agent-builder — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited agent-builder (Agent Skill) and scored it 92/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 2 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 2 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
The authoritative agent-authoring guidance ships in this plugin. Read the specific document a decision needs, when that decision is on the table — never read them all up front, because that defeats progressive disclosure and burns context on guidance the current agent does not touch.
${CLAUDE_PLUGIN_ROOT}/skills/guidance/references/${CLAUDE_PLUGIN_ROOT}/skills/guidance/references/agent-building-guidelines/Map from decision to governing document (read just-in-time):
| Decision on the table | Read |
|---|---|
| Agent vs. skill vs. hook; one role (generate or evaluate) | plugin-entity-taxonomy.md, agent-building-guidelines/agent-domain-focus.md |
| Domain focus, vocabulary, role identity, anti-patterns | agent-building-guidelines/agent-domain-focus.md |
The description field (four components, boundaries, length) | agent-building-guidelines/agent-description-length.md, skill-building-guidance/skill-description-frontmatter.md |
Model tier (opus / sonnet / haiku / inherit) | agent-building-guidelines/agent-model-selection.md, specialization-and-model-selection.md |
| Self-containment — no references, scripts, or context injection | agent-building-guidelines/agent-external-files.md |
| Which frontmatter fields are valid (and which plugins ignore) | agent-building-guidelines/agent-external-files.md |
| Degraded environments (no git, missing tools) | agent-building-guidelines/graceful-degradation.md |
| Whether this agent is justified at all; how it gets dispatched | agent-building-guidelines/multi-agent-economics.md, skill-building-guidance/agent-dispatch-namespacing.md |
| New plugin needed (plugin.json, marketplace.json) | claude-marketplace-and-plugin-configuration/ and templates/ |
about every aspect of the agent until you reach a shared understanding. Walk down each branch of the design tree, resolving dependencies between decisions one-by-one. If a question can be answered by exploring the repository — the target plugin's existing agents, sibling descriptions, the skills that would dispatch this agent, conventions, the guidance documents above — explore instead of asking. Only surface questions that genuinely require the user's judgment.
let its answer resolve dependent decisions, then ask the next. Later answers routinely make earlier questions moot.
recommended answer with rationale grounded in evidence (existing agents, conventions, the guidance, the user's stated goal). The user can accept, amend, or redirect.
document when a decision is on the table (Step 4), and run a full guidance-conformance pass over the finished agent at the end (Step 6). The interview gets each decision approximately right; the review pass makes the artifact correct.
.md file. No references/ folder, no scripts/ folder, no ` !command ` context injection. Everything the agent needs is inlined in its body.
Read the user's argument and the conversation to extract what the agent should do. If the request is too thin to start (for example, just "build an agent"), ask the user for one or two sentences on the agent's domain and what it produces — nothing else yet.
Confirm the entity type before anything else. Read ${CLAUDE_PLUGIN_ROOT}/skills/guidance/references/plugin-entity-taxonomy.md and apply its decision heuristic. An agent is the thinking layer: it applies contextual judgment, taste, and discernment ("Does this require reasoning about context?" → agent). If the work is a deterministic, flowchartable process, it is a skill — stop and recommend skill-builder. If it fires automatically on an event, it is a hook.
Confirm the single role. An agent generates or evaluates, never both, because self-evaluation bias means the reasoning that created a blind spot also rates it as correct (agent-domain-focus.md). If the request bundles generation and evaluation, recommend splitting it into a generator agent and a separate evaluator agent. Only proceed once an agent — with one role — is the right entity.
Locate the target plugin and learn its conventions before asking the user anything beyond the framing. Use Glob, Grep, and find to gather:
.claude-plugin/plugin.json. Confirm theplugin actually ships agents (an agents/ directory) or is the right home for the first one. If the user has not said which plugin, infer candidates and confirm in Step 4.
{plugin}/agents/*.md) — their descriptions,role identities, model tiers, domain vocabulary, and the boundaries they draw. A new agent's description must disambiguate against near-sibling agents in both directions.
via the Agent tool using the qualified defining-plugin:agent-name. Knowing the caller tells you what the agent receives and returns.
time, which drives graceful-degradation wording.
Record what was found (file paths) and what was not.
Enumerate the decisions the agent needs, in dependency order. Resolve foundational decisions before dependent ones; never ask a dependent question before its parent is settled.
Generate or evaluate? What does the agent produce, and who dispatches it?
(under 50 tokens, domain + task + perspective, no flattery)? What 15-30 domain-vocabulary terms pass the 15-year-practitioner test? What 5-10 named anti-patterns with detection signals does the agent hunt for?
description say across all four components(what, when, boundary, breadth), and how does it disambiguate against near-sibling agents in both directions, within 1024 characters?
opus forsynthesis and judgment, sonnet for structured procedures, haiku for fast lookups, inherit only when matching the session is intentional)? What tools does it need — and never the Agent tool, because subagents cannot spawn subagents?
does the agent need to do its job, given it cannot use external files? Where does graceful-degradation wording belong?
Keep each node a concrete decision with a candidate answer. Do not pre-fill the tree with content the user has not confirmed.
For each decision in dependency order:
agents, calling skills, conventions, and the governing guidance document for this decision (see the map above). If the evidence answers it, record the decision with its evidence and move on — do not ask.
guidance and the evidence available. Read the governing document first so the recommendation is correct, not improvised.
and the alternatives. State what changes depending on the answer. Wait for the answer before asking anything else.
decisions the new answer resolves, and continue.
Keep the interview moving — do not stall on questions the evidence can answer, and do not batch.
Write the single self-contained file:
{plugin}/agents/ if it does not exist (use mkdir), then write{plugin}/agents/{agent-name}.md. The file is flat — no per-agent subdirectory, no companion folders.
name, the description settled in the interview, tools(the allowlist — agents use tools, not allowed-tools), and model. Add other supported fields (disallowedTools, maxTurns, color, and so on) only when a decision called for them. Do not rely on `hooks`, `mcpServers`, or `permissionMode` — Claude Code ignores all three on plugin agents as a security boundary. No XML angle brackets in any frontmatter value.
## Domain Vocabulary section, the ## Anti-Patterns section, and the inlined protocol or checklist the agent follows. Embed reasoning in constraints. Add graceful-degradation wording ("If {tool} is not available, skip this step and note the limitation") to any tool-dependent step. No flattery, superlatives, or motivational framing — let domain vocabulary do the routing.
the claude-marketplace-and-plugin-configuration/ guidance and templates/.
This is the review pass the skill commits to. Re-read each governing document that applies to what you built and verify the finished agent against it, applying every fix directly. Do not summarize problems for the user without fixing them. Cover at minimum:
plugin-entity-taxonomy.md,agent-building-guidelines/agent-domain-focus.md) — the agent is genuinely a judgment layer, targets one narrow domain, and only generates or only evaluates.
agent-domain-focus.md) — the opening paragraph is under50 tokens, states domain + task + perspective, and carries no flattery or motivational filler.
agent-domain-focus.md) — 15-30precise terms that pass the 15-year-practitioner test, and 5-10 named anti-patterns each with a detection signal, both inlined in the body.
agent-description-length.md,skill-description-frontmatter.md) — covers what, when, boundary, and trigger breadth; names near-sibling agents in boundary clauses; disambiguates in both directions (repair the sibling's description if a one-way gap exists); within 1024 characters, with domain vocabulary and anti-patterns kept in the body, not the description.
agent-model-selection.md,specialization-and-model-selection.md) — model is set explicitly and matches the cognitive load, chosen on capability and not on cost.
agent-external-files.md) — no references/ orscripts/ folder, no ` !command context injection; all protocol and reference content is inlined; frontmatter uses tools (not allowed-tools`), and the file relies on no field plugins ignore.
agent-dispatch-namespacing.md, agent-external-files.md) —the agent does not have the Agent tool (subagents cannot spawn subagents), and the tools allowlist is the minimum the work needs.
agent-building-guidelines/graceful-degradation.md)— every tool-dependent step checks availability inline and notes the limitation when the tool is absent.
multi-agent-economics.md) — the agent clearsthe bar for existing: a single well-prompted agent or an instruction improvement to an existing agent would not do the job as well.
Apply the YAGNI discipline throughout: vocabulary terms, anti-patterns, tools, and frontmatter fields must each earn their place against the agent's actual job. Cut anything added "for completeness."
Summarize for the user:
and anti-pattern counts).
defining-plugin:agent-name andwhich skill (existing or to-be-built) would call it. If a calling skill is needed and does not exist, recommend skill-builder.
Note that plugin entities rarely land in one pass: per iterative-plugin-development.md, plan for 3-5 iterations. Ask whether the user wants to iterate on the agent's domain framing or considers it ready to test.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.