Evaluation report
Warningstop-web-vulnerabilities · skill9d252b3· last month
Every check MetaHub ran on this artifact, grouped by area. Static checks run on the source at publish time; behavioral checks run the artifact in a sandbox and judge what it actually does.
Structural
7 passedRepository is reachable
https://github.com/zebbern/claude-code-guide @ 9d252b3 — ★ 4,573 · Python · MIT · last push yesterday
Manifest detected
kind=skill slug=top-web-vulnerabilities · path=skills/top-web-vulnerabilities · source=SKILL.md
Slug is URL-safe
"top-web-vulnerabilities" matches /^[a-z0-9][a-z0-9-]{0,62}$/
Slug is unique within kind
No collision found for skill/top-web-vulnerabilities
Version is semver
0.1.0
Manifest present and parseable
Manifest found at SKILL.md.
Name declared and well-formed
Name "top-web-vulnerabilities" is well-formed.
Documentation
8 passed1 warningHomepage or repository declaredwarn
No homepage or repository declared.
Add a "homepage" or "repository" field to SKILL.md.
Description quality
71 words · 597 chars — "This skill should be used when the user asks to "identify web application vulner…"
README is present and substantial
168,182 chars · 12 sections · 127 code blocks
Tags / topics declared
20 total — ai, ai-agent, ai-agent-tools, anthropic-claude, claude, claude-ai (+14)
README has usage / example sections
found: Quick Start · Example · Example
Homepage / docs URL declared
no homepage declared (registry will use the repo URL) — info-only, not blocking
Safety
7 passed1 warning1 queuedLicense declaredwarn
No license found.
Add a LICENSE file at the artifact root, or declare a `license` field in the manifest. MIT and Apache-2.0 are the common choices.
LICENSE file at repo root
LICENSE
No sensitive files in the repo
scanned for .env, credentials.json, *.pem, .ssh/, AWS / GCP configs — none found
No credentials in file contents
No credentials found in 1 files.
Kind-specific
7 passed3 warningsSkill: triggers declaredwarn
No `trigger` phrases in SKILL.md frontmatter
Add `trigger:` lines so Claude knows when to activate this skill — e.g. `when building MCP servers` or `for diagram creation`.
Tool scope declaredwarn
No tool scope declared.
Declare `allowed-tools` with the minimum set the skill actually needs. If it needs none, declare an empty list explicitly.
Skill is not needlessly expensive to loadwarn
Skill loads heavier than it needs to (~150 + ~5890 tokens). body is ~5890 tokens and inlines everything — no scripts/ or references/ to lazy-load.
Trim the description to the routing cue. Move long procedures, examples, and reference material into files under references/ and point to them, so they load only when actually needed.
Skill: SKILL.md present
found at skills/top-web-vulnerabilities/SKILL.md · frontmatter source: SKILL.md
Maintenance
2 passed1 warning1 queuedTests detectedwarn
no test/tests/__tests__/spec/t/ dirs, no JVM src/test/, and no JS/TS/Python/Go/Ruby/Elixir test files
Add tests (even a smoke test). Consumers gauge maintenance quality by their presence.
Recent activity
last push yesterday
CI configuration detected
GitHub Actions (1 workflows)