skills/development/scripting/makefile/validator/SKILL.md
Comprehensive toolkit for validating, linting, and optimizing Makefiles. Use when working with Makefiles (Makefile, makefile, *.mk files), validating build configurations, checking for best practices, identifying security issues, or debugging Makefile problems. Concrete capabilities include detecting missing .PHONY declarations, validating tab indentation in recipes, checking variable expansion safety, identifying hardcoded credentials, and flagging missing prerequisites or syntax errors.
npx skillsauth add pantheon-org/tekhne makefile-validatorInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
-n --dry-run validation; catches errors with line numbers.DELETE_ON_ERROR, .PHONY declarations, $(MAKE) for recursive calls, .ONESHELL error handlingrm/sudo/curl/wget, command injection, .EXPORT_ALL_VARIABLES leakage.NOTPARALLEL, .INTERMEDIATE/.SECONDARY, VPATH usage, incremental build efficiencySee references/best-practices.md, references/common-mistakes.md, and references/bake-tool.md for detailed explanations.
# Validate a Makefile
bash scripts/validate_makefile.sh Makefile
========================================
MAKEFILE VALIDATOR
========================================
File: Makefile
[SYNTAX CHECK (GNU make)]
✓ No syntax errors found
[MBAKE VALIDATION]
✓ mbake validation passed
[MBAKE FORMAT CHECK]
⚠ Formatting issues found
Run 'mbake format Makefile' to fix formatting issues
Or run 'mbake format --diff Makefile' to preview changes
[CUSTOM CHECKS]
⚠ No .PHONY declarations found
✗ Potential spaces instead of tabs in recipes detected
ℹ No VPATH/vpath declarations found
========================================
VALIDATION SUMMARY
========================================
Errors: 1
Warnings: 2
Info: 1
⚠ Validation PASSED with warnings
bash scripts/validate_makefile.sh Makefile
# Preview changes
mbake format --diff Makefile
# Apply formatting
mbake format Makefile
# Re-validate
bash scripts/validate_makefile.sh Makefile
# 1. Validate current state
bash scripts/validate_makefile.sh legacy.mk
# 2. Fix critical errors (tabs, syntax), then apply formatting
mbake format legacy.mk
# 3. Add .PHONY declarations
mbake format --auto-insert-phony-declarations legacy.mk
# 4. Re-validate
bash scripts/validate_makefile.sh legacy.mk
# 5. Reference best-practices.md for modernization guidance
The validator automatically checks for hardcoded credentials, unsafe variable expansion in dangerous commands, and command injection vulnerabilities. Reference references/common-mistakes.md for detailed explanations and fixes.
For pre-commit hooks, CI/CD pipelines (e.g. GitHub Actions), and self-validating Makefile targets, use the validation script at scripts/validate_makefile.sh and match on files named Makefile, makefile, or *.mk. The script's exit codes (0/1/2) map cleanly to pass/warn/fail states for any automation context. See references/bake-tool.md for CI/CD configuration details.
make -n)minphony, phonydeclared rules)
go install github.com/checkmake/checkmake/cmd/checkmake@latest
mbake is automatically installed in an isolated venv per invocation and cleaned up on exit — no manual installation required.
makefile-validator/
├── skill.md # This file
├── scripts/
│ └── validate_makefile.sh # Main validation script
├── references/
│ ├── best-practices.md # Makefile best practices
│ ├── common-mistakes.md # Common Makefile mistakes
│ └── bake-tool.md # mbake tool reference (config, CI/CD, advanced features)
└── assets/
├── good-makefile.mk # Well-written example
└── bad-makefile.mk # Anti-patterns example
missing separator errors that are notoriously confusing.echo "building" (spaces instead of tab)\techo "building" (hard tab — \t)scripts/validate_makefile.sh catches this; run make -n to surface the error..PHONY for non-file targets.PHONY, if a file named clean or test exists, Make will silently skip the target because it considers it up-to-date.clean: with no .PHONY declaration.PHONY: clean test build all declared at the top$(shell ...) calls in recipe variables without quotingrm, sudo, or curl commands enables command injection when variable values contain spaces or special characters.rm -rf $(DIR) when DIR can be user-controlledrm -rf "$(DIR)" or validate that DIR does not contain path separatorsmake with a bare make commandmake in a recipe does not inherit the jobserver flags passed by the parent make, breaking parallel builds and potentially starting a separate build chain with different settings.make -C subdir$(MAKE) -C subdir.EXPORT_ALL_VARIABLES.env files) gets exported to every sub-process, creating credential leakage risk..EXPORT_ALL_VARIABLES: at top of Makefileexport VAR only for variables that need sub-process visibilitymbake doesn't recognize some valid GNU Make special targets (.DELETE_ON_ERROR, .SUFFIXES, .ONESHELL, .POSIX) — the validator filters these false positives and surfaces them as informational messages. The mbake format --check vs mbake format output may also differ; this is a known upstream issue. See references/bake-tool.md for full details including mbake configuration (~/.bake.toml) and format-disable comments.
Internal:
External:
.PHONY and rule declaration checkstools
A skill that produces warnings but no errors.
testing
A well-formed example skill for testing the validator.
development
A skill with code blocks and imperative instructions for testing content and contamination analysis.
tools