Fixes a silent-fallback bug where subagents skipped the skill catalog entirely.
The bug
design-review and vulnerability-audit told the model to Read '.claude/skills/<name>/SKILL.md' — a bare relative path. Subagents run with cwd = target repo (not the plugin), so on every non-self review the path resolved to <audited-repo>/.claude/skills/… and missed. design-review visibly reported:
"No skill file exists in this repo; I'll apply the checklist from memory."
The whole /security-review catalog — the 52 skills the plugin ships — was being bypassed on every real audit, replaced by whatever the model remembered.
The fix
- Added
Skilltodesign-reviewandvulnerability-audittools:frontmatter. - Swapped file-read language for
Skill('<name>')invocations. Activates the actual skill guidance in-context; no path resolution, no dependence on cwd.
Impact
Every /security-review, /pr-review (deep-mode variant), and soundcheck-action run against a non-soundcheck repo previously bypassed the skill catalog. Upgrading restores the intended behavior. If your finding counts jump post-upgrade, that's why.
Compatibility
No schema or interface changes. If you are pinned to @v1 via soundcheck-action, the floating tag now points at v1.0.40 → v1.17.1.