Home / Claude Code skill packs

claude-code-tooling-skills

Claude Code skills for keeping a Claude Code setup safe.

Python · MIT · latest v0.1.0

What it is

Eight skills, each with an offline, standard-library Python script and tests: skill-supply-chain-review, skill-description-linter, skill-trigger-eval, context-budget-audit, permissions-builder, hook-author, skill-collision-check and skill-portability-check.

claude-code-tooling-skills is a Claude Code plugin for the upkeep of Claude Code itself. A setup grows by accretion: skills and plugins installed from other people's repositories, descriptions written once and never measured, memory files and MCP servers that fill the context before the first word, permission rules added one "always allow" at a time, hooks copied from examples, two skills with the same name, a script that works on one laptop only. Each skill here turns one of those into a check with a script that reads local files, applies stated rules, and reports what it found with the file and line, leaving the decision to you.

Who it is for: people who write or maintain Claude Code skills and plugins, teams that share a .claude/ folder in a repository, and anyone about to install a skill or plugin they did not write.

Why: skill and plugin supply chains are now an attack path, descriptions decide whether a skill is ever used, and the context window is shared by everything installed. The author already maintains command-line tools for parts of this (skill-scan-gate, cc-plugin-lock, claude-perm-sim, claude-mcp-allow, cc-hooks, mcp-tools-lint); these skills tell Claude when and how to run them, and add the offline checks they do not cover.

/plugin marketplace add basitalisandhu/claude-code-tooling-skills
/plugin install cc-setup-tooling@claude-code-tooling-skills

Quickstart: open Claude Code in a folder of skills and ask "will this skill work on Windows?" or "why is my context so full?". Or run a script directly from a clone of this repository:

python3 scripts/cli.py portability path/to/my-skill
python3 scripts/cli.py desc-lint path/to/skills --diff
python3 scripts/cli.py context-budget . --home ~

Questions, bugs and ideas: open an issue on this repository. Security reports: see SECURITY.md.

Releases

Topics: agent-skills, ai-agents, ai-security, claude-code, claude-code-plugin, claude-code-skills, claude-skills, context-engineering, developer-tools, hacktoberfest, hooks, linting, permissions, python, skill-security, supply-chain-security