Skill Auditor

Security auditor for agent skills. Run before installing any new skill from skills.sh, GitHub, or any source. 6-step vetting protocol covering typosquatting, permissions, dependencies, prompt injection, network exfiltration, and content red flags. Use when about to install a skill, reviewing a SKILL.md, auditing existing skills, or when a skill update changes permissions. Triggers on "install skill", "add skill", "npx skills add", "vet this skill", "audit skill", or "is this skill safe." Based on useai-pro/openclaw-skills-security. MUST be invoked before any skill installation — this is part of the quality gate.

kevin-liu-01 Updated

File contents

kevin-liu-01/agent-machines/tree/main/knowledge/skills/skill-auditor commit 035ad3d211

Frequently asked questions

npx skillmds@latest add kevin-liu-01/skill-auditor