Vetting Agent Extensions

Decide whether an agent skill, plugin, or MCP server is safe to install into an AI coding agent, where its content is loaded into a model's context and its config can run on startup. Use when reviewing a skill pack, Claude Code / Cursor / Cline plugin, or MCP server before adoption; when a repo ships a SKILL.md, .mcp.json, or plugin.json you are about to trust; or when judging whether third-party agent content can steer the model or exfiltrate an engagement.

trilwu fce6e34 12.6 KB Updated

File contents

trilwu/secskills/tree/main/secskills-core/skills/vetting-agent-extensions commit fce6e34e52

Frequently asked questions

npx skillmds add trilwu/vetting-agent-extensions