publicity-review skillA
publicity-review is agent-read markdown (skill) from hiroro-work/claude-plugins: Review uncommitted diff for content unsuitable for publication to a public repository — secrets/credentials, user-specific absolute paths, internal-only URLs/hostnames, and personal identifiers. Each iteration dispatches a fresh subagent that returns findings and the main thread applies the subagent's mechanical fixes — a single pass by default, or re-dispatching up to `Max iterations` when the caller raises it. Non-interactive — no user prompts. Use as a final gate before publishing changes; de.
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# Publicity Review The convergence signal is the executor itself returning `findings: []` AND `suggested_edits: []` on a pass verdict. By default the skill runs a **single** pass; a caller that raises `Max iterations` loops until that signal, max iterations is reached, a divergence is detected, or a safety rail trips. The detection scope is narrow on purpose: secrets, user-specific absolute paths (e.g. `/Users/<name>/...`), internal-only URLs / hostnames, personal identifiers, and obvious proprietary internal info. It is **not** a generic linter — license, brand, or stylistic content is out of scope. It never prompts the user. ## Invocation contract The caller passes these fields in natural language (the skill extracts them from the invocation text): - `Base ref` *(optional, default `HEAD`)* — git ref to diff against - `Max iterations` *(optional, default `1`)* — upper bound on the refinement loop. Default `1` is a single detect-and-apply pass — a caller that wants the applied fixes re-verified raises it explicitly …
Read the whole file at its exact version.
How to install
mdr add hiroro-work/claude-plugins/publicity-review@git:20260819.bbea1b2mdr add hiroro-work/claude-plugins/publicity-review@sha256:2bc8a43fceee24d6Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
[](https://markdownregistry.com/a/art_342ivfgtxe7l3ro5)
1 badge views in 30 days
Versions
| version | committed | commit | size | audit | |
|---|---|---|---|---|---|
| git:20260819.bbea1b2 latest | 2026-08-19 | bbea1b2 | 23,068 B | A | view · diff |
| git:20260818.c661bc3 | 2026-08-18 | c661bc3 | 22,710 B | A | view · diff |
| git:20260801.4832566 | 2026-08-01 | 4832566 | 27,243 B | A | view · diff |
| git:20260710.15f09b2 | 2026-07-10 | 15f09b2 | 24,566 B | A | view · diff |
| git:20260612.47840e7 | 2026-06-12 | 47840e7 | 24,390 B | A | view |
Audit of the latest version
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (23068 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No instruction to read or print local credentials
- pass: No base64 blob over 200 characters
- pass: No link to a raw IP address
- pass: No script tag
Source
hiroro-work/claude-plugins · 48 stars · license none · pushed 2026-09-23 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_342ivfgtxe7l3ro5 GET https://markdownregistry.com/api/v1/resolve?ref=hiroro-work/claude-plugins/publicity-review GET https://markdownregistry.com/api/v1/blob/2bc8a43fceee24d67c9d2600fbeed836d2036e2183d93825bff46c447a647808
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.