Skill Security Vendor Pack

    3

    Audit AI agent skills for security risks, packaging errors, and marketplace readiness with professional reports.

    Free

    33 installs5.0 (1 review)

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseDotsDots+22 more

    skill-security-vendor-pack

    Example session with this skill installed

    Audit my local SEO-audit-skill folder and save the results to output.json and report.md.

    • Read your context and instructions
    • Compiled the -security-vendor-

    Security Review: [PASS/WARNING]

    • Risk Level: Medium
    • Issues:
      1. Found 'subprocess.run' call in skill.py (Suspicious Pattern)
      2. Missing 'tags' in skill.yaml (Packaging Issue)
    • JSON artifacts saved to output.json.
    • Full Markdown report generated for client delivery.
    2. Missing 'tags' in skill.yaml

    Connects securely to your tools. The creator never sees your data.

    About this skill

    Ensure Professional Credibility for Your AI Skills

    The Skill Security Vendor Pack is a specialized auditing tool designed for developers and agencies building for AI marketplaces. It automates the pre-flight inspection of skill packages, ensuring they meet the high standards required for commercial distribution and client delivery.

    What it does

    This skill performs a deep-dive scan of a skill folder to identify security risks, packaging defects, and marketplace-readiness gaps. It replaces manual checklists with an automated, script-based review process that generates both developer-friendly JSON data and client-ready Markdown reports.

    • Permission Auditing: Scans for high-risk or over-scoped permissions that might block marketplace approval.
    • Pattern Matching: Flags suspicious code patterns or shell execution risks that require manual verification.
    • Packaging Validation: Checks for missing configuration files, metadata inconsistencies, and directory structure errors.
    • Portable Analysis: Built with zero-dependency Python for easy inclusion in CI/CD pipelines or local development workflows.

    Why use this skill?

    While basic prompting might catch high-level errors, this skill follows a strict Output Contract, ensuring every report is structured for professional use. It provides evidence-backed flags rather than generic warnings, allowing you to fix issues before they become "denied" statuses on a marketplace or security concerns for a client. It effectively turns your audit process into a repeatable, professional service.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    5.0
    1 review
    5
    1
    4
    0
    3
    0
    2
    0
    1
    0

    33 people have installed this skill.

    Trust & safety

    Security scanned

    Verified clean 6 months ago

    • Free to download with an account

    Listed6 months ago

    What's inside

    Frequently Asked Questions