What problem does it solve?
This Skill prevents unsafe or unauthorized community skills from being installed without source review, structural trust checks, license validation, quality analysis, and explicit user approval.
Core Features & Use Cases
- Allowlist Enforcement: Checks registries, publishers, MCP connectors, and licenses before fetching or installing a skill.
- Security Review: Displays the complete raw SKILL.md and identifies prompt injection, unusual content, network calls, elevated tools, hooks, and risky file-write paths.
- Controlled Installation: Runs skills-qa, applies role-aware routing and freshness validation, records an auditable install log, and installs only after a fresh approval.
- Use Case: A legal team can evaluate a community skill from a watched registry, inspect every requested capability, verify its license and freshness metadata, and install it only when the configured controls permit it.
Quick Start
Use the skill-installer to review and safely install the requested community skill from its registry.