.claude-plugin — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited .claude-plugin (MCP Server) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Official Revelica plugin for AI coding tools — provides MCP-connected skills for product intelligence. Follows the Agent Skills open standard, compatible with Claude Code, Cursor, Gemini CLI, OpenAI Codex, and more.
revelica/skills
├── .claude-plugin/
│ ├── marketplace.json # Claude Code marketplace catalog
│ ├── plugin.json # Claude Code plugin manifest
│ └── mcp.json # MCP config for Claude Code plugin
├── .cursor-plugin/
│ └── plugin.json # Cursor plugin manifest
├── skills/ # Skill definitions (Agent Skills open standard)
│ ├── product-for-coding-agents/ # Product layer for coding agents (orientation)
│ └── write-spec/ # Author a feature spec attached to an idea
├── server.json # MCP registry manifest (registry.modelcontextprotocol.io)
├── .mcp.json # MCP config for Cursor/Gemini
└── gemini-extension.json # Gemini CLI extension manifest/plugin marketplace add revelica/skills
/plugin install revelica@revelicaSkills are model-invoked — Claude automatically uses them based on context. The MCP server is registered automatically.
Install via the .cursor-plugin/plugin.json manifest. Cursor will discover skills from the skills/ directory and connect to the MCP server via .mcp.json automatically.
gemini extensions install revelica/skillsThe gemini-extension.json manifest registers both skills and the MCP server.
These tools are provided by the Revelica MCP server and callable from any skill:
| Tool | Description |
|---|---|
query | Search the workspace knowledge base — artifacts, entities, schemas. Filter by artifact_type, control detail with depth. |
read | Read a single artifact or entity in full by id. |
create | Create new artifacts or entities. Content validated against registered schemas. |
update | Apply partial field-level updates via dot-path notation. |
load_skill | Load a skill's instructions and prefetched workspace data. |
All tools require OAuth authentication and enforce Supabase RLS — users only see their own workspace's data.
| Skill | Description |
|---|---|
product-for-coding-agents | Orientation for a coding agent: read the idea/spec/UX behind the code, write high-level results (impl docs, PRs, tested feasibility assumptions, ideas, sources) back. |
write-spec | Author a feature spec attached to an idea, following the Revelica spec template — incremental section-by-section writes that fit coding-agent tool-call budgets. |
skills/: mkdir skills/my-skill
touch skills/my-skill/SKILL.mdSKILL.md following the Agent Skills spec: ---
name: my-skill
description: What this skill does and when to use it.
compatibility: Requires Revelica MCP server (query, read, create, update tools)
---
Instructions for the agent... /plugin update revelica@revelicaNo backend changes needed unless the skill requires a new MCP tool.
Revelica is an AI-native product discovery platform. It helps product managers create customer insights, competitive analysis, and validated specs that feed into their AI development workflow.
🔗 https://revelica.com
🔗 https://app.revelica.com/insights
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.