Catalog-building price — 25% off. Code tap to copy

Skill Kit · Node.js CI + review kit

Agent Skill Production Kit

The review layer every publishable Claude Code skill needs — validate, scan, ship.

⇩ Instant download — yours right after checkout

Official scaffolding gets you a well-formed skill; it doesn't check whether that skill is safe for a stranger to install. An audit of 22,511 public Claude Code skills found about 6.3 issues each, and Snyk's ToxicSkills research found prompt injection in 36% of skills tested. This kit is the layer scaffolding skips: a CI schema validator for skills, agents, commands, hooks and plugin manifests, and a static review harness that flags credential access, network egress and prompt-injection-shaped instructions before an installer finds them — with real, tested fixtures (a clean example and a deliberately flawed one) proving the scan actually works, not just claiming it. Scaffolds, release automation and a distribution playbook included. Picks and shovels for the same ecosystem as our MCP kit: it pays off whichever skill wins.

Built for: Developers publishing Claude Code skills, agents, commands or plugins that strangers will install

Pick your license

Solo

$79

One developer, unlimited skills.

  • The full kit
  • Validator + review harness
  • Scaffolds + fixtures
  • 12 months of updates

One developer's own projects.

Most popular

Team

$149

Your whole team ships with it.

  • Everything in Solo
  • Team-wide license
  • Priority email support

One team, internal and client skills.

Agency

$349

Unlimited client work.

  • Everything in Team
  • Unlimited client skills/plugins
  • Source design files where provided

Unlimited client projects.

14-day money-back guarantee — if the kit doesn't fit your stack, reply to your receipt within 14 days and we refund it in full. Keep nothing, owe nothing.

More from the store

AI Usage Billing Kit

Credits that can't double-spend, caps that hold, and margin you can actually see.

AI Voice Receptionist Kit

Answer every call for your clients — on your own keys, at your own margin.

Agent Eval Harness Kit

The eval layer free runners leave as an exercise — task sets, rubrics & a CI gate that says no.

Questions

What exactly do I get?

An instant download: the CI schema validator and static review harness (both real, tested Node scripts), scaffolds for skill/agent/command/hook, two working fixtures (a clean skill and a deliberately flawed one the harness catches on purpose), a release-automation script, a distribution playbook, and 12 months of kit updates from your library link. npm test runs both tools against the bundled fixtures.

Why not just use the free official scaffolding?

Scaffolding gets you a well-formed skill; it doesn't tell you whether it's safe. A public audit found about 6.3 security issues per skill on average, and prompt injection in 36% of skills tested. This kit is the review layer scaffolding was never meant to be.

Does this guarantee my skill is safe?

No, and we'd rather say that up front. The review harness is a heuristic static scanner — the same category of tool as a linter, not a sandboxed analyzer. It reliably catches the common, un-obfuscated issues that make up most of that 6.3-per-skill average. It is not a certification and it is not affiliated with or endorsed by Anthropic.

Was this scoped by AI?

The niche was researched, scored and gate-checked by Upshift's commercial engine — ecosystem scale, security-audit data and a comparable free kit's pricing all verified before it earned a build slot. The kit itself is engineered and QA'd by hand against the same contract the engine validated.

01 / 01

Drag to read · 2880px capture