Claude Code's (and Copilot's) native plugin installer has zero awareness of .apm/ nesting -- it convention-scans only flat skills/, agents/, commands/, hooks.json at each plugin's root. Confirmed via strings on the installed claude binary and live installs of git@holocron/gitea@holocron/kyberforge@ holocron, all reporting Skills(0) Agents(0) Hooks(0) post ADR-0015's apm conversion. Root cause (apm_cli/core/plugin_manifest.py): apm's plugin.json compiler deliberately strips skills/agents/commands keys, assuming the host already auto-discovers those convention directories -- it has no model of .apm/ being host-visible at all. Separately, apm's own bundle exporter (apm_cli/bundle/plugin_exporter.py, behind `apm pack --format plugin`) implements the correct .apm/ -> flat mapping, but only ever targeted build/<name>-<version>/, a path nothing in marketplace.json's source: points at. scripts/sync-plugin-content.sh wraps that bundle exporter and copies its agents/, skills/, commands/, instructions/, extensions/, and merged hooks.json back into each plugin's own root as a second tracked compiled-output category -- same governance status as .claude-plugin/plugin.json: generated from .apm/, never hand-edited. tests/ subdirectories are excluded from the mirror (dev fixtures, not host-visible runtime content; several hardcode a relative repo-root walk-up sized for the .apm/-nested depth, which breaks when duplicated one level shallower). Applied for real across all 6 plugins and verified two ways: `claude plugin validate --strict` passes on every real plugin directory, and a live `claude --plugin-dir <path> -p "list skills/agents"` behavioral test confirms content is now actually discovered. Also, from the same issue #90 review round: - scripts/check-manifests.sh pointed at each plugin's root-level plugin.json (checking skills/hooks/mcpServers/agents pointer fields) -- that file was a stale near-duplicate of .claude-plugin/plugin.json nothing else read or wrote, now deleted across all 6 plugins. check-manifests.sh is rewritten to validate .claude-plugin/plugin.json instead, and drops the pointer-field checks entirely (nothing to check -- those fields are correctly absent by design). Content-presence drift is now check-plugin-content-sync's job, a new pre-push hook wired in .pre-commit-config.yaml. docs/adr/0017 records the root cause and decision in full, including two rejected alternatives (patching plugin.json's path fields directly -- apm's compiler strips them on every run; pointing marketplace.json at apm pack's build/ output -- a version-suffixed non-source directory nothing can install from without an extra build step). ADR-0015 and CONTEXT.md are updated to point at it. Refs: #90
agent-audit
Audits an agent definition for correctness and quality — a single vendor-neutral file at plugin/APM scope, or a Claude Code and Copilot file pair at project/user scope.
What it does
At plugin/APM scope, accepts the single .apm/agents/<name>.agent.md file — there is no
counterpart. Structural checks via validate.sh hard-FAIL any frontmatter field outside the
vendor-neutral allowlist (name, description, model, source_keys — the last for
provenance tracking, checked separately by validate-provenance.sh against sources.md; see
ADR-0016), since apm compile
copies frontmatter verbatim to both harnesses and an unsafe field can't be silently dropped for
just one of them.
At project/user scope, accepts either file in a CC .md / Copilot .agent.md pair, derives
the counterpart automatically, and validates both. Runs structural checks via validate.sh
(required fields, kebab-case name, no placeholders, no CC-only fields in the Copilot file, no
Copilot-only fields in the CC file), provenance chain validation via validate-provenance.sh
(checks source_keys against sources.md at the plugin root — plugin/APM scope only), then
qualitative checks on description phrasing and system prompt quality. Step 1 also runs a
Vale-based prose sub-check via vale-wrap.sh against both files of the pair, using the
Kyberforge style (both files) and KyberforgeCopilot style (Copilot file only) — every alert
is a FAIL, cited by rule ID — falling back to Step 2 judgment when the vale binary is
unavailable or reports 0 files scanned. Produces a compact findings report in the same format
as skill-audit.
Usage
/agent-audit
Pass the path to either agent file as the argument.
Files
| File | Purpose |
|---|---|
SKILL.md |
Skill instructions for agents |
assets/vale/.vale.ini |
Vale config: scopes Kyberforge to **/agents/*.md, Kyberforge+KyberforgeCopilot to **/*.agent.md |
assets/vale/styles/Kyberforge/DescriptionOpener.yml |
Flags descriptions opening with "This skill/agent" instead of an imperative "Use when..." |
assets/vale/styles/Kyberforge/PaddingPhrase.yml |
Flags generic "see references/ for info" pointers instead of specific file references |
assets/vale/styles/Kyberforge/SentenceOpenerThereIs.yml |
Flags sentences opening with "There is/are" instead of naming the subject directly |
assets/vale/styles/Kyberforge/VagueWording.yml |
Flags vague capability wording ("helps with", "utilize", "assists with", "used for") in descriptions |
assets/vale/styles/KyberforgeCopilot/ProactivePhrase.yml |
Flags CC-specific "Use proactively" phrasing with no effect in Copilot descriptions |
references/README.md |
Directory documentation for references/ |
references/description-quality.md |
Qualitative guide for borderline description findings |
references/field-inventory.md |
Authoritative list of valid CC and Copilot agent fields |
references/sources.md |
Research provenance for skill content |
scripts/README.md |
Directory documentation for scripts/ |
scripts/validate.sh |
Structural validation script for agent file pairs |
scripts/validate-provenance.sh |
Provenance chain validation script for agent pairs against sources.md (plugin root) |
scripts/vale-wrap.sh |
Drop-in vale wrapper that works around a frontmatter-description NLP scope limitation |
tests/README.md |
Bats test dependency and run instructions |
tests/validate.bats |
Bats tests for validate.sh |
tests/validate-provenance.bats |
Bats tests for validate-provenance.sh |