Files
holocron/plugins/kyberforge/skills/skill-author
Defame1297 f037d49b5c fix(kyberforge): fix apm-scope validation gaps in agent/skill authoring scripts
Post-implementation review of PR #93 (issue #89's apm.yml-native retargeting
of skill-author/skill-audit/agent-author/agent-audit) found four confirmed
defects across the four scripts' apm.yml `type:` walk-up logic:

- field-inventory.md's apm-agent-allowlist was missing `source_keys`,
  contradicting agent-author/SKILL.md's own instruction (Step 5 checklist)
  to allow it at plugin/APM scope — a correctly-authored file with
  source_keys failed validate.sh.
- validate.sh's APM_TYPE_RE and validate-provenance.sh's TYPE_RE disagreed:
  the former tolerated a quoted `type: "skill"` value, the latter didn't,
  despite agent-audit/SKILL.md explicitly documenting that
  validate-provenance.sh walks up "the same way validate.sh does". Both
  also used `\b` word-boundary matching, which false-matches a malformed
  value like `type: prompts-only` on the `prompts` prefix. Unified both
  regexes to be quote-tolerant and require an exact value.
- All four scripts' `.git` project-boundary check used isdir()/[[ -d ]],
  which misses git worktrees where `.git` is a regular file (`gitdir: ...`)
  rather than a directory. Switched to exists()/[[ -e ]].
- new-agent.sh and new-skill.sh had the same quote-intolerance as above via
  inline `grep -qE` calls (new-skill.sh's also had the `\b` false-match
  bug); replaced both with a shared-shape `is_apm_package_manifest` bash
  helper matching the Python regex's semantics.

Four other findings from the same review turned out not to be bugs: a
bare `plugin.json` no longer signaling plugin scope is documented,
intentional behavior (agent-audit/SKILL.md:30, agent-author/SKILL.md:87),
deferred to issue #90's real plugin.json-to-apm.yml conversion — not
something this fix should reverse.

Verified via direct reproduction of each defect plus the full test suite:
147/147 bats tests, 39/39 shell-script tests, 12/12 summary categories.

Refs: #89
2026-08-11 19:13:26 +00:00
..

skill-author

Author and refine skills conforming to the agentskills.io specification — create new skills from scratch or apply improvement signals to existing ones.

What it does

Routes to one of two flows based on context: if no skill directory exists at the target path, it scaffolds the directory from annotated templates, fills in SKILL.md and supporting files, and validates the result. If an existing skill directory and improvement signals are both present, it groups those signals by root cause and applies targeted edits, then re-validates. In both flows, bumps the skill's metadata.version when present (minor for create, patch for improve).

Before you start

  • Run /grill-me to resolve design decisions before creating a new skill
  • Collect domain research, examples, and constraints
  • Know the skill name (kebab-case) and destination path

Placement

scripts/new-skill.sh resolves the mode automatically by walking up from the given path — see SKILL.md Step 1 for the full algorithm.

Mode Path Chosen when
Standalone <path>/<name>/ No apm.yml with a top-level type: field is found walking up from <path>, before hitting .git or the filesystem root
Package (APM) <package-root>/.apm/skills/<name>/ A type-bearing apm.yml is found at or above <path> — <path> just needs to be somewhere inside the package

If the destination resolves inside an APM package, read references/deployment-modes.md — self-containment rules apply to apm compile output the same way they applied to plugin cache isolation.

Usage

/skill-author

Files

File Purpose
README.md Human-readable overview of the skill and its files
SKILL.md Skill instructions for agents
scripts/new-skill.sh Walks up from the given path to resolve package vs standalone mode, then copies annotated templates to the resolved destination
references/deployment-modes.md APM package vs standalone differences and self-containment/cache-isolation rules (loaded on demand)
references/scripts.md Package runners, inline dependency patterns, and full script contract (loaded on demand)
references/sources.md Upstream research sources and which skill files each contributed to
assets/templates/SKILL.md Annotated SKILL.md template
assets/templates/README.md Annotated README template for the new skill
assets/templates/scripts/README.md Placeholder for bundled scripts
assets/templates/references/README.md Placeholder for reference docs
assets/templates/references/sources.md Sources provenance template for new skills
assets/templates/assets/README.md Placeholder for static assets
assets/templates/tests/README.md Placeholder for test files
tests/new-skill.bats Bats test suite for scripts/new-skill.sh
tests/README.md Setup instructions for bats-support and bats-assert test dependencies

Spec reference

agentskills.io specification