Validate PluginCAUTION
🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated
Overview
🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated
ef7d4f0535e5OBSERVED · 2026-09-26Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: validate-plugin description: Validate a Claude Code plugin structure, frontmatter, and MCP tool references argument-hint: "[plugin-path]" allowed-tools: mcp__plugin_ruflo-core_ruflo__transfer_plugin-info Bash Read Glob Grep --- # Validate Plugin Validate that a plugin follows the correct Claude Code plugin format. ## When to use After creating or modifying a plugin, run validation to catch structural issues before publishing. ## Checks performed 1. **Directory structure** — `.claude-plugin/plugin.json` exists at plugin root 2. **plugin.json schema** — required fields present (name, description, version) 3. **Skills auto-discovery** — every `skills/<name>/SKILL.md` is a valid skill (Claude Code auto-discovers from directory; `plugin.json` MUST NOT list a `skills` array) 4. **Commands auto-discovery** — every `commands/<name>.md` is a valid command (auto-discovered; no `commands` array in `plugin.json`) 5. **Agents auto-discovery** — every `agents/<name>.md` is a valid agent (auto-discovered; no `agents` array in `plugin.json`) 6. **No legacy arrays in plugin.json** — presence of `skills`, `commands`, or `agents` arrays in `plugin.json` is a validation error (they cause Claude Code to reject the plugin) 7. **SKILL.md frontmatter** — each skill has `name`, `description`, and `allowed-tools` (no wildcards) 8. **Agent frontmatter** — each agent has `name`, `description`, and `model` 9. **No files in wrong locations** — skills/commands/agents not inside `.claude-plugin/` 10. **MCP tool references** — tools in `allowed-tools` are valid `mcp__plugin_ruflo-core_ruflo__*` identifiers ## Steps 1. Read the plugin's `plugin.json` and assert no `skills` / `commands` / `agents` arrays present 2. Glob `skills/*/SKILL.md`, `commands/*.md`, `agents/*.md` and validate each frontmatter 3. For each SKILL.md, verify frontmatter has required fields and `allowed-tools` has no wildcards 4. For each agent .md, verify frontmatter has required fields 5. Report pass/fail for each check with actionable fix suggestions
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (4)
crates
plugin/agents
plugin/commands
plugin/skills
Gates applied: no_behavioural_pass.
ef7d4f0535e5full audit observations/trust-audit/skill/ruvnet__validate-plugin.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-26 | ef7d4f0535e5 | CAUTION | B | 89 | first audit |
Questions
What does the Validate Plugin skill do?
🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated
Is Validate Plugin safe to install?
With care. The audit graded it B (89/100) and found 4 things worth knowing before you trust this skill, listed below with the exact line each was found on.
What can Validate Plugin access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Validate Plugin work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (ef7d4f0535e5), read on 2026-09-26. The repository is watched, and a new audit runs when it changes — this is the first audit.