Loading...
Loading...
Use this skill when the user wants to audit Agent Skills, SKILL.md files, imported skills, prompts, tools, scripts, or skill repositories for safety, prompt injection risk, secret leakage, unsafe commands, unclear permissions, untrusted external references, or repo policy violations. Trigger phrases include "audit this skill," "skill security," "review imported skills," "prompt injection risk," "unsafe skill," "scan skills," and "security audit for skills."
npx skill4agent add scayver/marketing-skills skill-security-auditor.marketing-os/product-context.md| Area | What To Check |
|---|---|
| Frontmatter | Valid YAML, accurate name, specific description |
| Activation | Clear trigger scope and no broad hijacking |
| Instruction safety | No role override, exfiltration request, or policy bypass |
| File access | No unnecessary private path reads |
| Command usage | No destructive or broad shell commands without safeguards |
| Network behavior | No untrusted downloads or silent external calls |
| Secrets | No tokens, keys, passwords, private URLs, or credential examples |
| Dependencies | No unexplained scripts, binaries, or package installs |
| Data handling | No sensitive data retention instructions |
| Brand and repo fit | Matches local naming, routing, and content standards |
| Severity | Meaning | Action |
|---|---|---|
| Critical | Exfiltrates secrets, disables safety, or runs destructive commands | Block import |
| High | Encourages unsafe automation, broad file reads, or risky network calls | Rewrite before import |
| Medium | Poor scoping, unclear permissions, stale links, weak compliance | Fix before publish |
| Low | Style, naming, minor clarity, missing examples | Clean up during normalization |
skills/<name>/SKILL.md## Mandatory Content Standards| Skill | Severity | Finding | Evidence | Risk | Recommended Fix | Status |
|---|