Evaluation report
Warningsorca-skills · plugin93d7a76· 3 months ago
Every check MetaHub ran on this artifact, grouped by area. Static checks run on the source at publish time; behavioral checks run the artifact in a sandbox and judge what it actually does.
Structural
5 passedRepository is reachable
https://github.com/orcasecurity/orca-skills @ 93d7a76 — ★ 44 · MIT · last push 3 weeks ago
Manifest detected
kind=plugin slug=orca-skills · source=.claude-plugin/plugin.json
Slug is URL-safe
"orca-skills" matches /^[a-z0-9][a-z0-9-]{0,62}$/
Slug is unique within kind
No collision found for plugin/orca-skills
Version is semver
2.0.0
Documentation
5 passedDescription quality
12 words · 80 chars — OK but more detail helps
README is present and substantial
43,657 chars · 10 sections · 37 code blocks
Tags / topics declared
10 total — ai, ai-agents, ai-skills, claude, claude-code, codex (+4)
README has usage / example sections
found: Installation
Homepage / docs URL declared
https://github.com/orcasecurity/orca-skills
Safety
2 passedLICENSE file at repo root
LICENSE
No sensitive files in the repo
scanned for .env, credentials.json, *.pem, .ssh/, AWS / GCP configs — none found
Kind-specific
4 passedPlugin: manifest fields complete
Plugin: bundled artifacts present
12 skills
Plugin: bundle shape
12 skills
Plugin: manifest location
manifest at .claude-plugin/plugin.json (modern convention)
Maintenance
1 passed2 warningsTests detectedwarn
no test/tests/__tests__/spec/t/ dirs, no JVM src/test/, and no JS/TS/Python/Go/Ruby/Elixir test files
Add tests (even a smoke test). Consumers gauge maintenance quality by their presence.
CI configuration detectedwarn
no CI config found (looked for GitHub Actions, CircleCI, GitLab CI, etc.)
Add a simple workflow (lint + test on PR) — it tells consumers the artifact is built reproducibly.
Recent activity
last push 3 weeks ago
Behavioral
Behavioral results aren't published for this artifact. The publisher sees the full report on their own dashboard.