skill-supply-chain-audit

Solid

Audit agent skills, plugins, prompts, manifests, scripts, dependencies, and bundled assets for provenance, prompt-injection, permission, execution, exfiltration, persistence, and update risk. Use when evaluating a third-party skill before installing, enabling, updating, publishing, or distributing it; reviewing an untrusted SKILL.md, agent configuration, MCP integration, archive, or repository; comparing a package with a known-good version; or investigating unexpected tool, network, credential, or filesystem behavior.

AI & Automation 193 stars 37 forks Updated 1 months ago MIT

Install

View on GitHub

Quality Score: 82/100

Stars 20%
76
Recency 20%
75
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# Skill Supply Chain Audit Treat the target as untrusted. Produce an evidence-backed disposition without executing package code by default. ## Inputs Collect or state: - Target path, archive, repository snapshot, or exact version/commit. - Claimed purpose, publisher, source URL, license, and expected capabilities. - Intended runtime, available tools, requested permissions, and data sensitivity. - Known-good baseline or prior version when this is an update. - User constraints for network access, sandboxing, and dynamic testing. If provenance or version is unknown, record it as unknown; do not infer trust from popularity. ## Output contract Return: 1. Scope, target hash/version, provenance, method, and audit limitations. 2. A disposition: `approve`, `approve-with-constraints`, `quarantine`, or `reject`. 3. A behavior inventory covering instructions, executables, dependencies, endpoints, credentials, filesystem reach, and persistence. 4. Findings with stable IDs, severity, confidence, exact evidence, exploit preconditions, impact, and remediation. 5. Required permission constraints and a verification plan. 6. Residual risks and unanswered questions. Label each claim `observed`, `inferred`, or `unknown`. A clean heuristic scan is not proof of safety. ## Workflow ### 1. Establish a safe inspection boundary - Work read-only on a copy or immutable snapshot. - Do not import modules, run setup hooks, install dependencies, render active content, open embedded links, or invo...

Details

Author
seb1n
Repository
seb1n/awesome-ai-agent-skills
Created
7 months ago
Last Updated
1 months ago
Language
Python
License
MIT

Integrates with

Similar Skills

Semantically similar based on skill content — not just same category

AI & Automation Listed

skill-security-review

Audit third-party Agent Skills/extensions for supply-chain security without running them before install/trust. Inspect scripts, hooks, MCP/plugins, hidden instructions, symlinks, credential/network flows, and provenance/licenses.

9 Updated today
fmind
AI & Automation Listed

skill-security-audit

Gate before adopting any external agent skill, plugin, hook, script, installer, or MCP package: provenance and license review, deterministic static triage (scripts/audit_skill.py), optional NVIDIA SkillSpector scan, and manual review for prompt injection, credential access, exfiltration, and destructive commands. Fails closed on unresolved HIGH/CRITICAL findings or incomplete scans; scanning is a control, not proof of safety.

1 Updated 6 days ago
AL-JANEF
AI & Automation Listed

skill-auditor

Audit an Agent Skill or a repository of skills for trigger quality, scope overlap, instruction conflicts, progressive-disclosure cost, broken references/dependencies, eval blind spots, false-green paths, semantic-version and public-contract compatibility, host-support overclaims, package hygiene, supply-chain risks, migration/deprecation gaps, and drift between registry, docs, tests, and shipped archives. Use when the user asks to audit, review, roast, harden, compare, or quality-check a skill or skill library itself. Do not use to create/edit the skill (use skill-creator), to empirically benchmark model behavior with-vs-without it (use skill-evaluator), to audit ordinary software (use repo-roaster), or to issue a production release verdict.

1 Updated today
CometWeb-io