Audit an AI agent skill for security risks before installing or trusting it. Runs a deterministic scanner (regex patterns, Python AST analysis, source-to-sink taint tracking, and YARA signatures) and then reasons about intent — catching prompt injection, credential exfiltration, persistence, memory poisoning, malicious code, supply-chain risks, and description-vs-behavior mismatch. Make sure to use this skill whenever the user wants to scan, audit, vet, review, or check the safety of a skill, plugin, SKILL.md, or agent tool — whether it is a local folder, a zip/.skill file, or a cloned repo — and whenever someone asks "is this skill safe to install?".
Inicia sesión para votar.
New here? These commands run inside Claude Code, Anthropic's terminal-based coding assistant — not your regular shell. Open a terminal, type claude to start a session, then paste the two lines below inside it.
npx skills add superagent-ai/skills --skill "skill-security" -a claude-code -g -yPaste into a Claude Code session. This only adds/installs the plugin — nothing runs automatically.
O, si ya vinculaste skillcat-sync, envíalo directamente — te pedirá confirmar antes de tocar nada.
This listing is sourced from superagent-ai/skills. The security badge above comes from a third-party audit (skills.sh) — we haven't independently executed or reviewed this code ourselves. Review the source before installing.
¿Eres el autor y quieres corregir algo de este listado, o pedir que lo quitemos? Escribe a autores@skillcat.es.