capability-auditorlisted
Install: claude install-skill Xopoko/plug-n-skills
# Capability Auditor
Bundled commands use `$PLUGIN_ROOT` (`$env:PLUGIN_ROOT` in PowerShell; same path suffix) for the plugin root. Set it once: use the host's plugin-root variable when defined (Claude Code: `PLUGIN_ROOT="$CLAUDE_PLUGIN_ROOT"`), otherwise the absolute path of this skill folder's `../..`.
Use this for independent review before adopting, installing, publishing, or relying on a skill or plugin.
This is a static/source audit. When the decision depends on whether a candidate
artifact changes agent behavior relative to an explicit baseline, route the
controlled comparison and adoption receipt to `capability-evaluation`. Route
runner, orchestration, cancellation, recovery, or harness reliability failures
to Agent Harness.
## Audit Spine
1. Identify the subject: skill folder, plugin folder, marketplace entry, synthesis package, or candidate source.
2. Inventory files and metadata.
3. Classify risks as `required`, `optional`, `example`, `advisory`, or `hidden`.
4. Measure context density when the subject affects hot context or repeated agent behavior.
5. If audit findings imply split, merge, delete, router, reference-extract, or script-extract decisions, hand off to `capability-portfolio-architect` before changing structure.
6. Validate structure and run deterministic self-tests.
7. For synthesized or installed outputs, validate install scope, source surface, install requirement, and whether any required activation proof exists.
8. Produce a verdict: eligible, eli