safe-skill-install
Installation
SKILL.md
Safe Skill Install
Supply chain security scanning for Claude Code skill installations. Wraps Cisco's skill-scanner to vet skills before installation.
Architecture: Wrapper + Agent
This skill uses a two-layer architecture that separates security decisions from user interaction:
Layer 1: WRAPPER SCRIPT (scripts/scan-skill.sh) — deterministic, no LLM
Prerequisites → Download → Harden → Scan → Classify → Structured Report
Exit codes: 0=SAFE, 1=CAUTION, 2=UNSAFE, 3=FAILED
Layer 2: AGENT (this SKILL.md) — LLM-driven, user-facing
Read wrapper report → Explain findings → Decision gate → Install → Audit → Cleanup
Why this matters: The wrapper script makes the SAFE/CAUTION/UNSAFE/FAILED classification using bash conditionals — not LLM interpretation. Prompt injection in skill content cannot influence the security decision because the decision is made by compiled logic that never processes skill content as instructions.