Skill Supply Chain Audit · seb1n/awesome-ai-agent-skills

Audit a third-party skill for risks before installing

Reviews an untrusted skill's manifest, scripts, and dependencies for prompt-injection, permission, exfiltration, and persistence risks, then returns a disposition with evidence-backed findings and a verification plan. Useful before installing, enabling, or publishing a third-party skill.

Good for

  • Check a third-party skill's manifest for suspicious permissions
  • Scan bundled scripts for prompt-injection or exfiltration risks
  • Get an approve, quarantine, or reject decision before install
Category
Coding

Open-source skills are maintained by their authors and listed as published, with attribution. Results depend on how well the skill fits your task and material.

A good place to start

Audit this third-party skill archive for prompt-injection and exfiltration risks before I install it, and give me a disposition.

Make your next great thing.

Bring a question, a file, or an idea that’s not quite there yet.