Skill Audit

Security-scans third-party agent skills before you trust them. A SKILL.md is executable authority — agents follow it with your credentials and filesystem. Detects prompt-injection patterns (instruction overrides, concealment directives), data-exfiltration signatures (sensitive paths + network sends), and dangerous script patterns (pipe-to-shell, eval-on-download) in any skills directory. Offline, deterministic, stdlib-only.

trac3r00 bdbcb8d 2 files · 7.6 KB Updated

File contents

trac3r00/agent-skills/tree/main/skills/skill-audit commit bdbcb8de8c

Frequently asked questions

npx skillmds@latest add trac3r00/skill-audit