvnet/ruflo --skill validate-plugin -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/validate-plugin, .gemini/skills/validate-plugin, .github/skills/validate-plugin and .opencode/skills/validate-plugin in your project.

What does Validate Plugin need to run?

SKILL.md names no scripts, command-line tools or credentials: Validate Plugin is instructions for the agent only. Its frontmatter pre-approves these tools: mcp__plugin_ruflo-core_ruflo__transfer_plugin-info, Bash, Read, Glob, Grep.

Does Validate Plugin access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Validate Plugin safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Validate Plugin use?

Validate Plugin is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Validate Plugin use?

About 511 tokens (SKILL.md is roughly 2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Validate Plugin?

Skills that share tags, products or a category with Validate Plugin: MCP Integration for Plugins (anthropics/claude-plugins-official, 37k stars), Crush Configuration (charmbracelet/crush, 29k stars), Openpets (OpenPetsHQ/openpets, 1.3k stars) and Claude Automation Recommender (anthropics/claude-plugins-official, 37k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Validate Plugin?

ruvnet (a GitHub user) maintains it in ruvnet/ruflo, which has 74,012 GitHub stars. The repository holds 264 skills in this directory. The repository was last updated on October 7, 2026.

Source: ruvnet/ruflo on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.