skill-auditor

Audit AI skills for security vulnerabilities and quality issues before installation.

Updated Jun 25, 2026
One-click install
npx skills add https://github.com/z1439527767/claude-config --skill skill-auditor-z1439527767
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: skill-auditor
Source: https://github.com/z1439527767/claude-config/tree/main/skills/imported/skill-auditor
Command: npx skills add https://github.com/z1439527767/claude-config --skill skill-auditor-z1439527767

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps prevent unsafe or low-quality AI skill installations by systematically reviewing third-party skills for security issues, quality problems, and compatibility risks before activation.

Core Features & Use Cases

  • Security Quality Scan: Performs a 10-point review covering prompt injection, dangerous commands, data exfiltration risks, obfuscated code, and dependency concerns.
  • Skill Evaluation: Scores skills based on quality checks and provides installation guidance for trusted, cautionary, risky, or blocked skills.
  • Use Case: When reviewing a new marketplace skill, use this Skill to determine whether it is safe to install and whether it overlaps with existing capabilities.

Quick Start

Ask the skill auditor to review a third-party skill before installing it.

Frequently Asked Questions about skill-auditor

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit a third-party AI skill for security vulnerabilities before installation?

To audit a third-party AI skill for security vulnerabilities, you can perform a 10-point review covering prompt injection, dangerous commands, data exfiltration risks, obfuscated code, and dependency trust to determine if it is safe to install.

What is the best way to check for prompt injection risks in marketplace skills?

The best way to check for prompt injection risks in marketplace skills is to run a systematic security quality scan that evaluates metadata, command risks, and dependency trust before activation to provide installation guidance.

How do I evaluate duplicate capabilities when discovering new skills in a directory?

To evaluate duplicate capabilities when discovering new skills in a directory, you can review the skill against your existing stack to detect overlapping functionalities and determine whether installation is necessary.

Does the skill audit process check for dependency risks and data exfiltration?

Yes, the skill audit process checks for dependency risks and data exfiltration as part of a comprehensive 10-point review that scores skills based on quality checks to provide installation guidance.

What are the limitations of automated skill quality reviews for newly detected skills?

Automated skill quality reviews for newly detected skills evaluate prompt safety, command risks, and dependency trust, but require validation of skill metadata to accurately score trusted, cautionary, risky, or blocked installation statuses.