Agent skill

ShellCheck Configuration

by wshobson in wshobson/agents

“Master ShellCheck static analysis configuration and usage for shell script quality. Use when setting up linting infrastructure, fixing code issues, or ensuring script portability.”

— description from SKILL.md by wshobson
MITAuto-check passedDevelopment

Install ShellCheck Configuration

skills CLI
$ npx skills add wshobson/agents --skill shellcheck-configuration -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install wshobson/agents shellcheck-configuration --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/shell-scripting/skills/shellcheck-configuration .claude/skills/shellcheck-configuration && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
shellcheck-configuration
GitHub stars
40k
Used in
11 other repos
Token cost
~403 tokens
SKILL.md length
177 words
Files
2 (incl. references)
Skills in repo
142
Repo updated
First seen
Licence
MIT

At a glance

  • Works in 8 steps: Run ShellCheck in CI/CD - Catch issues… → Configure for your target shell - Don't… → Document exclusions - Explain why… → …
  • SKILL.md covers When to Use This Skill, Detailed patterns and worked… and Best Practices
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

About this skill

ShellCheck Configuration is a skill in wshobson/agents (40k stars). Its SKILL.md is about 403 tokens, with 1 other file in the folder (references), and copies of it appear in 11 other owners' repositories. Licence: MIT.

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Run ShellCheck in CI/CD - Catch issues before merging
  2. Configure for your target shell - Don't analyze bash as sh
  3. Document exclusions - Explain why violations are suppressed
  4. Address violations - Don't just disable warnings
  5. Enable strict mode - Use --enable=all with careful exclusions
  6. Update regularly - Keep ShellCheck current for new checks
  7. Use pre-commit hooks - Catch issues locally before pushing
  8. Integrate with editors - Get real-time feedback during development

What it can do on your machine

Read from SKILL.md and the folder at commit 46891e7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

ShellCheck Configuration loads about 403 tokens when it runs, and up to ~2.4k if it reads all its reference files. Until then it costs about 51 tokens; SKILL.md has 177 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~51
When it runs · the whole SKILL.md, loaded when a task matches
~403
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from wshobson/agents at commit 46891e7, republished under its MIT licence (© wshobson). 177 words, ~403 tokens.

Download SKILL.mdSave it as .claude/skills/shellcheck-configuration/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
shellcheck-configuration
description
Master ShellCheck static analysis configuration and usage for shell script quality. Use when setting up linting infrastructure, fixing code issues, or ensuring script portability.

ShellCheck Configuration and Static Analysis

Comprehensive guidance for configuring and using ShellCheck to improve shell script quality, catch common pitfalls, and enforce best practices through static code analysis.

When to Use This Skill

  • Setting up linting for shell scripts in CI/CD pipelines
  • Analyzing existing shell scripts for issues
  • Understanding ShellCheck error codes and warnings
  • Configuring ShellCheck for specific project requirements
  • Integrating ShellCheck into development workflows
  • Suppressing false positives and configuring rule sets
  • Enforcing consistent code quality standards
  • Migrating scripts to meet quality gates

Detailed patterns and worked examples

Detailed pattern documentation lives in references/details.md. Read that file when the navigation tier above is insufficient.

Best Practices

  1. Run ShellCheck in CI/CD - Catch issues before merging
  2. Configure for your target shell - Don't analyze bash as sh
  3. Document exclusions - Explain why violations are suppressed
  4. Address violations - Don't just disable warnings
  5. Enable strict mode - Use --enable=all with careful exclusions
  6. Update regularly - Keep ShellCheck current for new checks
  7. Use pre-commit hooks - Catch issues locally before pushing
  8. Integrate with editors - Get real-time feedback during development

© wshobson, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in plugins/shell-scripting/skills/shellcheck-configuration of wshobson/agents.

  • SKILL.md
  • references/details.md

Open the folder on GitHubat commit 46891e7

Used in 11 other repositories

We found 25 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 11 other GitHub owners. This page covers the copy in wshobson/agents, which our catalogue first saw on October 7, 2026.

Compare with similar skills

ShellCheck Configuration next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

ShellCheck Configuration compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
ShellCheck Configuration this skillwshobson/agents40k11 repos~403Automated safety check: PassMIT
Golang Continuous Integrationsamber/cc-skills-golang3.4k—~3.7kAutomated safety check: PassMIT
Golang Continuous Integrationcontext-labs/whip1.1k—~3.5kAutomated safety check: PassMIT
Bash Propromovaweb/setupvibe10111 repos~4.7kAutomated safety check: PassGPL-3.0
Writing Bash Scriptsarchibate/dotfiles-opencode1081 repos~413Automated safety check: PassNone
Shell Scriptingancoleman/ai-design-components5261 repos~2.2kAutomated safety check: PassMIT

Similar skills

  • Golang Continuous Integration

    samber/cc-skills-golang

    GitHub Actions CI/CD pipeline configuration for Golang projects — workflow files for test, lint, SAST, coverage and vulnerability-scan jobs, Dependabot and Renovate config files, GoReleaser release…

    3.4k GitHub stars~3.7k tokensUpdated 6 days ago
    DevelopmentAuto-check passed
  • CI/CD with GitHub Actions for Golang — testing, linting, SAST, security scanning, coverage, Dependabot, Renovate, GoReleaser, release pipelines.

    1.1k GitHub stars~3.5k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Bash Pro

    promovaweb/setupvibe

    Master of defensive Bash scripting for production automation, CI/CD pipelines, and system utilities.

    101 GitHub starsUsed in 11 repos~4.7k tokens
    DevelopmentAuto-check passed
  • Writing Bash Scripts

    archibate/dotfiles-opencode

    Create and refactor Bash scripts following conventions (strict mode, fct naming, quoting).

    108 GitHub starsUsed in 1 repo~413 tokens
    DevelopmentAuto-check passed
  • Shell Scripting

    ancoleman/ai-design-components

    Write robust, portable shell scripts with proper error handling, argument parsing, and testing.

    526 GitHub starsUsed in 1 repo~2.2k tokens
    DevelopmentAuto-check passed
  • Linting Shell Scripts

    agntcy/coffeeAgntcy

    Runs task shell:lint (shellcheck + shfmt) against every shell script in the repo and fixes what it reports.

    112 GitHub stars~548 tokensUpdated today
    DevelopmentAuto-check passed

More from wshobson/agents

All 142 skills in this repo
  • Billing Automation

    wshobson/agents

    Covers building subscription billing: billing cycles, subscription states, invoice generation, proration, tax handling and dunning for failed payments.

    40k GitHub starsUsed in 14 repos~473 tokens
    Auto-check passed
  • Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.

    40k GitHub starsUsed in 14 repos~1.7k tokens
    Auto-check passed
  • Profiles slow Python code with cProfile and memory profilers, then applies targeted fixes for CPU, memory, I/O and query bottlenecks.

    40k GitHub starsUsed in 13 repos~814 tokens
    Auto-check passed
  • Portfolio Risk Metrics

    wshobson/agents

    Covers portfolio risk measurement with VaR, CVaR, Sharpe, Sortino and drawdown, plus guidance on limits, stress tests and tail risk.

    40k GitHub starsUsed in 13 repos~502 tokens
    Auto-check passed
  • Writes unit tests for shell scripts with Bats: error-condition tests, fixtures and mocks, cross-shell checks, parallel runs, helper files and CI integration.

    40k GitHub starsUsed in 12 repos~1.3k tokens
    Auto-check passed
  • Plans memory headroom, works through out-of-memory failures and watches temperature and power during long ML training jobs on NVIDIA DGX Spark.

    40k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed

Works with

Categories

Questions about ShellCheck Configuration

How do I install ShellCheck Configuration in Claude Code?

Run `npx skills add wshobson/agents --skill shellcheck-configuration -a claude-code`. Or copy the skill folder (plugins/shell-scripting/skills/shellcheck-configuration in wshobson/agents) into .claude/skills/shellcheck-configuration in your project. Claude Code loads it when a task matches its description.

How do I install ShellCheck Configuration in Codex?

Run `npx skills add wshobson/agents --skill shellcheck-configuration -a codex`. Or copy the skill folder (plugins/shell-scripting/skills/shellcheck-configuration in wshobson/agents) into .agents/skills/shellcheck-configuration in your project. Codex loads it when a task matches its description.

Can I use ShellCheck Configuration in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add wshobson/agents --skill shellcheck-configuration -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/shellcheck-configuration, .gemini/skills/shellcheck-configuration, .github/skills/shellcheck-configuration and .opencode/skills/shellcheck-configuration in your project.

What does ShellCheck Configuration need to run?

SKILL.md names no scripts, command-line tools or credentials: ShellCheck Configuration is instructions for the agent only.

Does ShellCheck Configuration access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is ShellCheck Configuration safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does ShellCheck Configuration use?

ShellCheck Configuration is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does ShellCheck Configuration use?

About 403 tokens (SKILL.md is roughly 1.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.

What are the alternatives to ShellCheck Configuration?

Skills that share tags, products or a category with ShellCheck Configuration: Golang Continuous Integration (samber/cc-skills-golang, 3.4k stars), Golang Continuous Integration (context-labs/whip, 1.1k stars), Bash Pro (promovaweb/setupvibe, 101 stars) and Writing Bash Scripts (archibate/dotfiles-opencode, 108 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains ShellCheck Configuration?

wshobson (a GitHub user) maintains it in wshobson/agents, which has 40,287 GitHub stars. The repository holds 142 skills in this directory. The repository was last updated on October 5, 2026.

Source: wshobson/agents on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.