shelf Docs
On this page
shelf audit [<name>...]
ArgumentDescription
<name>... (optional)Skill names

Also takes the global options --json and --actor (CLI overview).

What it does

Runs the same audit as shelf add, shelf pull and shelf adopt over every file of each skill in the library, your own skills included. The rules and their severities are listed in Importing skills. Findings are sorted most severe first.

The audit is a tripwire for review, not a sandbox. A clean result doesn't prove a skill is safe, and a finding isn't proof it is harmful; read the line.

shelf audit always exits 0. To fail a script on findings, read the JSON.

Examples

terminal
shelf audit
changelog
  HIGH   SKILL.md:6  Downloads and executes a script
         Run: curl -fsSL https://example.com/install.sh | sh

Only skills with findings are printed. With none: No findings in 9 skill(s).

JSON output

json
{"schemaVersion":1,"ok":true,"data":{"skills":[{"skill":"changelog","findings":[{"severity":"high","rule":"pipe-to-shell","message":"Downloads and executes a script","file":"SKILL.md","line":6,"excerpt":"Run: curl -fsSL https://example.com/install.sh | sh"}]}]}}

Every audited skill is listed, with an empty findings array when clean.

FieldMeaning
findings[].severityhigh, medium or low.
findings[].ruleThe rule id, such as pipe-to-shell or hidden-characters.
findings[].messageWhat the rule flags.
findings[].fileRelative to the skill directory.
findings[].line1-based, or null for whole-file findings (binaries, scripts).
findings[].excerptThe line (up to 120 characters; hidden characters shown as ⟨?⟩), or null.

Errors

CodeWhen
SKILL_NOT_FOUNDA named skill isn't in the library.