Sota Skill Security

Security for AI agent skills, plugins and instruction bundles (2026) — the supply chain of things that tell an agent what to do. Use when installing, authoring, reviewing, updating or auditing any skill, plugin, ruleset or agent file an agent loads as instructions, including your own; when a repository you do not fully trust contains agent-readable instruction files; and when deciding what an installed skill may reach. Covers provenance and pinning, review-before-install, the instruction trust boundary, precedence and shadowing between overlapping skills, capability minimisation, revocation, and auditing a skill for guidance that is confidently wrong. Not for prompt injection arriving in ordinary application data — use sota-code-security rules/08. Trigger keywords: skill, agent skill, SKILL.md, AGENTS.md, CLAUDE.md, .cursorrules, instruction file, plugin, marketplace, skill install, skill provenance, skill pinning, malicious skill, skill shadowing, agent trust boundary.

martinholovsky b51307f 4 files · 26.7 KB Updated

File contents

martinholovsky/SOTA-skills/tree/main/skills/sota-skill-security commit b51307fda0

Frequently asked questions

npx skillmds@latest add martinholovsky/sota-skill-security