feat: add thariq-skills plugin - #53
Conversation
Ships Anthropic's internal skill-authoring playbook as an on-demand knowledge skill: 9 skill categories, 9 authoring tips, and distribution guidance, distilled from Thariq's March 17, 2026 post. Bundles the verbatim upstream baseline under vendor/ plus a maintainer-facing drift-check update script (--check/--apply) with self-contained regression tests. A vendor-scoped nested markdownlint config exempts the verbatim third-party baseline from local style rules without touching the managed root config. Co-Authored-By: Claude <noreply@anthropic.com>
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_8517580f-37db-449c-a95c-4aa3cbb755a9) |
|
Claude finished @kyle-sexton's task in 3m 26s —— View job PR Review: feat: add thariq-skills plugin
Overall this is a well-structured, thoughtfully documented submission. Plugin form compliance is solid (explicit Medium1. Content attribution in distilled The distilled skill is described as "Anthropic's internal skill-authoring playbook" in its frontmatter Comparing:
The distillation enhancement is reasonable, but framing all content as Anthropic's playbook misattributes the additions. The description frontmatter or the "Source" line should clarify that Suggested fix: Add a brief note (e.g. ``) adjacent to the added content, or qualify the attribution line as "distilled from and extended from @trq212's post." 2. Third-party domain for upstream source without content validation INSTALL_URL="https://howborisusesclaudecode.com/api/install-thariq"
The blast radius is limited (vendor baseline only, not the installed skill), and it's maintainer-only, but the risk is worth mitigating. A pinned known-good SHA stored in the repository and checked before Low3. curl -sSL --fail --max-time 30 "$INSTALL_URL" -o "$out" 2>/dev/null || return 1
4. sed -E "s|^([[:space:]]+${field}:[[:space:]]+).*\$|\\1${value_safe}|" \
"$FRONTMATTER_FILE" >"$tmp"
5. Update subcommand path ambiguity in
The instruction refers to Informational6.
7. Marketplace
Checklist
|
There was a problem hiding this comment.
Stale comment
Risk: medium. Not approving: Cursor Bugbot completed with a skipped status and left no review comment, so the required automated review signal is incomplete. Human review is needed; no reviewers were assigned because no suitable non-author maintainers were identified in this repository.
Sent by Cursor Approval Agent: Pull Request Router and Approver
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: fb6367b82c
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Claude Code substitutes ${CLAUDE_PLUGIN_DATA} and ${CLAUDE_EFFORT}
inline in skill content, so the teaching prose now names them without
the dollar-brace wrapper; the update action path is anchored via
${CLAUDE_SKILL_DIR} so it resolves from any working directory.
Co-Authored-By: Claude <noreply@anthropic.com>
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_59a80e9d-b6ab-45d8-898a-e1469989ce0b) |
|
Claude finished @kyle-sexton's task in 3m 4s —— View job PR Review: feat: add thariq-skills plugin
This is a clean, well-scoped additive plugin. The latest commit (414ca52) correctly addresses both issues raised in the previous automated review round. Findings below are ordered by severity; two Mediums from the first round remain open. Fixed since first review ✅Placeholder variable substitution (Codex P2 / previous review #1 table) Update script path (Codex P2 / previous Low #5) Medium — still open1. CLAUDE_EFFORT tip is an addition over the upstream; attribution doesn't say so The distilled skill adds a
Without any note that the skill extends the original. A maintainer running One-liner fix: change 2. Vendor sync fetches from an informal third-party domain without SHA pinning INSTALL_URL="https://howborisusesclaudecode.com/api/install-thariq"
Suggested mitigation: store a Low3. curl diagnostic suppression in curl -sSL --fail --max-time 30 "$INSTALL_URL" -o "$out" 2>/dev/null || return 1
4.
Informational5. The 18 checks in 6. Marketplace
Checklist
|
There was a problem hiding this comment.
Stale comment
Risk: medium. Not approving: Cursor Bugbot completed with a skipped status (usage limit reached) and did not produce a clean review signal. Human review is needed; no reviewers were assigned because no suitable non-author maintainers were identified in this repository.
Sent by Cursor Approval Agent: Pull Request Router and Approver
…kills # Conflicts: # .claude-plugin/marketplace.json # README.md
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_2b5d781c-40da-48cb-8ee5-3af0ee0ce5c5) |
|
Claude finished @kyle-sexton's task in 1m 34s —— View job PR Review: feat: add thariq-skills plugin
The latest commit (83ac699) is a merge of Fixed ✅
Medium — still open1. Distilled body adds content absent from vendor; attribution doesn't say so
The distilled skill adds a Minimum fix — change line 158 from: Source: [@trq212's March 17, 2026 post](…)to: Source (distilled and extended): [@trq212's March 17, 2026 post](…)2.
INSTALL_URL="https://howborisusesclaudecode.com/api/install-thariq"
…
cp "$upstream_md" "$VENDOR_FILE"
Suggested mitigation: store a Low3. curl -sSL --fail --max-time 30 "$INSTALL_URL" -o "$out" 2>/dev/null || return 1
4.
Informational5. 6. Checklist
|
There was a problem hiding this comment.
Risk: medium. Not approving: Cursor Bugbot completed with a skipped status (usage limit reached) and did not produce a clean review signal. Human review is needed; no reviewers were assigned because no suitable non-author maintainers were identified in this repository.
Sent by Cursor Approval Agent: Pull Request Router and Approver
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 83ac699aa8
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Closes melodic-software/medley#1292. Publishes the `boris` plugin per `docs/MIGRATION-PLAYBOOK.md` (per-plugin gate + acceptance security review). ## What ships - `plugins/boris/` — one knowledge skill (`/boris:boris`): Boris Cherny's Claude Code workflow tips (howborisusesclaudecode.com), 107 tips across 95 sections, hub SKILL.md + eight topic reference files (progressive disclosure). - Verbatim upstream baseline at `skills/boris/vendor/SKILL.md` (SHA-verified byte-identical to the source repo copy) for drift detection. - Maintainer-facing `scripts/update.sh` (`--check` read-only drift report / `--apply` vendor + frontmatter sync; reference-file integration stays manual) with self-contained `update.test.sh` (19 checks, network-free). - Marketplace entry: `category: learning`, tags `knowledge` + component tags. Explicit `version: 0.1.0` in `plugin.json` only. - Vendor-scoped nested `.markdownlint-cli2.jsonc` (`default: false`) — verbatim third-party content exempted from local style rules without touching the managed root config (same pattern as PR #53). ## Gate evidence - `claude plugin validate ./plugins/boris --strict` — PASS - `claude plugin validate . --strict` (catalog manifest) — PASS - `claude plugin details` token cost: **~211 tok always-on**, ~3.7k on-invoke (single skill) - `--plugin-dir` smoke test in a clean non-source repo — PASS: skill invoked, routed worktrees question to `reference/worktrees.md`, namespace confirmed as `boris:boris` - `update.test.sh` 19/19 PASS; shellcheck (repo rcfile) clean; shfmt clean; markdownlint 0 errors (11 files); typos clean; editorconfig-checker clean ## Security review (playbook acceptance) - No hooks, no MCP servers, no agents, no `userConfig` — pure skill content. - Code execution surface: `scripts/update.sh` only, run solely on explicit maintainer invocation (never automatic). Sole network egress: `curl` to `https://howborisusesclaudecode.com/api/version` and `/api/install` (the upstream source, which publishes these endpoints for exactly this consumption) — no other outbound calls, no `eval`, no untrusted input into shell. - Cache isolation: no `../` reach-outs; script resolves paths relative to itself; update path in the skill body anchored via `${CLAUDE_SKILL_DIR}`. - Taught placeholder names are written without their dollar-brace wrapper so Claude Code's inline substitution cannot rewrite the teaching content (lesson from PR #53 review). - No PII / secrets. Repo-agnostic: no source-repo references; body + script rewritten for plugin form (namespaced self-references, script-relative path resolution). Merge note: expected `marketplace.json` + root `README.md` conflict with PR #53 (thariq-skills) — the playbook prescribes serializing final merges; whichever lands second rebases the two shared files. <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **Low Risk** > Read-only knowledge skill with no hooks or MCP; network use is limited to maintainer-invoked `update.sh` against the documented upstream URLs. > > **Overview** > Adds the **`boris`** marketplace plugin: Boris Cherny’s Claude Code tips from howborisusesclaudecode.com, packaged like **`thariq-skills`** with progressive disclosure instead of one huge skill file. > > **Catalog:** `boris` is registered in **`.claude-plugin/marketplace.json`** (`learning`) and summarized in the root **`README.md`**. > > **Skill shape:** Hub **`SKILL.md`** (`/boris:boris`) with a topic index, quick reference, and **`update`** actions; eight **`reference/*.md`** topic slices (foundations through orchestration); verbatim **`vendor/SKILL.md`** for SHA drift checks. The hub tells agents to treat vendor content as untrusted (ignore upstream’s self-install **UPDATE CHECK** block). > > **Maintainer tooling:** **`scripts/update.sh`** (`--check` / `--apply`) hits the site’s version/install APIs, syncs vendor + frontmatter, and leaves reference integration manual; **`update.test.sh`** covers helpers offline; vendor gets a nested **markdownlint** off config so third-party text isn’t restyled locally. > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 7b85408. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY --> --------- Co-authored-by: Claude <noreply@anthropic.com>
Closes melodic-software/medley#1285. Publishes the `docs-hygiene` plugin per `docs/MIGRATION-PLAYBOOK.md` (per-plugin gate + acceptance security review). One cohesive capability — documentation hygiene — bundling five skills. ## What ships - `/docs-hygiene:compress` — flavor-trims markdown behind a mandatory fresh-context semantic-diff audit that reverts any semantic loss; optional `caveman` plugin backend (qualified `/caveman:compress` invocation, graceful in-session Edit fallback); optional snapshots persist under the plugin data directory. - `/docs-hygiene:declutter` — read-only classifier for five markdown noise shapes with internalized shape definitions, tier semantics, exemptions, and opt-out markers (no source-repo rule dependencies). - `/docs-hygiene:extract-ssot` — Rule-of-Three deduplication into a single source of truth with refuse-fast verification gates and internalized evidence discipline. - `/docs-hygiene:encapsulation-audit` — detects citations into skill-private surfaces; ships its own `context/public-surface-contract.md`; detector generalized to scan any consumer repo's instruction surfaces. - `/docs-hygiene:rename-references` — 12-form stale-reference pattern library (slash tokens, moved-file relative paths, frontmatter chains/globs) with audit, half-rename, and apply modes. Adaptation notes: source-repo rule citations internalized or routed to the consuming repo's own CLAUDE.md/rules; scripts resolve paths via BASH_SOURCE and scan the repo they run in; `${CLAUDE_SKILL_DIR}` anchors all script invocations; taught placeholder names written without dollar-brace wrappers (substitution lesson from PR #53); eval suites intentionally NOT shipped (the eval runner is authoring-repo-side; shipping them would be dead weight with broken references). ## Gate evidence - `claude plugin validate ./plugins/docs-hygiene --strict` — PASS; `claude plugin validate . --strict` (catalog) — PASS - `claude plugin details` token cost: **~1,161 tok always-on** (compress ~340, declutter ~280, encapsulation-audit ~150, extract-ssot ~170, rename-references ~230); on-invoke ~2.6k–6.4k per skill - Script tests: 73 checks across 4 self-contained suites (compress 9, declutter 17, encapsulation-audit 32, extract-ssot 15) — all pass, network-free, fixture-repo based - shellcheck (repo rcfile) clean on all 9 shell files; shfmt clean; markdownlint 0 errors (24 files); typos clean; editorconfig-checker clean - `--plugin-dir` smoke test in a clean non-source repo — PASS: `/docs-hygiene:declutter` invoked, answered the five noise shapes, namespace confirmed as `docs-hygiene:declutter` ## Security review (playbook acceptance) - No hooks, no MCP servers, no agents, no `userConfig`. - Code execution surface: bundled scripts are read-only detectors and fact emitters (grep/awk over the consuming repo's tracked files). **Zero network egress** — verified by grep over all shell files (no curl/wget/nc; the only `http` hit is a URL string inside a test fixture). - Cross-plugin trust: `compress` can delegate mechanical compression to the third-party `caveman` plugin ONLY when the consumer has installed it; detection is capability-probing, invocation is the qualified `/caveman:compress` form, and the built-in fallback keeps the skill fully functional without it. No other plugin is referenced. - Cache isolation: no `../` reach-outs; state (optional compress snapshots) goes to the plugin data directory. - No PII / secrets. Merge note: PRs #53 and #56 also touch `marketplace.json` + root `README.md` — the playbook prescribes serializing final merges; whichever lands later rebases the two shared files. <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **Low Risk** > Documentation and read-only/local shell tooling only—no hooks, MCP, network calls, or automatic repo writes beyond what users invoke via skills; optional third-party `caveman` compression is opt-in. > > **Overview** > Adds the **`docs-hygiene`** plugin to the marketplace catalog and root README, bundling five on-demand skills for keeping tracked markdown lean, deduplicated, and correctly referenced in any consumer repo. > > **`/docs-hygiene:compress`** tightens prose by cutting flavor while a mandatory fresh-context semantic-diff pass reverts semantic loss; it optionally uses the **`caveman`** plugin as a mechanical backend with an in-session Edit fallback, snapshots, and `markdownlint-cli2` gates. **`declutter`** is read-only noise classification (five shapes, tiered findings) backed by **`detect.sh`** and shared shape detectors. **`extract-ssot`** encodes Rule-of-Three markdown dedup with `identify` / `verify` / `plan` / `execute` / `batch` / `unwind`, private action docs, and **`emit-verify-facts.sh`**. **`encapsulation-audit`** ships **`public-surface-contract.md`** plus **`detect.sh`** (private skill paths, heading anchors, schemas; `scripts/` carve-out). **`rename-references`** is documented as the post-rename sweep skill (12-form patterns); sibling skills cite it after migrations. > > Scripts are repo-local, read-only where applicable, always-exit-0 or explicit exit codes for audits, and covered by self-contained bash test suites (`detect-caveman`, declutter, encapsulation-audit, extract-ssot). > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit e19b05c. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY --> --------- Co-authored-by: Claude <noreply@anthropic.com>
Closes melodic-software/medley#1293. Publishes the `fable-5-playbook` plugin per `docs/MIGRATION-PLAYBOOK.md` (per-plugin gate + acceptance security review). ## What ships - `plugins/fable-5-playbook/` — one knowledge skill (`/fable-5-playbook:fable-5-playbook`): Claude Fable 5's operating doctrine, authored by Fable 5 as introspected standing instructions. Core doctrine arms the session on invocation; twelve trigger-routed chapters under `context/` (calibration, reasoning-moves, problem-framing, planning, execution, debugging, orchestration, verification, communication, recovery, context-economy, trust-and-authority) plus `context/opus-adaptation.md` for non-Fable models. - Marketplace entry: `category: learning`, tags `knowledge` + component tags. Explicit `version: 0.1.0` in `plugin.json` only. - The source skill was already repo-agnostic (no repo-specific paths, tools, or slash references); the only content deltas from the source are the frontmatter description compressed to two sentences and one typo fix (`mis-framed` → `misframed`). ## Gate evidence - `claude plugin validate ./plugins/fable-5-playbook --strict` — PASS; `claude plugin validate . --strict` (catalog) — PASS - `claude plugin details` token cost: **~207 tok always-on**, ~4.7k on-invoke (single skill) - markdownlint 0 errors (15 files); typos clean; editorconfig-checker clean - `--plugin-dir` smoke test in a clean non-source repo — PASS: skill invoked, answered the four meta-rules (Precedence, One home per doctrine, Model adaptation, Silent application), namespace confirmed as `fable-5-playbook:fable-5-playbook` ## Security review (playbook acceptance) - Pure knowledge skill: no hooks, no MCP servers, no agents, no `userConfig`, no scripts, no state, zero network access. - Cache isolation: all references are skill-internal (`context/*.md` self-citations); no `../` reach-outs. - No PII / secrets. Merge note: open PRs #53, #56, #57 also touch `marketplace.json` + root `README.md` — merge serially; later ones rebase/merge the two shared files (this branch is based on post-context7 main, so it conflicts only with those unmerged siblings). <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **Low Risk** > Markdown-only plugin packaging and catalog updates; no executable code, credentials, or runtime side effects beyond skill text loaded into Claude Code. > > **Overview** > Adds the **`fable-5-playbook`** plugin to the marketplace and root catalog — a pure knowledge skill (no hooks, MCP, scripts, or `userConfig`) that arms sessions with Claude Fable 5’s operating doctrine. > > **`SKILL.md`** loads core standing instructions on invoke (bare / `full` / chapter name), defines four meta-rules, effort floors, a chapter routing table, and cites twelve on-demand **`context/*.md`** chapters (calibration through trust-and-authority) plus mandatory **`opus-adaptation.md`** for non-Fable models. Plugin **`README.md`** and **`plugin.json`** (`0.1.0`, learning category) document install and scope. > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 03fa989. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY --> Co-authored-by: Claude <noreply@anthropic.com>
Closes melodic-software/medley#1296. Publishes the `firecrawl` plugin per `docs/MIGRATION-PLAYBOOK.md` (per-plugin gate + acceptance security review). ## What ships - `plugins/firecrawl/` — one skill (`/firecrawl:firecrawl`): wraps the `firecrawl-cli` binary for scrape/search/crawl/map/parse/interact/agent/monitor with the core write-to-disk-then-Read pattern (results land in tempfiles via `-o`; the agent reads only the needed slice — 32–35× token savings vs the MCP per the Scalekit benchmark cited in the skill). - `context/commands.md` (full flag tables, carried verbatim), `context/configuration.md` + `context/update-flow.md` (adapted repo-agnostic). - Maintainer-facing `scripts/update.sh` (`--check` read-only CLI-version + upstream-SHA drift report; `--apply` npm upgrade + `UPSTREAM.md` rewrite behind approval gates; never touches SKILL.md — content integration is a gated manual step) with a new self-contained `update.test.sh` (17 checks, network-free). - `UPSTREAM.md` sidecar (SHA-tracking sync state + rollback version). - Marketplace entry: `category: utilities`. Explicit `version: 0.1.0` in `plugin.json` only. ## Gate evidence - `claude plugin validate ./plugins/firecrawl --strict` — PASS; catalog `--strict` — PASS - `claude plugin details` token cost: **~253 tok always-on**, ~4.9k on-invoke - `update.test.sh` 17/17 PASS; shellcheck (repo rcfile) clean; shfmt clean; markdownlint 0 errors; typos clean; editorconfig-checker clean - Smoke test via `--plugin-dir` — PASS: skill body loaded, answered the write-to-disk flag (`-o`) from the body, namespace confirmed as `firecrawl:firecrawl`. The smoke run surfaced two real headless-permission defects that are fixed in this PR: a credential-shaped `printenv FIRECRAWL_API_KEY` preamble line was rejected by permission preflight (removed — `firecrawl --status` already reports auth), and the status/sync preamble lines needed narrow `allowed-tools` grants (`Bash(command -v firecrawl*)`, `Bash(firecrawl --status*)`, `Bash(grep -m1 *UPSTREAM.md*)`). Caveat: in a fully sandboxed scratch dir the preamble lines may still fall back to their error text; the skill body loads and functions regardless. ## Security review (playbook acceptance) - No hooks, no MCP servers, no agents, no `userConfig`. - Data egress (normal invocation): the user-installed `firecrawl-cli` calls `api.firecrawl.dev` (or a self-hosted `FIRECRAWL_API_URL`) — that is the plugin's documented purpose. The credential is the consumer-owned `FIRECRAWL_API_KEY` env var; never stored in or written by the plugin. Env-var auth is preferred over `firecrawl login`/`config` explicitly to avoid a second credential store. - Data egress (update path, maintainer-invoked only): `registry.npmjs.org` (version metadata) + `www.firecrawl.dev` (upstream skill source, hashed in a tmpdir). `npm install -g` and any SKILL.md rewrite sit behind two explicit approval gates; `--check` is read-only. - The skill hard-prohibits `firecrawl init` (would install a parallel MCP + skill copy) and documents the login/config divergence risk. - Cache isolation: script resolves paths relative to itself; preamble reads its own `UPSTREAM.md` via the skill-dir substitution; no `../` reach-outs. - No PII / secrets. Merge note: open PRs #53, #56, #57, #59 also touch `marketplace.json` + root `README.md` — merge serially; later ones need a conflict-merge of the two shared files. <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **Medium Risk** > New plugin steers agents toward external Firecrawl API egress and credit use via a user-installed CLI and `FIRECRAWL_API_KEY`; maintainer `--apply` runs `npm install -g`, but there are no hooks/MCP and updates are gated. > > **Overview** > **Adds a new `firecrawl` plugin** to the marketplace and root catalog, shipping `/firecrawl:firecrawl` as the maintained `firecrawl-cli` integration (scrape, search, crawl, map, parse, interact, agent, monitor) instead of the Firecrawl MCP. > > The skill centers on **write-to-disk then `Read`** (`-o` tempfiles) with escalation tables for when to use Firecrawl vs WebFetch, narrow **`allowed-tools`** for the status/sync preamble (`firecrawl --status`, `UPSTREAM.md` grep), and prohibitions against `firecrawl init` / login-style config drift. Supporting **`context/`** docs cover flags, env defaults, and the maintainer update pipeline; **`UPSTREAM.md`** records upstream SHA and CLI rollback versions. > > **Maintainer tooling:** `scripts/update.sh` (`--check` read-only drift vs npm + upstream skill; `--apply` global `npm install` + `UPSTREAM.md` rewrite only, not `SKILL.md`) and network-free **`update.test.sh`** regression checks. > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 3184b4e. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY --> Co-authored-by: Claude <noreply@anthropic.com>


Closes melodic-software/medley#1294.
Publishes the
thariq-skillsplugin perdocs/MIGRATION-PLAYBOOK.md(per-plugin gate + acceptance security review).What ships
plugins/thariq-skills/— one knowledge skill (/thariq-skills:thariq-skills): Anthropic's internal skill-authoring playbook (9 skill categories, 9 authoring tips, distribution guidance), distilled from Thariq's March 17, 2026 post.skills/thariq-skills/vendor/SKILL.md(SHA-verified byte-identical to the source repo copy) for drift detection.scripts/update.sh(--checkread-only drift report /--applyvendor + frontmatter sync; distilled-body integration stays manual) with self-containedupdate.test.sh(18 checks, network-free).category: learning, tagsknowledge+ component tags. Explicitversion: 0.1.0inplugin.jsononly..markdownlint-cli2.jsonc(default: false) — verbatim third-party content is exempted from local style rules without touching the managed root config (nested-config merge verified locally in the exact CI invocation form).Gate evidence
claude plugin validate ./plugins/thariq-skills --strict— PASSclaude plugin validate . --strict(catalog manifest) — PASSclaude plugin detailstoken cost: ~248 tok always-on, ~2.8k on-invoke (single skill)--plugin-dirsmoke test in a clean non-source repo — PASS: skill invoked, content answered correctly, namespace confirmed asthariq-skills:thariq-skillsupdate.test.sh18/18 PASS; shellcheck (repo rcfile) clean; shfmt clean; markdownlint 0 errors; typos clean; editorconfig-checker cleanSecurity review (playbook acceptance)
userConfig— pure skill content.scripts/update.shonly, run solely on explicit maintainer invocation (never automatic). Sole network egress:curltohttps://howborisusesclaudecode.com/api/install-thariq(the upstream source) — no other outbound calls, noeval, no untrusted input into shell.../reach-outs; script resolves paths relative to itself.Repo-agnostic: no source-repo references; body + script rewritten for plugin form (namespaced self-references, script-relative path resolution).
Note
Low Risk
Documentation-only skill surface for consumers; limited risk from optional maintainer update script that fetches a fixed upstream URL and writes only within the plugin tree.
Overview
Adds a new
thariq-skillsmarketplace plugin that exposes Anthropic’s skill-authoring playbook as an on-demand knowledge skill (/thariq-skills:thariq-skills), and registers it inmarketplace.jsonand the root README catalog (learningcategory).The plugin ships a distilled
SKILL.md(nine skill categories, nine authoring tips, distribution guidance) plus a verbatimvendor/SKILL.mdbaseline for drift checks. Maintainers can runscripts/update.sh(--check/--apply) to compare or refresh the vendor copy and bump frontmatter metadata; merging upstream changes into the distilled body stays manual.update.test.shcovers the script helpers without network access, andvendor/.markdownlint-cli2.jsoncdisables lint on third-party vendor content.No hooks, MCP, agents, or
userConfig— normal use is read-only skill content; only the explicit maintainer update path usescurlto the upstream install URL.Reviewed by Cursor Bugbot for commit 83ac699. Bugbot is set up for automated code reviews on this repo. Configure here.