Output of apm pack, sync-plugin-content.sh --all and sync-marketplace-mirror.sh against this round's source changes. No file here is hand-edited. Carries the version bumps and marketplace owner.email into the compiled manifests, the disallowedTools frontmatter and doc corrections into the flat mirrors, and changes plugins/bin/.github/plugin/plugin.json's mcpServers from the inlined server object to the ".mcp.json" pointer. That last file also returns to 0644: the previous re-injection wrote it through mktemp and carried 0600 across, which no gate could see because the mode check did not cover .github/plugin/ and git tracks only the exec bit. .agents/plugins/marketplace.json is unchanged and that is correct -- apm's codex profile carries neither version nor owner keys, so nothing in this round reaches it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01X7GvKuJfy2WrdBmUttV4DT
agent-audit
Audits an agent definition for correctness and quality — a single vendor-neutral file at plugin/APM scope, or a Claude Code and Copilot file pair at project/user scope.
What it does
At plugin/APM scope, accepts the single .apm/agents/<name>.agent.md file — there is no
counterpart. Structural checks via validate.sh hard-FAIL any frontmatter field outside the
vendor-neutral allowlist (name, description, model, source_keys — the last for
provenance tracking, checked separately by validate-provenance.sh against sources.md; see
ADR-0016), since apm compile
copies frontmatter verbatim to both harnesses and an unsafe field can't be silently dropped for
just one of them.
At project/user scope, accepts either file in a CC .md / Copilot .agent.md pair, derives
the counterpart automatically, and validates both. Runs structural checks via validate.sh
(required fields, kebab-case name, no placeholders, no CC-only fields in the Copilot file, no
Copilot-only fields in the CC file), provenance chain validation via validate-provenance.sh
(checks source_keys against sources.md at the plugin root — plugin/APM scope only), then
qualitative checks on description phrasing and system prompt quality. Step 1 also runs a
Vale-based prose sub-check via vale-wrap.sh against both files of the pair, using the
Kyberforge style (both files) and KyberforgeCopilot style (Copilot file only) — every alert
is a FAIL, cited by rule ID — falling back to Step 2 judgment when the vale binary is
unavailable or reports 0 files scanned. Produces a compact findings report in the same format
as skill-audit.
Usage
/agent-audit
Pass the path to either agent file as the argument.
Files
| File | Purpose |
|---|---|
SKILL.md |
Skill instructions for agents |
assets/vale/.vale.ini |
Vale config: scopes Kyberforge to **/agents/*.md, Kyberforge+KyberforgeCopilot to **/*.agent.md |
assets/vale/styles/Kyberforge/DescriptionOpener.yml |
Flags descriptions opening with "This skill/agent" instead of an imperative "Use when..." |
assets/vale/styles/Kyberforge/PaddingPhrase.yml |
Flags generic "see references/ for info" pointers instead of specific file references |
assets/vale/styles/Kyberforge/SentenceOpenerThereIs.yml |
Flags sentences opening with "There is/are" instead of naming the subject directly |
assets/vale/styles/Kyberforge/VagueWording.yml |
Flags vague capability wording ("helps with", "utilize", "assists with", "used for") in descriptions |
assets/vale/styles/KyberforgeCopilot/ProactivePhrase.yml |
Flags CC-specific "Use proactively" phrasing with no effect in Copilot descriptions |
references/README.md |
Directory documentation for references/ |
references/description-quality.md |
Qualitative guide for borderline description findings |
references/field-inventory.md |
Authoritative field lists read as data by validate.sh: valid CC and Copilot agent fields, and the vendor-neutral plugin/APM-scope allowlist |
references/sources.md |
Research provenance for skill content |
scripts/README.md |
Directory documentation for scripts/ |
scripts/validate.sh |
Structural validation script for agent file pairs |
scripts/validate-provenance.sh |
Provenance chain validation script for agent pairs against sources.md (plugin root) |
scripts/vale-wrap.sh |
Drop-in vale wrapper that works around a frontmatter-description NLP scope limitation |
tests/README.md |
(source-only) Bats test dependency and run instructions |
tests/validate.bats |
(source-only) Bats tests for validate.sh |
tests/validate-provenance.bats |
(source-only) Bats tests for validate-provenance.sh |
Rows marked (source-only) exist in the authoring source (.apm/skills/agent-audit/) but are
not present in an installed plugin: scripts/sync-plugin-content.sh strips
<category>/<name>/tests when it generates the flat mirror, because these are dev-time fixtures no
plugin host needs to discover (ADR-0017). Run them from a repo checkout, not from an install.