vetting-agent-extensions
Installation
SKILL.md
Vetting Agent Extensions
An agent extension is not a library you call — it is text and configuration that your model reads as instructions and tooling your agent runs on your behalf. A malicious dependency has to wait for you to call it. A malicious skill is already in the context window, and a malicious MCP server may execute the moment the agent starts. The trust decision happens before either runs, and it is the decision this skill is about.
This is an adoption gate, not a code audit. The question is not "does this server have a CVE" — it is "if I install this, what can it make my agent do, and what can it read on its way out."