Lesson 26 / 26

Revision: Cheat Sheet and Self-Check

Review the key ideas of the whole course.

Cheat sheet

What: a skill = folder + SKILL.md (YAML frontmatter name + description, then Markdown instructions) + optional scripts, references, templates; progressive disclosure: descriptions always loaded, body when relevant, extra files/scripts only when needed. Vs others: CLAUDE.md = always-on facts; skill = on-demand procedure; slash command = prompt you trigger; subagent = separate context; MCP = external tools; hook = deterministic enforcement. Write: one job per skill; lowercase-hyphen name matching the folder (<= 64 chars); description <= 1024 chars saying what, when, and trigger phrases; body with steps, outputs, verification, gotchas; < 500 lines, details in references/. Files: reference each file by relative path and say when to read it; scripts for exact work (clear args, concise JSON, exit codes, helpful errors); allowed-tools as narrow as possible. Use: personal `/.claude/skills, project .claude/skills` (git), plugins; chosen automatically by description or invoked by name/slash; share and version like code, update with the process. Test: should / should-not prompts, script fixtures, read transcripts, change one thing at a time. Security: scripts run with your permissions, so review third-party skills fully, pin versions, prefer sandboxes, no secrets in files, treat fetched content as data, confirm before destructive actions; scanning never replaces reading. Patterns: review checklists with cited evidence, "look at it" verification loops, templates and workflows with approval gates; avoid vague descriptions, giant bodies and rules that need a hook. Details of Claude Code evolve, so check the official documentation.

Quick check: Your skill never triggers. You have already checked the folder name and frontmatter. What next?

  • Rewrite the description with what, when and the exact phrases users say, then test with real prompts
  • Make the body longer
  • Delete the skill
  • Rename the folder randomly
Answer

Rewrite the description with what, when and the exact phrases users say, then test with real prompts — Selection depends mainly on the description.

Quick check: You are asked to install a public skill whose setup says to run a downloaded script piped into bash. What do you do?

  • Paste your tokens into it
  • Run it immediately
  • Pre-approve all Bash tools
  • Refuse or inspect the script fully first; run unfamiliar code only in a sandbox without credentials
Answer

Refuse or inspect the script fully first; run unfamiliar code only in a sandbox without credentials — Download-and-execute with your permissions is a classic compromise route.

Quick check: Which content belongs in CLAUDE.md rather than in a skill?

  • A rarely used 20-step deployment procedure
  • Facts and rules needed in every session, such as the test command and conventions
  • A large API reference
  • A one-off migration script
Answer

Facts and rules needed in every session, such as the test command and conventions — Always-needed context goes in memory; on-demand procedures go in skills.