What problem does it solve? Installing third-party or unreviewed AI skills can introduce hidden risks like data exfiltration, prompt injection, credential exposure, and malicious scripts. This Skill performs a systematic security review of any skill package so you can identify threats before deployment. ## Core Features & Use Cases - Systematic Security Analysis: Reviews SKILL.md instructions, scripts, references, and assets against a catalog of known security patterns and anti-patterns. - Severity-Rated Findings: Produces an executive summary, CRITICAL/HIGH/MEDIUM/LOW findings list, and a 10-point security checklist covering data exfiltration, network access, prompt injection, and more. - .skill Package Support: Extracts and audits packaged .skill files, with heightened scrutiny for third-party skills of unknown provenance. - Use Case: Before installing a community-built skill, run this audit to detect undisclosed network calls, hardcoded credentials, obfuscated code, or instruction-override attempts. ## Quick Start Analyze the security of this skill package and report any vulnerabilities with severity ratings.