跳到主要内容
知仓学习社ZHICANG

plugin-review

Review plugin quality with tiered checks and dependency scoping. Use for PR and pre-release audits.

不碰外部(只输出文字)无严重或高危命中athola/claude-night-market

它会碰到什么

扫了多少5 个文本文件,13 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Plugin Review

Overview

Tiered quality review of plugins with dependency-aware scoping.

When NOT To Use

  • Reviewing one skill rather than a plugin (use abstract:skills-eval)
  • Reviewing hooks (use abstract:hooks-eval)
  • Tracing Skill() references across plugins (use

abstract:skill-graph-audit)

Table of Contents

  • [Tiers](#tiers)
  • [Orchestration](#orchestration)
  • [Scope Detection](#scope-detection)
  • [Module Loading](#module-loading)
  • [Verdict](#verdict)
  • [Output Format](#output-format)
  • [Quality Gate Mode](#quality-gate-mode)
  • [Configuration](#configuration)

Tiers

| Tier | Trigger | Scope | Depth | Duration |

|------|---------|-------|-------|----------|

| branch | Default | Affected and related | Quick gates | ~2 min |

| pr | Before merge | Affected and related | Standard | ~5 min |

| release | Before version bump | All 17 plugins | Full | ~15 min |

Orchestration

  1. Detect scope: parse --tier flag, find affected

plugins from git diff, resolve related plugins from

docs/plugin-dependencies.json

  1. Plan: build check matrix (tier x plugin x role)
  2. Execute: run checks per tier definition
  3. Report: per-plugin table, aggregate verdict

Scope Detection

Affected plugins: git diff main --name-only filtered to

plugins/*/.

Related plugins: load docs/plugin-dependencies.json,

look up each affected plugin's reverse index to find

dependents. Mark as "related" (lighter checks).

If --tier release or no git diff available, scope to

all plugins.

Module Loading

  • Always: this SKILL.md (orchestration logic)
  • branch tier: load modules/tier-branch.md
  • pr tier: load modules/tier-branch.md then

modules/tier-pr.md

  • release tier: load all tier modules plus

modules/tier-release.md

  • When resolving deps: load

modules/dependency-detection.md

Verdict

| Result | Meaning |

|--------|---------|

| PASS | All checks green |

| PASS-WITH-WARNINGS | Non-blocking issues |

| FAIL | Blocking issues found |

Output Format

Plugin Review (<tier> tier)
Affected: <list>
Related:  <list> (<reason>)

Plugin          test  lint  type  reg   verdict
<name>          PASS  PASS  PASS  PASS  PASS
...

Verdict: <PASS|PASS-WITH-WARNINGS|FAIL> (N/N plugins healthy)

PR and release tiers add scorecard sections.

Quality Gate Mode

The --quality-gate flag enables CI/CD integration with

exit codes that distinguish warnings from failures:

  • 0: all quality gates passed
  • 1: warnings present but gates passed (non-blocking)
  • 2: quality gate failures (blocking)
  • 3: critical issues found (blocking)

Use --fail-on warning to treat warnings as blocking.

Configuration

Place a .plugin-review.yaml file in the plugin root

to customize thresholds and focus areas:

plugin_review:
  quality_gates:
    structure_min: 80
    skills_min: 75
    hooks_min: 70
    tokens_max_total: 50000
    bloat_max_percentage: 15
  focus_areas:
    - skills
    - hooks
    - tokens
  exclude_patterns:
    - "*/legacy/*"
    - "*/deprecated/*"
  severity_overrides:
    missing_description: warning
    large_file: info

See the /plugin-review command reference for full

usage examples.

Exit Criteria

  • [ ] The output includes a per-plugin table with columns: test, lint, type, reg, verdict, and

an aggregate PASS / PASS-WITH-WARNINGS / FAIL verdict.

  • [ ] Scope detection identifies affected plugins via git diff main --name-only filtered to

plugins/*/; if git diff is unavailable, the skill falls back to all-plugin scope and

states this explicitly.

  • [ ] Any plugin scoring below the structure_min (default 80) or skills_min (default 75)

threshold is listed as a FAIL, not a warning.

  • [ ] --quality-gate mode returns exit code 2 for blocking failures and exit code 1 for

non-blocking warnings, distinguishable by the calling CI step.

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。