governanca

Validate SKILL.md definitions and permissions for compliance and security issues.

Updated Apr 12, 2026
One-click install
npx skills add https://github.com/MaxServDev/DriClaw-Evolution-local --skill governanca
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: governanca
Source: https://github.com/MaxServDev/DriClaw-Evolution-local/tree/main/.agents/skills/governanca
Command: npx skills add https://github.com/MaxServDev/DriClaw-Evolution-local --skill governanca

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Identifies misconfigurations, over-privileged tool requests, weak prompts, and architectural issues across repository skills to prevent security, compliance, and maintainability regressions.

Core Features & Use Cases

  • Frontmatter & Naming Validation: Verifies SKILL.md frontmatter fields, name format (lowercase-hyphen), and description quality for AgentSkills.io compliance.
  • Permission & Security Checks: Detects skills requesting inappropriate tools or excessive privileges and flags risky patterns.
  • Quality and Architecture Suggestions: Recommends exact prompt, permission, and structural improvements and produces actionable remediation guidance for onboarding, audits, or pre-deployment reviews.

Quick Start

Ask Dri to audit a target skill and return a structured compliance report listing issues, severity, and exact suggested fixes.

Frequently Asked Questions about governanca

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit SKILL.md files for security and compliance issues?

To audit SKILL.md files for security and compliance issues, validate skill definitions and requested permissions to detect misconfigurations, over-privileged tool requests, and frontmatter mismatches. This generates a structured compliance report with severity levels and exact suggested fixes.

What is skill governance and when do I need permission validation?

Skill governance is the process of validating skill definitions and requested permissions to detect compliance, security, and integrity issues. You need permission validation during onboarding, code review, and periodic governance audits to catch naming, frontmatter, and permission mismatches.

How do I detect over-privileged tool requests in repository skills?

To detect over-privileged tool requests in repository skills, validate skill definitions and requested permissions to flag risky patterns and inappropriate tools. This security check produces actionable remediation guidance to prevent security and maintainability regressions.

Can I verify AgentSkills.io compliance for frontmatter and naming formats?

Yes, you can verify AgentSkills.io compliance by validating SKILL.md frontmatter fields, name format (lowercase-hyphen), and description quality. This ensures your repository skills meet compliance standards and prevents architectural issues.

What's the best way to check skill architecture and prompt quality before deployment?

The best way to check skill architecture and prompt quality before deployment is to validate skill definitions and permissions, which identifies weak prompts and architectural issues. This produces a structured report listing issues, severity, and exact suggested fixes.

Does skill governance require file access and script execution to validate definitions?

Yes, skill governance requires file access and optional script execution to validate definitions and permissions. It also uses web and vision lookups to detect compliance, security, and integrity issues, generating structured reports with actionable remediation steps.