Vetting Skills Before Install

Vet an agent skill or MCP server before you install it, and reach a clear verdict: install, install with constraints, or deny. Combines an instruction-text audit, a declared-versus-used permission diff, and a bundled-code inspection for secret exfiltration (harvesting environment variables, credential files, or dotfiles and sending them out) and for obfuscation and install-time supply-chain risk (decode-then-execute, download-and-run on install, unpinned fetches). Pin the exact artifact you vet, audit each surface, and record the reason for the verdict. Use whenever adding a third-party skill, server, or marketplace entry to an agent. The verdict plus its evidence is the finding.

UnboundCompute Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/vetting-skills-before-install commit 22d27afc50

Frequently asked questions

npx skillmds@latest add unboundcompute/vetting-skills-before-install