Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
avifenesh avatar

Enhance Skills

  • 2 installs
  • 931 repo stars
  • Updated July 26, 2026
  • avifenesh/awesome-slash

enhance-skills is a Claude Code skill that reviews SKILL.md files for structure, trigger quality, and discoverability.

About

enhance-skills analyzes SKILL.md files for trigger quality, structure, and discoverability. It validates frontmatter fields, checks that descriptions contain 'Use when' trigger phrases, verifies side-effect skills are protected from auto-invocation, and confirms tools are scoped. With --fix it applies auto-fixes for detected issues. It ships a complete frontmatter and invocation-control reference.

  • Analyzes SKILL.md files for frontmatter, trigger quality, and discoverability
  • Flags missing triggers, unrestricted Bash, and unprotected side-effect skills
  • Documents the full skill frontmatter reference and invocation-control patterns

Enhance Skills by the numbers

  • 2 all-time installs (skills.sh)
  • Ranked #611 of 782 Skill Development skills by installs in the Skillselion catalog
  • Data as of Aug 5, 2026 (Skillselion catalog sync)
At a glance

enhance-skills capabilities & compatibility

Capabilities
skill audit · trigger review · skill linting
Use cases
documentation · code review
From the docs

What enhance-skills says it does

Analyze skill definitions for trigger quality, structure, and discoverability.
SKILL.md
**Good:** `"Use when user asks to 'review code', 'check PR', or 'code review'"`
SKILL.md
npx skills add https://github.com/avifenesh/awesome-slash --skill enhance-skills

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs2
repo stars931
Last updatedJuly 26, 2026
Repositoryavifenesh/awesome-slash

What it does

Review SKILL.md files for strong triggers, safe invocation, and scoped tools.

Who is it for?

Improving SKILL.md trigger descriptions and tool scoping

Skip if: Improving agent frontmatter files or general prompts

When should I use this skill?

The user asks to review SKILL.md files for structure or trigger quality

What you get

SKILL.md files with strong triggers, protected side effects, and scoped tools.

  • Skill analysis report
  • Auto-fixed SKILL.md files

By the numbers

  • Skill descriptions capped at 1024 chars
  • SKILL.md recommended under 500 lines

Files

SKILL.mdMarkdownGitHub ↗

enhance-skills

Analyze skill definitions for trigger quality, structure, and discoverability.

Workflow

1. Discover - Find all SKILL.md files 2. Parse - Extract frontmatter and content 3. Check - Run all pattern checks against knowledge below 4. Filter - Apply certainty filtering 5. Report - Generate markdown output 6. Fix - Apply auto-fixes if --fix flag present

---

Skill Knowledge Reference

Frontmatter Fields (Complete Reference)

FieldRequiredDescriptionValidation
nameNoDisplay name, defaults to directory namelowercase, max 64 chars
descriptionRecommendedWhat skill does and when to usemax 1024 chars, should include trigger
argument-hintNoAutocomplete hint, e.g., [file-path]keep under 30 chars
disable-model-invocationNotrue = manual only (for side effects)boolean, default false
user-invocableNofalse = hidden from / menu (auto-only)boolean, default true
allowed-toolsNoTools Claude can use without permissioncomma-separated list
modelNoSpecific model when skill is activeopus, sonnet, haiku
contextNofork = run in isolated subagent contextfork or omit
agentNoSubagent type for executionExplore, Plan, general-purpose
hooksNoSkill-scoped lifecycle hooksPreToolUse, PostToolUse

Directory Structure

skills/my-skill/
├── SKILL.md           # Required - core definition (under 500 lines)
├── reference.md       # Optional - detailed documentation
├── examples.md        # Optional - usage examples
└── scripts/           # Optional - helper scripts
    └── helper.py

Storage Locations:

  • Enterprise: Managed settings
  • Personal: ~/.claude/skills/<name>/SKILL.md
  • Project: .claude/skills/<name>/SKILL.md

Invocation Control Patterns

Manual Only (for skills with side effects):

---
name: deploy
description: Deploy to production
disable-model-invocation: true
---

Background Knowledge (auto-only, hidden from menu):

---
name: legacy-context
description: How the legacy payment system works
user-invocable: false
---

Full Access (default - both auto and manual):

---
name: review
description: Use when user asks to review code. Checks quality and security.
---

Trigger Phrases

Description should include trigger context for auto-discovery:

  • "Use when user asks..."
  • "Use when..."
  • "Invoke when..."

Good: "Use when user asks to 'review code', 'check PR', or 'code review'" Bad: "Reviews code" (no trigger context)

Dynamic Context Injection

Skills can inject dynamic content using backtick syntax:

---
name: pr-summary
description: Summarize PR changes
context: fork
agent: Explore
allowed-tools: Bash(gh:*)
---

## Pull request context
- PR diff: !`gh pr diff`
- PR comments: !`gh pr view --comments`
- Changed files: !`gh pr diff --name-only`

Rules:

  • Use ! followed by backtick-wrapped command
  • Limit to 3 injections per skill
  • Each injection adds to context budget

String Substitutions

VariableDescription
$ARGUMENTSAll arguments passed when invoking
${CLAUDE_SESSION_ID}Current session ID

Context Budget

  • Skill descriptions have ~15,000 character default limit
  • Content beyond limit is truncated
  • Check with /context command
  • Increase via: SLASH_COMMAND_TOOL_CHAR_BUDGET=30000

Subagent Execution

When using context: fork:

---
name: deep-research
description: Research a topic thoroughly
context: fork
agent: Explore
allowed-tools: Read, Grep, Glob
---

Research $ARGUMENTS thoroughly:
1. Find relevant files
2. Analyze the code
3. Summarize findings

Agent Types:

AgentPurposeTool Access
ExploreRead-only codebase explorationRead, Grep, Glob only
PlanPlanning-focused reasoningRead, analysis tools
general-purposeFull capabilitiesAll tools

Skill-Scoped Hooks

---
name: secure-operations
hooks:
  PreToolUse:
    - matcher: "Bash"
      hooks:
        - type: command
          command: "./scripts/security-check.sh"
---

Tool Restrictions

Use scoped tool patterns for security:

PatternMeaning
Bash(git:*)Only git commands
Bash(npm:*)Only npm commands
Bash(gh:*)Only GitHub CLI
Read(src/**)Only files in src/

---

Detection Patterns

1. Frontmatter Validation (HIGH Certainty)

Required:

  • YAML frontmatter with --- delimiters
  • name field (lowercase, max 64 chars)
  • description field (max 1024 chars)

Recommended:

  • version field for tracking
  • argument-hint for skills accepting input
  • allowed-tools for security
  • model when specific model required

Flag:

  • Missing frontmatter delimiters
  • Invalid field values (uppercase name, description >1024 chars)

2. Trigger Quality (HIGH Certainty)

Check: Description includes trigger phrase Trigger patterns: "Use when", "Invoke when", "Use when user asks"

Flag:

  • Description without trigger context
  • Vague descriptions like "Useful tool" or "Does stuff"

3. Invocation Control (HIGH Certainty)

Check: Side-effect skills are protected

Flag:

  • Skills with deploy/ship/publish in name but disable-model-invocation not set
  • Dangerous auto-invocable skills (can accidentally trigger)

4. Tool Restrictions (HIGH Certainty)

Check: Tools are appropriately scoped

Flag:

  • Unrestricted Bash (should be Bash(git:*) or similar)
  • Read-only skills with Write/Edit
  • Research skills with Task tool

5. Content Scope (MEDIUM Certainty)

Guidelines:

  • SKILL.md under 500 lines
  • Large content in references/ subdirectory
  • Max 3 dynamic injections

Flag:

  • SKILL.md over 500 lines
  • More than 3 !backtick`` injections
  • Embedded large examples (move to examples.md)

6. Structure Quality (MEDIUM Certainty)

Recommended Sections:

  • Purpose/overview
  • Required checks or workflow steps
  • Output format
  • Examples (if complex)

7. Context Configuration (MEDIUM Certainty)

Check: Context settings are appropriate

Flag:

  • context: fork without agent type
  • agent type without context: fork
  • Mismatch between agent type and allowed-tools

8. Anti-Patterns (LOW Certainty)

  • Vague descriptions without specific triggers
  • Too many responsibilities (should split into multiple skills)
  • Missing argument-hint for skills that clearly need input
  • Redundant chain-of-thought instructions (modern models don't need "think step by step")

---

Auto-Fix Implementations

1. Missing frontmatter

---
name: skill-name
description: "Use when..."
version: 4.2.0
---

2. Missing trigger phrase

Add "Use when user asks..." prefix to description

3. Unrestricted Bash

Replace Bash with Bash(git:*) or appropriate scope

---

Output Format

## Skill Analysis: {skill-name}

**File**: {path}

### Summary
- HIGH: {count} issues
- MEDIUM: {count} issues

### Frontmatter Issues ({n})
| Issue | Fix | Certainty |

### Trigger Issues ({n})
| Issue | Fix | Certainty |

### Invocation Issues ({n})
| Issue | Fix | Certainty |

### Tool Issues ({n})
| Issue | Fix | Certainty |

### Scope Issues ({n})
| Issue | Fix | Certainty |

---

Pattern Statistics

CategoryPatternsAuto-Fixable
Frontmatter52
Trigger21
Invocation31
Tool31
Scope30
Structure20
Context30
Anti-Pattern40
Total255

---

<examples>

Example: Missing Trigger Phrase

<bad_example>

name: code-review
description: "Reviews code for issues"

Why it's bad: No trigger context for auto-discovery. </bad_example>

<good_example>

name: code-review
description: "Use when user asks to 'review code', 'check this PR'. Reviews code for issues."

Why it's good: Clear trigger phrases enable auto-discovery. </good_example>

Example: Dangerous Auto-Invocation

<bad_example>

name: deploy
description: "Deploys code to production"

Why it's bad: Side-effect skill could be auto-invoked accidentally. </bad_example>

<good_example>

name: deploy
description: "Deploy to production environment"
disable-model-invocation: true

Why it's good: Manual-only prevents accidental deployments. </good_example>

Example: Unrestricted Tools

<bad_example>

name: git-helper
allowed-tools: Bash

Why it's bad: Unrestricted Bash allows any command. </bad_example>

<good_example>

name: git-helper
allowed-tools: Bash(git:*)

Why it's good: Scoped to only git commands. </good_example>

Example: Oversized Skill

<bad_example>

# Complex Analysis
[800 lines of detailed instructions]

Why it's bad: Large skills consume context budget (15K char limit). </bad_example>

<good_example>

# Complex Analysis
Core instructions here (under 500 lines).
For details, see `references/detailed-guide.md`.

Why it's good: Core skill is concise; details in separate files. </good_example>

Example: Context/Agent Mismatch

<bad_example>

name: researcher
context: fork
# Missing agent type

Why it's bad: Fork context without specifying agent type. </bad_example>

<good_example>

name: researcher
context: fork
agent: Explore
allowed-tools: Read, Grep, Glob

Why it's good: Agent type matches allowed tools (Explore = read-only). </good_example> </examples>

---

Constraints

  • Only apply auto-fixes for HIGH certainty issues
  • Consider skill context when evaluating trigger quality
  • Never remove content, only suggest improvements
  • Validate against embedded knowledge reference above

Related skills

FAQ

What makes a good skill trigger?

A description with trigger context like 'Use when user asks to...' rather than a bare 'Reviews code'.

How does it protect side-effect skills?

It flags skills with deploy/ship/publish in the name that do not set disable-model-invocation, since they can accidentally auto-trigger.

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.