Skill Vetting

Vet an agent skill before installing it — read the SKILL.md and any scripts for the red-flag patterns (credential access, obfuscation, exfiltration, prompt injection), audit its blast radius, and produce a risk-tiered verdict. Use when asked is this skill safe to install, vet this SKILL.md, review this skill from a marketplace, or check what this skill can do to my machine. Produces the risk classification with quoted evidence, the permission-surface audit, the red-flag checklist results, and an install/sandbox/reject recommendation.

majiayu000 a91316c 2 files · 7.4 KB Updated 567 repo stars

File contents

majiayu000/claude-skill-registry-data/tree/main/other/skill-vetting commit a91316c6aa

Frequently asked questions

npx skillmds add majiayu000/skill-vetting