Statically audits Agent Skills for dangerous code, prompt injection, exfiltration, privilege escalation, and supply-chain risk before you install them, returning a PASS/WARN/FAIL verdict.
---
name: skill-security-auditor
description: Security gate that statically scans an Agent Skill (local dir or git repo) for malicious code before installation - command injection, eval/exec, network exfiltration, credential harvesting, prompt injection in SKILL.md, and dependency risk. Use before installing any skill from an untrusted source.
---
# Skill Security Auditor
Produces a clear PASS / WARN / FAIL verdict with findings and remediation for an AI agent skill, using static analysis only (it never executes the code).
## How to use
1. Run `python3 scripts/skill_security_auditor.py /path/to/skill/` on a local directory, or pass a git URL with `--skill <name>`.
2. It scans `.py/.sh/.js/.ts` for code-execution and exfiltration patterns (`os.system`, `eval`, `subprocess(shell=True)`, `requests.post`, reads of `~/.ssh`/`~/.aws`), plus base64/hex obfuscation and privilege escalation.
3. It scans SKILL.md and reference `.md` files for prompt injection ("ignore previous instructions", role hijacking, safety bypass, hidden zero-width text).
4. It checks `requirements.txt`/`package.json` for typosquatting, unpinned versions, and inline installs; flags binaries, symlinks, and out-of-boundary file access.
5. Read the severity-grouped report; use `--strict` (WARN becomes FAIL) and `--json` for CI gating.
When in doubt after an audit, don't install.
Full skill & source: https://github.com/alirezarezvani/claude-skills/tree/4a3c05b69e64f4925f7fc65c88890f614f79caf0/engineering/skills/skill-security-auditor