Skill Vetting

Vet a third-party skill, plugin, hook, or instruction file for trojan patterns before it runs. Load BEFORE adding or trusting untrusted skill content - a `git clone` into a skills directory, a `/plugin marketplace add`, a dropped-in SKILL.md, a shared "install this skill / agent config" link or repo - or when a session-start advisory flags an unvetted or changed skill. NOT for trusted first-party content you authored, for code-correctness (use the code-review tooling), or for general dependency/supply-chain risk (security-architect). The doctrine this enforces lives in operational-rigor §2; this skill only drives it.

F-e-u-e-r 6808e89 2 files · 27.5 KB Updated

File contents

F-e-u-e-r/opus-pack/tree/main/skills/skill-vetting commit 6808e89318

Frequently asked questions

npx skillmds@latest add f-e-u-e-r/skill-vetting