/verify-plugin
Minimum pass rate threshold (0.0-1.0, default 0.8)
$ npx -y skills add athola/claude-night-market --agent claude-codeHow it fires
How this command gets triggered: by you, by Claude, or both.
- Fires itselfClaude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/verify-plugin
Context preview
What this command does when you run it.
Minimum pass rate threshold (0.0-1.0, default 0.8)
Command definition
verify-plugin.mdname: verify-plugin
description: Verify plugin behavioral contract history via GitHub Attestations (SLSA)
arguments:
- name: plugin-name
description: Name of the plugin to verify
required: true
- name: --level
description: Minimum assertion level to check (L1, L2, L3)
required: false
- name: --min-score
description: Minimum pass rate threshold (0.0-1.0, default 0.8)
required: falseVerify Plugin Trust
Query GitHub Actions workflow runs for a plugin's behavioral contract assertion history and produce a trust assessment. Uses GitHub's free SLSA attestation infrastructure.
When to Use
- Before installing a plugin from an unfamiliar source
- In CI pipelines to gate deployments on trust scores
- To audit a plugin's verification track record over time
- When evaluating whether to upgrade trust level requirements
When NOT to Use
- The plugin is local-only with no GitHub Actions history
- You are offline and cannot reach the GitHub API
- The trust-attestation workflow has not been set up yet
Workflow
The command runs the verification script which:
1. **Parse arguments**: plugin name, optional level and score threshold 2. **Query GitHub API**: fetch recent workflow run results for the repository 3. **Compute pass rates**: calculate L1/L2/L3 pass rates from workflow conclusions 4. **Produce assessment**: return a recommendation of "trusted", "caution", or "untrusted" based on whether the target level meets the minimum score threshold
Output
The script prints a human-readable summary:
Plugin: sanctum
Recommendation: trusted
Meets threshold: True
Level scores:
L1: 10/10 (100.0% pass rate)
L2: 0/0 (0.0% pass rate)
L3: 0/0 (0.0% pass rate)
Recent assertions: 10 records
Use `--json` for machine-readable output in CI.
Exit Codes
| Code | Meaning | |------|---------| | 0 | Plugin meets trust threshold | | 1 | Plugin does not meet threshold | | 2 | Error (gh CLI unavailable, API failure) |
Examples
Verify with defaults (L1, 80% threshold):
python3 plugins/leyline/scripts/verify_plugin.py sanctum
Strict L3 verification:
python3 plugins/leyline/scripts/verify_plugin.py sanctum --level L3 --min-score 0.9
JSON output for CI:
python3 plugins/leyline/scripts/verify_plugin.py sanctum --json
Prerequisites
- The `gh` CLI must be installed and authenticated
- Use `--repo owner/repo` to specify a different repository
(default: athola/claude-night-market)
Notes
- All GitHub API calls are read-only; no write permissions
needed
- Assertion history comes from the 10 most recent completed
workflow runs
- The caution zone is between 70% and 100% of the
threshold (e.g., for 0.8 threshold, 0.56-0.79 is caution)
Read more
name: verify-plugin
description: Verify plugin behavioral contract history via GitHub Attestations (SLSA)
arguments:
- name: plugin-name
description: Name of the plugin to verify
required: true
- name: --level
description: Minimum assertion level to check (L1, L2, L3)
required: false
- name: --min-score
description: Minimum pass rate threshold (0.0-1.0, default 0.8)
required: falseVerify Plugin Trust
Query GitHub Actions workflow runs for a plugin's behavioral contract assertion history and produce a trust assessment. Uses GitHub's free SLSA attestation infrastructure.
When to Use
- Before installing a plugin from an unfamiliar source
- In CI pipelines to gate deployments on trust scores
- To audit a plugin's verification track record over time
- When evaluating whether to upgrade trust level requirements
When NOT to Use
- The plugin is local-only with no GitHub Actions history
- You are offline and cannot reach the GitHub API
- The trust-attestation workflow has not been set up yet
Workflow
The command runs the verification script which:
1. **Parse arguments**: plugin name, optional level and score threshold 2. **Query GitHub API**: fetch recent workflow run results for the repository 3. **Compute pass rates**: calculate L1/L2/L3 pass rates from workflow conclusions 4. **Produce assessment**: return a recommendation of "trusted", "caution", or "untrusted" based on whether the target level meets the minimum score threshold
Output
The script prints a human-readable summary:
Plugin: sanctum Recommendation: trusted Meets threshold: True Level scores: L1: 10/10 (100.0% pass rate) L2: 0/0 (0.0% pass rate) L3: 0/0 (0.0% pass rate) Recent assertions: 10 records
Use `--json` for machine-readable output in CI.
Exit Codes
| Code | Meaning | |------|---------| | 0 | Plugin meets trust threshold | | 1 | Plugin does not meet threshold | | 2 | Error (gh CLI unavailable, API failure) |
Examples
Verify with defaults (L1, 80% threshold):
python3 plugins/leyline/scripts/verify_plugin.py sanctum
Strict L3 verification:
python3 plugins/leyline/scripts/verify_plugin.py sanctum --level L3 --min-score 0.9
JSON output for CI:
python3 plugins/leyline/scripts/verify_plugin.py sanctum --json
Prerequisites
- The `gh` CLI must be installed and authenticated
- Use `--repo owner/repo` to specify a different repository
(default: athola/claude-night-market)
Notes
- All GitHub API calls are read-only; no write permissions
needed
- Assertion history comes from the 10 most recent completed
workflow runs
- The caution zone is between 70% and 100% of the
threshold (e.g., for 0.8 threshold, 0.56-0.79 is caution)
A plugin marketplace for Claude Code. Install only the plugins you need to run git workflows, code review, spec-driven development, and autonomous agents from inside your Claude Code session.
Other commands on claude-night-market.
- /aggregate-logs
Generate LEARNINGS.md from skill execution logs.
Open command - /analyze-skill
Analyze skill file complexity metrics and generate modularization recommendations for splitting or progressive loading.
Open command - /bulletproof-skill
Harden skills against rationalization and bypass behaviors
Open command - /context-report
Generate context optimization report for skill directories
Open command - /create-command
Create slash commands with brainstorming and best practices
Open command - /create-hook
Create hooks with brainstorming and security-first design
Open command

