verify-bundle-sync skillA
verify-bundle-sync is agent-read markdown (skill) from hiroro-work/claude-plugins: Verify the dev-workflow-bundle canonical and bundle copy directories are in sync. Workaround for upstream symlink bug; delete this skill and its callers when symlinks are restored..
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# Verify Bundle Sync This skill exists solely to work around an upstream Claude Code symlink bug ([anthropics/claude-code#53948](https://github.com/anthropics/claude-code/issues/53948)) that requires `plugins/dev-workflow-bundle/skills/<name>/` to be a real directory copy of `skills/<name>/` rather than a symlink. It is a **project-local** skill (lives under `.claude/skills/verify-bundle-sync/`, not registered in `.claude-plugin/marketplace.json`). When the bug is fixed and the bundle layout returns to symlinks, **delete this skill directory, the `.claude/dev-workflow.md` `test_commands` entry, the `dev-workflow-triage` (f.5) sub-step, and the `.claude/rules/project.rules.md` bullet** that document this workaround. The skill compares each bundle member's canonical directory against its bundle copy and reports drift. It is detect-only — it never modifies any files. ## Process Accepts an optional `--base-commit <sha>` argument (ignored — the scope is structural, not changeset-dependent). Running with no arguments behaves identically. …
Read the whole file at its exact version.
How to install
mdr add hiroro-work/claude-plugins/verify-bundle-sync@git:20260923.b852b0bmdr add hiroro-work/claude-plugins/verify-bundle-sync@sha256:ad9382a35e743ff1Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
[](https://markdownregistry.com/a/art_5nxspevgep3anpha)
1 badge views in 30 days
Versions
| version | committed | commit | size | audit | |
|---|---|---|---|---|---|
| git:20260923.b852b0b latest | 2026-09-23 | b852b0b | 6,158 B | A | view · diff |
| git:20260908.2f8ee93 | 2026-09-08 | 2f8ee93 | 6,141 B | A | view · diff |
| git:20260905.c5a474e | 2026-09-05 | c5a474e | 6,127 B | A | view · diff |
| git:20260902.b999a01 | 2026-09-02 | b999a01 | 6,115 B | A | view · diff |
| git:20260719.b5bfe15 | 2026-07-19 | b5bfe15 | 6,227 B | A | view |
Audit of the latest version
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (6158 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No instruction to read or print local credentials
- pass: No base64 blob over 200 characters
- pass: No link to a raw IP address
- pass: No script tag
Source
hiroro-work/claude-plugins · 48 stars · license none · pushed 2026-09-23 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_5nxspevgep3anpha GET https://markdownregistry.com/api/v1/resolve?ref=hiroro-work/claude-plugins/verify-bundle-sync GET https://markdownregistry.com/api/v1/blob/ad9382a35e743ff156cc14e0db3ed1c9bef864305b36cf8a302b6d2021a5165a
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.