Skill Security Vendor Pack
by Roy Yuen
Audit AI agent skills for security risks, packaging errors, and marketplace readiness with professional reports.
Free
Works with the AI tools you already use
See it in action
You say
Audit my local SEO-audit-skill folder and save the results to output.json and report.md.
Your agent does
Security Review: [PASS/WARNING]
- Risk Level: Medium
- Issues:
- Found 'subprocess.run' call in skill.py (Suspicious Pattern)
- Missing 'tags' in skill.yaml (Packaging Issue)
- JSON artifacts saved to output.json.
- Full Markdown report generated for client delivery.
About this skill
Ensure Professional Credibility for Your AI Skills
The Skill Security Vendor Pack is a specialized auditing tool designed for developers and agencies building for AI marketplaces. It automates the pre-flight inspection of skill packages, ensuring they meet the high standards required for commercial distribution and client delivery.
What it does
This skill performs a deep-dive scan of a skill folder to identify security risks, packaging defects, and marketplace-readiness gaps. It replaces manual checklists with an automated, script-based review process that generates both developer-friendly JSON data and client-ready Markdown reports.
- Permission Auditing: Scans for high-risk or over-scoped permissions that might block marketplace approval.
- Pattern Matching: Flags suspicious code patterns or shell execution risks that require manual verification.
- Packaging Validation: Checks for missing configuration files, metadata inconsistencies, and directory structure errors.
- Portable Analysis: Built with zero-dependency Python for easy inclusion in CI/CD pipelines or local development workflows.
Why use this skill?
While basic prompting might catch high-level errors, this skill follows a strict Output Contract, ensuring every report is structured for professional use. It provides evidence-backed flags rather than generic warnings, allowing you to fix issues before they become "denied" statuses on a marketplace or security concerns for a client. It effectively turns your audit process into a repeatable, professional service.
How to install
Drop the file into your AI Agent. Works with Claude, Cursor, ChatGPT, and 20+ more.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
20 installs
Downloaded by developers to date
Free forever
No account required to browse
More reviews for Roy Yuen5.0(7)
Feedback buyers left on other skills by the same creator.
Trust & safety
Security scanned
Verified clean 4 months ago
- Free to download with an account
Frequently Asked Questions
Popular in Security & Compliance

🔒 PII & Data-Leak Scanner
Scan local SQL, CSV, JSON, seed, fixture, and log files for PII-indicating names plus email-, SSN-, card-, and phone-like values. Get file/line findings with matched values redacted by default—no network, writes, database connection, or compliance claim.
dependency-auditor
Audit dependencies for security, licenses, and health while generating a phased, low-risk upgrade and migration plan.
cybersecurity-bridge for all agentic
A high-performance wrapper to route security tasks directly to the Anthropic-Cybersecurity-Skills library.
Bounty Security Pattern Master Library — 399 Vulnerability Patterns
A premium library of 399 vulnerability patterns and DeFi attack vectors for AI-driven bug hunting and security audits.