Ww Skill Auditor

Audit any agent skill, plugin, hook, or external Markdown instruction file before installing or trusting it. Fetches the SKILL.md from GitHub (or accepts a local path or URL), runs deterministic pattern scans for prompt injection, credential exfiltration, dangerous shell commands, hook installation, and supply-chain code execution, then runs a cheap-model semantic check. Returns SAFE / CAUTION / UNSAFE / UNKNOWN with specific findings. Use this skill whenever you or another skill is about to install a third-party skill, when evaluating an unknown component from `npx skills add`, when reviewing a SKILL.md from an external source, when a marketplace or repo is being added, or any time you say “audit this skill,” “is this safe to install,” “/ww-skill-auditor,” “check this skill before installing,” or point to an external skill, plugin, or hook to evaluate.

lee-fuhr Updated

File contents

lee-fuhr/claude-operator-skills/tree/main/skills/ww-skill-auditor commit 92a0612082

Frequently asked questions

npx skillmds@latest add lee-fuhr/ww-skill-auditor