Skip to content
Back to skills

Waffle Validate

ASecurity

Validate wafflestack's own toolkit definitions — manifests, frontmatter, and placeholder declarations. Use when authoring or forking the toolkit itself, not for a plain consuming repo.

  • 2 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 19, 2026
ai-agentsbashnodegit

Works with

  • cli

Security analysis

A100/100

Scanned September 19, 2026

npx -y skills add dustinkeeton/wafflestack --skill waffle-validate --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Waffle Validate?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Waffle Validate
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/dustinkeeton-waffle-validate/badge)](https://www.skillsdirectory.com/skills/dustinkeeton-waffle-validate)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: waffle-validate
description: Validate wafflestack's own toolkit definitions — manifests, frontmatter, and placeholder declarations. Use when authoring or forking the toolkit itself, not for a plain consuming repo.
user-invocable: true
argument-hint: "(no arguments)"
---

# Validate the toolkit definitions

Wraps `wafflestack validate` — the **toolkit-developer** lint. It loads every `stack.yaml`
plus its agents/skills/`files` and reports problems: missing descriptions, frontmatter `name`
mismatches, placeholders referencing dotted config keys the `stack.yaml` never declares,
declared config keys that are never referenced, dangling `requires:`/`optIn:` refs, and
`pattern:` defaults that fail their own regex. It exits non-zero when any problem is found.

## Scope — read this before running

`validate` checks the **toolkit source**, not this consuming repo's render. Run against the
published toolkit it just confirms the release is well-formed (always clean); its real value is
while **developing or forking** the toolkit — after editing a `stack.yaml`, a `SKILL.md`, an
agent, or a `files/` payload.

- **Toolkit checkout (the common case):** run the CLI against the working tree so you validate
  your edits, not the published copy:
  ```bash
  node installer/cli.mjs validate
  ```
- **Via the pinned ref (published toolkit):** confirms the release itself is valid:
  ```bash
  npx --yes github:dustinkeeton/wafflestack validate
  ```
  Point `github:dustinkeeton/wafflestack` at a local path to validate a fork without publishing.

## Interpret the result

- **`toolkit is valid`** — clean; safe to render/commit.
- **`N problems`** — each line is `stack <name>: <problem>`. Fix at the **source**: declare a
  missing placeholder in that `stack.yaml` `config:`, remove or reference an unused key, add a
  missing description, or correct a `requires:`/`optIn:` ref. Re-run until clean, then
  **`/waffle-render`** so the render and lock reflect the fixed source.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…