skill-supply-chain-audit
SolidAudit agent skills, plugins, prompts, manifests, scripts, dependencies, and bundled assets for provenance, prompt-injection, permission, execution, exfiltration, persistence, and update risk. Use when evaluating a third-party skill before installing, enabling, updating, publishing, or distributing it; reviewing an untrusted SKILL.md, agent configuration, MCP integration, archive, or repository; comparing a package with a known-good version; or investigating unexpected tool, network, credential, or filesystem behavior.
Install
Quality Score: 82/100
Skill Content
Details
- Author
- seb1n
- Repository
- seb1n/awesome-ai-agent-skills
- Created
- 7 months ago
- Last Updated
- 1 months ago
- Language
- Python
- License
- MIT
Integrates with
Similar Skills
Semantically similar based on skill content — not just same category
skill-security-review
Audit third-party Agent Skills/extensions for supply-chain security without running them before install/trust. Inspect scripts, hooks, MCP/plugins, hidden instructions, symlinks, credential/network flows, and provenance/licenses.
skill-security-audit
Gate before adopting any external agent skill, plugin, hook, script, installer, or MCP package: provenance and license review, deterministic static triage (scripts/audit_skill.py), optional NVIDIA SkillSpector scan, and manual review for prompt injection, credential access, exfiltration, and destructive commands. Fails closed on unresolved HIGH/CRITICAL findings or incomplete scans; scanning is a control, not proof of safety.
skill-auditor
Audit an Agent Skill or a repository of skills for trigger quality, scope overlap, instruction conflicts, progressive-disclosure cost, broken references/dependencies, eval blind spots, false-green paths, semantic-version and public-contract compatibility, host-support overclaims, package hygiene, supply-chain risks, migration/deprecation gaps, and drift between registry, docs, tests, and shipped archives. Use when the user asks to audit, review, roast, harden, compare, or quality-check a skill or skill library itself. Do not use to create/edit the skill (use skill-creator), to empirically benchmark model behavior with-vs-without it (use skill-evaluator), to audit ordinary software (use repo-roaster), or to issue a production release verdict.