Skill Auditor
Look for these red flags:
| Category | Patterns |
|---|---|
| Credential access | ~/.ssh, ~/.aws, .env, id_rsa |
| Execution | eval, exec, os.system, subprocess |
| Exfiltration | curl or fetch to an unknown host |
The classic injection string is "ignore all previous instructions" — treat any skill containing it as suspect until explained.