skill-security-auditor

Installation
SKILL.md

Skill Security Auditor

Static analysis for AI agent skills. Run it on any skill from outside your own trust boundary before letting an agent execute its scripts. The auditor walks the entire skill directory and emits findings across ten threat categories, then collapses them into a single verdict that CI can gate on.

This skill is paranoid by design. It assumes a skill author may be trying to compromise the host system, exfiltrate credentials, persist beyond the session, or inject hostile instructions into the model. Most skills will trip a couple of LOW or MEDIUM findings — that's expected. The signal worth acting on is CRITICAL and HIGH.

When to use

Trigger this skill when the user:

Installs
4
GitHub Stars
635
First Seen
Jun 26, 2026
skill-security-auditor — lawve-ai/awesome-legal-skills