Skills Registry Security

Checks the third-party security audit status of a skill published to a skills registry (skills.sh) across every cached surface, decides whether a failing finding is real or points at content already removed, and drives a stale badge to green unattended. Runs a real install to capture what users see, reads the per-provider finding codes the JSON API omits, and greps each flagged literal against the repository and shipped tree; emits a next-action verdict, checks whether an install can even fire the re-index beacon in this environment, and watches on a durable schedule until the registry's own re-audit clears a stale finding. Use when a published skill shows a FAIL or CRITICAL audit, when an audit looks stale or predates a fix, when a registry badge disagrees with a merged change, when deciding whether to request a re-index, before or after publishing a flagged skill, or when a Snyk, Socket, or Gen Agent Trust Hub verdict needs to be explained or disputed — so no one has to babysit a rescan by hand.

starslingdev 2fd0bd2 9 files · 132.3 KB Updated

File contents

starslingdev/skills/tree/main/maintainers/skills-registry-security commit 2fd0bd24c7

Frequently asked questions

npx skillmds@latest add starslingdev/skills-registry-security