Skip to content

Validate SKILL.md frontmatter in CI - #440

Open
Mosquito1123 wants to merge 2 commits into
cursor:mainfrom
Mosquito1123:validate-skill-frontmatter
Open

Mosquito1123 wants to merge 2 commits into
cursor:mainfrom
Mosquito1123:validate-skill-frontmatter

Conversation

@Mosquito1123

@Mosquito1123 Mosquito1123 commented Sep 27, 2026 •

Copy link
Copy Markdown

scripts/validate-plugins.mjs only validated marketplace.json and each
plugin.json, and the workflow's paths filter excluded **/SKILL.md, so
skill frontmatter was never checked and could drift silently.

Changes

  • Add schemas/skill.schema.json describing SKILL.md frontmatter
    (required name and description; name in kebab-case; unknown keys
    allowed so plugins keep harness-specific options).
  • Parse and validate every SKILL.md frontmatter with Ajv, and require the
    frontmatter name to match the skill's folder name.
  • Add **/SKILL.md and scripts/** to the workflow paths filter and
    install the yaml parser.

Fixes for the violations this exposes

The validator is green on the updated tree and reports each of these cases
when reintroduced.

Note for reviewers

Enforcing name == folder is the one deliberate policy choice here: 91 of the
96 skills already match, and #237 / #269 are filed about the mismatches. If you
would rather allow a separate display name, I'm happy to relax that check to
the kebab-case pattern only.


Note

Low Risk
Changes are limited to CI validation scripts and skill metadata fixes; no runtime product or auth/data paths are modified.

Overview
Adds CI validation for SKILL.md YAML frontmatter so skill metadata cannot drift without failing the validate-plugins workflow.

A new schemas/skill.schema.json requires name (kebab-case) and description, with extra frontmatter keys still allowed. scripts/validate-plugins.mjs now walks every SKILL.md, parses frontmatter with the yaml package, validates against that schema, and requires name to match the parent folder name. The same script also fails if any repo directory with .cursor-plugin/plugin.json is missing from marketplace.json.

The GitHub workflow runs on changes to **/SKILL.md and scripts/** and installs yaml alongside Ajv. Several existing skills are updated to pass the new rules (kebab-case names aligned with folders, quoted description where ": " broke YAML parsing).

Reviewed by Cursor Bugbot for commit 3ea2c18. Bugbot is set up for automated code reviews on this repo. Configure here.

scripts/validate-plugins.mjs only validated marketplace.json and each
plugin.json, and the workflow's paths filter excluded **/SKILL.md, so skill
frontmatter was never checked and could drift silently.

- Add schemas/skill.schema.json describing SKILL.md frontmatter (required
  `name` and `description`; name in kebab-case; unknown keys allowed so
  plugins can keep harness-specific options).
- Parse and validate every SKILL.md frontmatter with Ajv, and require the
  frontmatter `name` to match the skill's folder name.
- Add **/SKILL.md and scripts/** to the workflow paths filter and install
  the `yaml` parser.

Fix the violations this exposes:

- agent-compatibility/skills/check-agent-compatibility: quote a description
  containing ": " so the frontmatter parses (closes cursor#381).
- third_party/x/skills/x-api-mcp-guide: name "X MCP guide" -> "x-api-mcp-guide" (closes cursor#269).
- pstack/skills/poteto-mode: name "Poteto Mode" -> "poteto-mode" (closes cursor#237).
- pstack/skills/make-bot-ui: name "Make Bot UI" -> "make-bot-ui".
- third_party/x/skills/x-chat: name "X Chat" -> "x-chat".
- third_party/x-money/skills/x-money-guide: name "X Money guide" -> "x-money-guide".

The validator is green on the updated tree and reports each of these when
reintroduced.
The validator only iterated the marketplace entries, so a plugin directory
added without a marketplace entry would pass CI and never be listed. Walk the
repository for `.cursor-plugin/plugin.json` files and fail when one is missing
from `.cursor-plugin/marketplace.json`.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant