validate-provenance.sh matched Contributing files only as a single inline line beginning "- **Contributing files:**". Seven skills write it as a bare "**Contributing files:**" heading above a bullet list, so parse_contributing_files returned None and checks 4 (contributing file exists) and 5 (bidirectional source_keys) silently verified nothing on git-branches, git-remotes, git-submodules, git-workflow, git-worktrees, gitea-files and gitea-releases. Those are among the skills this branch changed most — git-branches alone gained five reference files — and the retrofit's mandatory sources.md collateral went in unchecked. Demonstrated rather than argued: planting a nonexistent contributing path in git-remotes yields 0 findings under the old parser and 1 FAIL under the new one. Both forms are now accepted. The bullet form is parsed per bullet rather than by splitting a joined value, because its per-file notes contain commas that would otherwise be read as path separators. The return type becomes a list of note-stripped paths, with "(none)" as an empty list and an absent entry as None, so the two callers no longer re-split a string. Applied to agent-audit's copy as well. No agent ships a sources.md today, so it is latent there, but it is the same defect. This is a third gate blind spot alongside #117 and #118, and was unfiled. One real defect surfaced immediately and is fixed separately. Refs #99
scripts/
Executable code bundled with this skill. Agents run scripts in this directory to perform repeatable operations rather than reinventing the logic each run.
When to add a script
Add a script when agents independently reinvent the same logic across runs — building the same parser, chart, or validation routine from scratch each time. Bundle it here once, tested and reliable.
Script requirements (agentskills.io)
Scripts must be designed for non-interactive, agentic execution:
- No interactive prompts — agents run in non-interactive shells. Accept all input via flags, env vars, or stdin. A script that blocks on TTY input hangs indefinitely.
- Expose
--help— this is how agents learn your script's interface. Keep the output concise; it enters the agent's context window. - Structured output — write data (JSON, CSV, TSV) to stdout. Write progress, warnings, and diagnostics to stderr.
- Idempotent — prefer "create if not exists" over "create and fail on duplicate". Agents may retry on failure.
- Meaningful exit codes —
0for success, non-zero for failure. Use distinct codes for different failure types; document them in--help. - Dry-run support — add
--dry-runfor destructive operations.
Self-contained scripts
Bundle dependencies inline so the agent can run the script with a single command.
Python (PEP 723 + uv):
# /// script
# dependencies = ["requests>=2.31,<3"]
# requires-python = ">=3.11"
# ///
import requests
uv run scripts/my-script.py
If no scripts are needed
Delete this README and the scripts/ directory entirely.