What problem does it solve? Agent skills are unvetted instructions and files that an AI follows with your permissions, and nothing checks them before they run. This Skill inspects a skill or skill pack before you install it, surfacing hidden directives, data exfiltration, and dangerous scripts that a casual read would miss. ## Core Features & Use Cases - Full-file inventory and review: Reads every file in the target, including scripts, test files, dotfiles, and bundled references, not just SKILL.md. - Nine-category threat model: Checks data exfiltration, unknown network destinations, confirmation bypass, prompt injection, hidden or obfuscated content, risky scripts, supply-chain risk, scope overreach, and misleading intent, with an optional Python static scan for invisible Unicode payloads. - Severity-rated verdict report: Produces a PASS, PASS WITH CAUTIONS, or FAIL verdict with cited findings, defence-in-depth guidance, and a recommended next action (install, fix and re-audit, or delete and blocklist the source). - Use Case: Someone sends you a .skill file or a GitHub repo of skills. Run this audit to get a per-skill verdict and a roll-up verdict for the pack before anything touches your machine. ## Quick Start Audit the skill pack in this folder and tell me whether it is safe to install.