Skill Security Audit

Gate before adopting any external agent skill, plugin, hook, script, installer, or MCP package: provenance and license review, deterministic static triage (scripts/audit_skill.py), optional NVIDIA SkillSpector scan, and manual review for prompt injection, credential access, exfiltration, and destructive commands. Fails closed on unresolved HIGH/CRITICAL findings or incomplete scans; scanning is a control, not proof of safety.

AL-JANEF Updated

File contents

AL-JANEF/janef-forge/tree/main/skills/security/skill-security-audit commit 85236196e3

Frequently asked questions

npx skillmds@latest add al-janef/skill-security-audit