Skill Security Auditor
Scan and audit AI agent skills for security risks before installation. Performs static analysis on code files for dangerous patterns, scans markdown files for prompt injection, validates dependency supply chains, checks file system boundaries, and detects obfuscation. Produces a structured PASS / WARN / FAIL verdict with findings categorized by severity and actionable remediation guidance.
Keywords: skill security, AI security, prompt injection, code audit, supply chain, dependency scanning, data exfiltration, credential harvesting, obfuscation detection, pre-install security
Core Capabilities
- Code execution risk detection — command injection (
os.system, subprocess shell=True, backticks), eval/exec/compile, obfuscation (base64/hex/chr()), network exfiltration, credential harvesting (~/.ssh, ~/.aws), privilege escalation.
- Prompt injection detection — system-prompt overrides, role hijacking, safety bypass, hidden zero-width/HTML-comment instructions, data-extraction directives, excessive-permission requests.
- Supply chain analysis — known-vulnerable pins, typosquatting, unpinned versions, inline
pip/npm install, low-reputation packages.
- File system & structure validation — out-of-scope paths, hidden/credential files, unexpected binaries, escaping symlinks, oversized payloads.
- Verdict & reporting — PASS / WARN / FAIL with severity-categorized findings, remediation, and a strict mode for CI gates.
When to Use
- Evaluating a skill from an untrusted source before installation
- Pre-install security gate for CI/CD pipelines
- Auditing a skill directory or git repository for malicious code
- Reviewing skills before adding them to a team's approved list
- Post-incident scanning of installed skills
Clarify First
Before the audit, confirm these inputs. If any is unknown or vague, ASK — do not assume:
Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the artifact.
Tools
| Tool |
Purpose |
Command |
code_scanner.py |
Scan Python scripts for eval/exec, subprocess, network exfiltration, credential harvesting, obfuscation, unsafe imports |
python scripts/code_scanner.py <target> --strict --json |
prompt_injection_scanner.py |
Scan markdown/text for prompt-injection patterns and hidden directives |
python scripts/prompt_injection_scanner.py <target> --strict --json |
supply_chain_checker.py |
Check imports/requirements for typosquatting, unpinned versions, inline installs |
python scripts/supply_chain_checker.py <target> --strict --json |
All tools take a target (file or directory), and support --strict (any HIGH → FAIL) and --json.
References
Load the reference that matches the task — keep this file lean and pull detail on demand:
- references/threat-model-and-patterns.md — the attack-vector threat model, trust boundaries, full regex pattern sets for code-execution and prompt-injection detection, and known evasion techniques. Read when deciding what to scan for or tuning detection.
- references/audit-output-and-workflow.md — the report format, verdict criteria (incl. strict mode), CI/CD integration YAML, and the manual audit checklist. Read when producing or interpreting an audit.
- references/quality-and-best-practices.md — static-analysis limitations, common pitfalls, best practices, troubleshooting matrix, and success criteria. Read before shipping or relying on an audit.
Scope & Limitations
This skill covers:
- Static pattern-based detection of dangerous code constructs in Python, Bash, JavaScript, and TypeScript files
- Prompt injection scanning across all markdown files within a skill package
- Dependency supply chain validation for
requirements.txt and package.json
- File structure boundary checks including symlinks, binaries, hidden files, and oversized payloads
This skill does NOT cover:
- Runtime or dynamic analysis — code is never executed during the audit (see
skill-tester for runtime validation)
- Live CVE database lookups or real-time vulnerability feeds (see
dependency-auditor for active CVE scanning)
- Infrastructure-level security controls such as network segmentation, container hardening, or cloud IAM policies (see
infrastructure-compliance-auditor in ra-qm-team)
- Compliance framework certification against ISO 27001, SOC 2, GDPR, or other regulatory standards (see
information-security-manager-iso27001 and gdpr-dsgvo-expert in ra-qm-team)
Integration Points
| Skill |
Integration |
Data Flow |
dependency-auditor |
Feed audit findings into live CVE scanning for flagged dependencies |
Security audit report → dependency-auditor for real-time vulnerability lookup |
ci-cd-pipeline-builder |
Embed the audit workflow as a required check in generated CI/CD pipelines |
Pipeline template ← audit job YAML from this skill's CI/CD section |
skill-tester |
Run dynamic runtime tests on skills that pass static analysis |
PASS verdict from this skill → skill-tester for behavioral validation |
infrastructure-compliance-auditor |
Extend auditing scope from skill-level to infrastructure-level security controls |
Skill audit findings → infrastructure auditor for environment-wide posture review |
env-secrets-manager |
Cross-reference credential harvesting findings with secrets management policy |
Credential-access flags from audit → env-secrets-manager for policy verification |
pr-review-expert |
Surface audit findings as inline PR review comments on flagged lines |
Audit report line references → PR review annotations for developer visibility |
1---2name: skill-security-auditor3description: Security audit and vulnerability scanning for AI agent skills before install. Detects prompt injection, dangerous code, exfiltration, credential harvesting, and supply chain risks. Use when evaluating untrusted skills or gating installs.4license: MIT + Commons Clause5---6# Skill Security Auditor
7
8Scan and audit AI agent skills for security risks before installation. Performs static analysis on code files for dangerous patterns, scans markdown files for prompt injection, validates dependency supply chains, checks file system boundaries, and detects obfuscation. Produces a structured PASS / WARN / FAIL verdict with findings categorized by severity and actionable remediation guidance.
9
10**Keywords:** skill security, AI security, prompt injection, code audit, supply chain, dependency scanning, data exfiltration, credential harvesting, obfuscation detection, pre-install security
11
12## Core Capabilities
13
14- **Code execution risk detection** — command injection (`os.system`, `subprocess shell=True`, backticks), `eval`/`exec`/`compile`, obfuscation (base64/hex/`chr()`), network exfiltration, credential harvesting (`~/.ssh`, `~/.aws`), privilege escalation.
15- **Prompt injection detection** — system-prompt overrides, role hijacking, safety bypass, hidden zero-width/HTML-comment instructions, data-extraction directives, excessive-permission requests.
16- **Supply chain analysis** — known-vulnerable pins, typosquatting, unpinned versions, inline `pip`/`npm install`, low-reputation packages.
17- **File system & structure validation** — out-of-scope paths, hidden/credential files, unexpected binaries, escaping symlinks, oversized payloads.
18- **Verdict & reporting** — PASS / WARN / FAIL with severity-categorized findings, remediation, and a strict mode for CI gates.
19
20## When to Use
21
22- Evaluating a skill from an untrusted source before installation
23- Pre-install security gate for CI/CD pipelines
24- Auditing a skill directory or git repository for malicious code
25- Reviewing skills before adding them to a team's approved list
26- Post-incident scanning of installed skills
27
28## Clarify First
29
30Before the audit, confirm these inputs. If any is unknown or vague, ASK — do not assume:
31
32- [ ] **Target path** — the skill file or directory to scan (the subject of every scanner)
33- [ ] **Scan dimensions** — code execution / prompt injection / supply chain (selects which of the three scanners run)
34- [ ] **Strict mode / gate threshold** — whether any HIGH finding forces FAIL (CI gate vs advisory report changes the verdict)
35
36Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the artifact.
37
38## Tools
39
40| Tool | Purpose | Command |
41|------|---------|---------|
42| `code_scanner.py` | Scan Python scripts for eval/exec, subprocess, network exfiltration, credential harvesting, obfuscation, unsafe imports | `python scripts/code_scanner.py <target> --strict --json` |
43| `prompt_injection_scanner.py` | Scan markdown/text for prompt-injection patterns and hidden directives | `python scripts/prompt_injection_scanner.py <target> --strict --json` |
44| `supply_chain_checker.py` | Check imports/requirements for typosquatting, unpinned versions, inline installs | `python scripts/supply_chain_checker.py <target> --strict --json` |
45
46All tools take a `target` (file or directory), and support `--strict` (any HIGH → FAIL) and `--json`.
47
48## References
49
50Load the reference that matches the task — keep this file lean and pull detail on demand:
51
52- **[references/threat-model-and-patterns.md](references/threat-model-and-patterns.md)** — the attack-vector threat model, trust boundaries, full regex pattern sets for code-execution and prompt-injection detection, and known evasion techniques. Read when deciding what to scan for or tuning detection.
53- **[references/audit-output-and-workflow.md](references/audit-output-and-workflow.md)** — the report format, verdict criteria (incl. strict mode), CI/CD integration YAML, and the manual audit checklist. Read when producing or interpreting an audit.
54- **[references/quality-and-best-practices.md](references/quality-and-best-practices.md)** — static-analysis limitations, common pitfalls, best practices, troubleshooting matrix, and success criteria. Read before shipping or relying on an audit.
55
56## Scope & Limitations
57
58**This skill covers:**
59- Static pattern-based detection of dangerous code constructs in Python, Bash, JavaScript, and TypeScript files
60- Prompt injection scanning across all markdown files within a skill package
61- Dependency supply chain validation for `requirements.txt` and `package.json`
62- File structure boundary checks including symlinks, binaries, hidden files, and oversized payloads
63
64**This skill does NOT cover:**
65- Runtime or dynamic analysis — code is never executed during the audit (see `skill-tester` for runtime validation)
66- Live CVE database lookups or real-time vulnerability feeds (see `dependency-auditor` for active CVE scanning)
67- Infrastructure-level security controls such as network segmentation, container hardening, or cloud IAM policies (see `infrastructure-compliance-auditor` in ra-qm-team)
68- Compliance framework certification against ISO 27001, SOC 2, GDPR, or other regulatory standards (see `information-security-manager-iso27001` and `gdpr-dsgvo-expert` in ra-qm-team)
69
70## Integration Points
71
72| Skill | Integration | Data Flow |
73|-------|-------------|-----------|
74| `dependency-auditor` | Feed audit findings into live CVE scanning for flagged dependencies | Security audit report → dependency-auditor for real-time vulnerability lookup |
75| `ci-cd-pipeline-builder` | Embed the audit workflow as a required check in generated CI/CD pipelines | Pipeline template ← audit job YAML from this skill's CI/CD section |
76| `skill-tester` | Run dynamic runtime tests on skills that pass static analysis | PASS verdict from this skill → skill-tester for behavioral validation |
77| `infrastructure-compliance-auditor` | Extend auditing scope from skill-level to infrastructure-level security controls | Skill audit findings → infrastructure auditor for environment-wide posture review |
78| `env-secrets-manager` | Cross-reference credential harvesting findings with secrets management policy | Credential-access flags from audit → env-secrets-manager for policy verification |
79| `pr-review-expert` | Surface audit findings as inline PR review comments on flagged lines | Audit report line references → PR review annotations for developer visibility |