skill-security-review

Installation
SKILL.md

Skill Security Review

A skill is a prompt injector with file access by definition: once installed, its SKILL.md text runs with full agent trust, and its scripts run with your permissions. Never trust the registry description. Audit the actual content.

Scope — audit EVERY file, not just SKILL.md

Fetch the full tree first (gh api repos/OWNER/REPO/git/trees/REF?recursive=1 or the release archive). Audit each file by class:

  1. SKILL.md — injection & truthfulness
  2. scripts/*, *.sh, *.ps1, *.js — code: exfiltration & destruction
  3. references/*, assets/*, templates — embedded injection & sneaky config
  4. agents/*.yaml, plugin manifests — hidden tool grants, auto-invocation
  5. Install hooks, postinstall, Makefiles — supply-chain actions

Detection checklist

Exfiltration (the priority)

Installs
1
GitHub Stars
11
First Seen
Sep 6, 2026
skill-security-review — klh/speedy-claude