Comprehensive validation suite for Claude Code plugins, marketplaces, hooks, skills, and MCP servers
active 2026-01-23 → 2026-08-05 (UTC)
Activity over time
Daily event counts in the loaded window
Line chart, 195 days from 2026-01-23 to 2026-08-05. Pushes: 192 total, peak 10 in a day. Pull requests: 0 total, peak 0 in a day. Issues: 24 total, peak 7 in a day. Comments: 16 total, peak 5 in a day. Stars: 1 total, peak 1 in a day.
- Pushes
- Pull requests
- Issues
- Comments
- Stars
Stars, PRs, issues and forks are under-captured in the later part of this window. GH Archive progressively stopped capturing non-push events during 2026 — −95% or worse by the end of the window. Every series here except Pushes fades for that reason, so a decline above reflects the archive, not this repository. Pushes stay reliable throughout, so read them, and the contributor counts derived from them, as the real signal. Data health has the measurements.
Top contributors
Pushes, PRs, issues, reviews and comments — stars and forks excluded, so this is contribution rather than popularity
| Contributor | Contributions | Pushes | PRs | Comments |
|---|---|---|---|---|
| Emasoft | 230 | 190 | 0 | 16 |
| dependabot[bot] | 2 | 2 | 0 | 0 |
Recent activity
Latest issues, pull requests and releases
- Issue#152Emasoft2026-06-24 00:55C1 fold: accept a plugin's own hard-coded ~/.claude/plugins/data/<slug>/ daemon-launcher target (source-provided, no binaries)
- Issue#118Emasoft2026-06-16 23:56RC-PIPELINE-DRIFT-001: --force-templates output is staler than the warning text + detector can't distinguish ahead/behind (regresses hardened plugins)
- Issue comment#76Emasoft2026-06-16 09:08SkillAudit context-aware matcher (post-#33) still blocks legitimate documentation under --strict (demotes, does not suppress)
- Issue#94Emasoft2026-06-16 08:59Suggestion: add 'workflows' to known_dirs — plugins now ship Workflow-DSL (ultracode) scripts
- ReleaseEmasoft2026-06-15 23:32Release v2.126.26
- Issue#87Emasoft2026-06-14 08:41False positive: CMD_INJECTION on a documented shell-usage snippet (sh "$VAR/...") in a markdown code fence
- Issue comment#106Emasoft2026-06-14 07:28Dependency-pinning guidance contradicts itself: validate_plugin advises {name,version} object form, validate_marketplace rejects non-strings
- Issue#89Emasoft2026-06-14 05:40Progressive-discovery TOC check: per-inline-link duplication + verbatim-only matching produces many confusing MINORs
- Issue comment#106Emasoft2026-06-14 05:11Dependency-pinning guidance contradicts itself: validate_plugin advises {name,version} object form, validate_marketplace rejects non-strings
- Issue#109Emasoft2026-06-14 04:29Noise: MCP-tool-in-prose warning fires per-mention on documentation sections (18x on one plugin)
- Issue#117Emasoft2026-06-14 03:23False positive: 'Rust source ... no pre-compiled binaries in bin/ — users will need to compile' fires when the plugin ships prebuilt binaries as release assets + a checksum-verified installer
- Issue comment#117Emasoft2026-06-14 03:23False positive: 'Rust source ... no pre-compiled binaries in bin/ — users will need to compile' fires when the plugin ships prebuilt binaries as release assets + a checksum-verified installer
- Issue#119Emasoft2026-06-14 02:37Link-checker FP: apt/dnf package-repo BASE URLs (e.g. cli.github.com/packages) flagged as Dead URL 404
- Issue#91Emasoft2026-06-14 01:52skillaudit REGEX_DOS false positive: linear dynamically-built RegExp flagged as catastrophic
- Issue comment#91Emasoft2026-06-14 01:52skillaudit REGEX_DOS false positive: linear dynamically-built RegExp flagged as catastrophic
- Issue comment#76Emasoft2026-06-14 00:27SkillAudit context-aware matcher (post-#33) still blocks legitimate documentation under --strict (demotes, does not suppress)
- Issue#120Emasoft2026-06-14 00:17FP: .gitignore '.claude/' coverage check unsatisfiable when a plugin tracks content under .claude/ (e.g. .claude/project/memory/)
- Issue#111Emasoft2026-06-11 23:17FP: backtick-path check flags deliberately-external paths (upstream-repo and runtime cwd-relative citations)
- ReleaseEmasoft2026-06-09 22:41Release v2.126.2
- Issue comment#69Emasoft2026-06-08 01:32skillaudit false positives (v2.99.1 regression) block --strict publish: TOKEN_STEAL / CMD_INJECTION / A2A_CROSS_AGENT_INJECT / INTENT_DESTRUCTIVE_INTENT over-fire on benign governance docs
- Issue comment#67Emasoft2026-06-08 01:31validate_security 2.116.1: false positives — code-rules fire on docs/diagrams/data (RC-119/24/67/122-123/112-113, placeholder creds)
- Issue#65Emasoft2026-06-08 01:31skillaudit FP regression: 19 CRITICAL false-positives on a security-scanner plugin (CAA v3.4.x, CPV v2.116.1) — #57/#58/#59 fixes don't hold for .py/.yml/vendored-CPV code
- Issue comment#70Emasoft2026-06-07 02:34cpv-pre-install-scan unusable: validate_plugin --json writes REPO LINT to stdout (blocker) + skillaudit self-match false positives
- Issue#60Emasoft2026-05-31 03:33skillaudit FP: yaml.load with a SafeLoader subclass flagged as unsafe deserialization
- Issue comment#61Emasoft2026-05-31 03:33skillaudit FP: rm of a LaunchAgents plist (removal) flagged as a persistence mechanism
Totals cover only the window loaded into ClickHouse and count events, not GitHub's lifetime totals — 1 stars here means stars gained during the window, not the repo's star count.