Files
holocron/plugins/kyberforge/skills/agent-audit
Defame1297 874bf06b18 chore(apm): regenerate compiled manifests and content mirrors
Output of apm pack, sync-plugin-content.sh --all and
sync-marketplace-mirror.sh against this round's source changes. No file here
is hand-edited.

Carries the version bumps and marketplace owner.email into the compiled
manifests, the disallowedTools frontmatter and doc corrections into the flat
mirrors, and changes plugins/bin/.github/plugin/plugin.json's mcpServers from
the inlined server object to the ".mcp.json" pointer. That last file also
returns to 0644: the previous re-injection wrote it through mktemp and carried
0600 across, which no gate could see because the mode check did not cover
.github/plugin/ and git tracks only the exec bit.

.agents/plugins/marketplace.json is unchanged and that is correct -- apm's
codex profile carries neither version nor owner keys, so nothing in this round
reaches it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01X7GvKuJfy2WrdBmUttV4DT
2026-08-14 11:05:20 +00:00
..

agent-audit

Audits an agent definition for correctness and quality — a single vendor-neutral file at plugin/APM scope, or a Claude Code and Copilot file pair at project/user scope.

What it does

At plugin/APM scope, accepts the single .apm/agents/<name>.agent.md file — there is no counterpart. Structural checks via validate.sh hard-FAIL any frontmatter field outside the vendor-neutral allowlist (name, description, model, source_keys — the last for provenance tracking, checked separately by validate-provenance.sh against sources.md; see ADR-0016), since apm compile copies frontmatter verbatim to both harnesses and an unsafe field can't be silently dropped for just one of them.

At project/user scope, accepts either file in a CC .md / Copilot .agent.md pair, derives the counterpart automatically, and validates both. Runs structural checks via validate.sh (required fields, kebab-case name, no placeholders, no CC-only fields in the Copilot file, no Copilot-only fields in the CC file), provenance chain validation via validate-provenance.sh (checks source_keys against sources.md at the plugin root — plugin/APM scope only), then qualitative checks on description phrasing and system prompt quality. Step 1 also runs a Vale-based prose sub-check via vale-wrap.sh against both files of the pair, using the Kyberforge style (both files) and KyberforgeCopilot style (Copilot file only) — every alert is a FAIL, cited by rule ID — falling back to Step 2 judgment when the vale binary is unavailable or reports 0 files scanned. Produces a compact findings report in the same format as skill-audit.

Usage

/agent-audit

Pass the path to either agent file as the argument.

Files

File Purpose
SKILL.md Skill instructions for agents
assets/vale/.vale.ini Vale config: scopes Kyberforge to **/agents/*.md, Kyberforge+KyberforgeCopilot to **/*.agent.md
assets/vale/styles/Kyberforge/DescriptionOpener.yml Flags descriptions opening with "This skill/agent" instead of an imperative "Use when..."
assets/vale/styles/Kyberforge/PaddingPhrase.yml Flags generic "see references/ for info" pointers instead of specific file references
assets/vale/styles/Kyberforge/SentenceOpenerThereIs.yml Flags sentences opening with "There is/are" instead of naming the subject directly
assets/vale/styles/Kyberforge/VagueWording.yml Flags vague capability wording ("helps with", "utilize", "assists with", "used for") in descriptions
assets/vale/styles/KyberforgeCopilot/ProactivePhrase.yml Flags CC-specific "Use proactively" phrasing with no effect in Copilot descriptions
references/README.md Directory documentation for references/
references/description-quality.md Qualitative guide for borderline description findings
references/field-inventory.md Authoritative field lists read as data by validate.sh: valid CC and Copilot agent fields, and the vendor-neutral plugin/APM-scope allowlist
references/sources.md Research provenance for skill content
scripts/README.md Directory documentation for scripts/
scripts/validate.sh Structural validation script for agent file pairs
scripts/validate-provenance.sh Provenance chain validation script for agent pairs against sources.md (plugin root)
scripts/vale-wrap.sh Drop-in vale wrapper that works around a frontmatter-description NLP scope limitation
tests/README.md (source-only) Bats test dependency and run instructions
tests/validate.bats (source-only) Bats tests for validate.sh
tests/validate-provenance.bats (source-only) Bats tests for validate-provenance.sh

Rows marked (source-only) exist in the authoring source (.apm/skills/agent-audit/) but are not present in an installed plugin: scripts/sync-plugin-content.sh strips <category>/<name>/tests when it generates the flat mirror, because these are dev-time fixtures no plugin host needs to discover (ADR-0017). Run them from a repo checkout, not from an install.