Agent skill

Skill Security Audit

by sickn33 in sickn33/agentic-awesome-skills

Audit an Agent Skill, MCP server, connector, or desktop extension before installation by tracing code, dependencies, permissions, credentials, data flow, and irreversible actions.

CC0-1.0Auto-check passedAgent Workflows

Install Skill Security Audit

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill skill-security-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills skill-security-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/skill-security-audit .claude/skills/skill-security-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
skill-security-audit
GitHub stars
47k
Used in
1 other repo
Token cost
~1.4k tokens
SKILL.md length
660 words
Files
1
Skills in repo
1,354
Repo updated
First seen
Licence
CC0-1.0

At a glance

Audit an Agent Skill, MCP server, connector, or desktop extension before installation by tracing code, dependencies, permissions, credentials, data flow, and irreversible actions.

  • Works in 7 steps: Record the exact repository, revision or… → Read the complete SKILL.md or equivalent… → Inventory capabilities: filesystem… → …
  • Tasks that involve Prompt injection and agent security
  • SKILL.md covers Overview, When to Use This Skill, How It Works and Output, plus 4 more sections
  • Needs API_TOKEN

What it does

Skill Security Audit is an agent skill from sickn33/agentic-awesome-skills. Audit an Agent Skill, MCP server, connector, or desktop extension before installation by tracing code, dependencies, permissions, credentials, data flow, and irreversible actions.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows, covering Prompt injection and agent security and MCP servers. It works with Model Context Protocol. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is CC0-1.0.

When your agent uses it

  • Tasks that involve Prompt injection and agent security
  • Tasks that involve MCP servers

Example prompts

  • “/skill-security-audit”

Requirements

  • A credential in API_TOKEN

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Record the exact repository, revision or release, license, archive status, latest meaningful update, and files reviewed. State any scope…
  2. Read the complete SKILL.md or equivalent instructions and every file it directly invokes. Follow references to scripts, hooks, manifests…
  3. Inventory capabilities: filesystem access, command execution, network access, browser control, account actions, publishing, messaging…
  4. Trace sensitive data from its source to local stores, subprocesses, logs, models, APIs, MCP servers, analytics services, and other network…
  5. Inspect dependency manifests, lockfiles, install scripts, and release provenance. Note unpinned remote execution, broad dependencies…
  6. Separate confirmed findings from contextual risks and unanswered questions. Cite file paths, line numbers, configuration fields, commands…
  7. Propose a minimal-permission test using disposable data or accounts; do not run it without explicit user approval.

What it can do on your machine

Read from SKILL.md and the folder at commit ec02547. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • API_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Skill Security Audit loads about 1.4k tokens when it runs. Until then it costs about 50 tokens; SKILL.md has 660 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~50
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit ec02547, republished under its CC0-1.0 licence (© sickn33). 660 words, ~1,378 tokens.

Download SKILL.mdSave it as .claude/skills/skill-security-audit/SKILL.md (or your agent's skills folder).
name
skill-security-audit
description
Audit an Agent Skill, MCP server, connector, or desktop extension before installation by tracing code, dependencies, permissions, credentials, data flow, and irreversible actions.
category
security
risk
safe
source
community
source_repo
sandbaseai/awesome-workbuddy
source_type
community
date_added
2026-09-05
author
sandbaseai
tags
security, audit, agent-skills, mcp, supply-chain
tools
claude, codex, cursor, gemini, workbuddy
license
CC0-1.0

Skill Security Audit

Overview

Review a third-party Agent Skill, MCP server, connector, or desktop extension before installation. The default workflow is read-only: do not install dependencies, execute project code, sign in, provide credentials, or connect the project to a real account during static review.

When to Use This Skill

  • Use before installing an unfamiliar Skill, MCP server, connector, plugin, or desktop extension.
  • Use when a project handles files, credentials, browser sessions, external accounts, network requests, or destructive actions.
  • Use when a release, binary, dependency, or remote installer cannot be independently verified.

How It Works

  1. Record the exact repository, revision or release, license, archive status, latest meaningful update, and files reviewed. State any scope limitation.
  2. Read the complete SKILL.md or equivalent instructions and every file it directly invokes. Follow references to scripts, hooks, manifests, package-install steps, binaries, remote URLs, environment variables, and bundled assets.
  3. Inventory capabilities: filesystem access, command execution, network access, browser control, account actions, publishing, messaging, deletion, payment, credential access, persistence, and self-update behavior.
  4. Trace sensitive data from its source to local stores, subprocesses, logs, models, APIs, MCP servers, analytics services, and other network destinations. Missing documentation is an unresolved question, not proof that data stays local.
  5. Inspect dependency manifests, lockfiles, install scripts, and release provenance. Note unpinned remote execution, broad dependencies, opaque binaries, and mismatches between source and distributed artifacts.
  6. Separate confirmed findings from contextual risks and unanswered questions. Cite file paths, line numbers, configuration fields, commands, or primary documentation for every material claim.
  7. Propose a minimal-permission test using disposable data or accounts; do not run it without explicit user approval.

Output

Begin with the audited identity and one verdict:

  • Lower observed risk: no material concern was found in the reviewed scope; this is not a guarantee.
  • Review required: important behavior, provenance, permissions, or data flow remains unclear.
  • High observed risk: confirmed behavior could expose sensitive data, weaken account or device security, cause irreversible action, or bypass informed control.

Then provide:

  1. Scope and limitations.
  2. A capability and permission table.
  3. A data-flow table.
  4. Findings ordered by severity, with evidence, impact, and mitigation.
  5. Unanswered questions.
  6. A minimal-permission test plan.

Examples

Example 1: A local, read-only Skill

Input: a repository containing only SKILL.md and Markdown references, with no scripts, dependencies, credentials, or network instructions.

Report: record the reviewed revision and files, mark command/network/credential capabilities as not observed in scope, note any missing license or provenance evidence, and recommend a disposable-data trial only if the remaining questions are resolved.

Show full SKILL.md (240 more words)Show less
Example 2: An MCP server with a token

Input: a server whose setup reads API_TOKEN and whose tools can create or delete records.

Report: trace the token and request destinations, classify the write/delete capability separately from read access, require a least-privilege test account and action-time confirmation, and do not run the server with production credentials during review.

Best Practices

  • ✅ Prefer implementation and current primary documentation over badges, screenshots, descriptions, or popularity.
  • ✅ Pin revisions and inspect manifests, lockfiles, checksums, and release provenance.
  • ✅ Use disposable data, least privilege, localhost binding, dry runs, backups, confirmation gates, and rollback where applicable.
  • ✅ Mark unknown behavior explicitly and preserve the exact reviewed revision.
  • ❌ Do not call a project safe, malicious, official, or compliant without evidence for that claim.
  • ❌ Do not execute install commands, remote scripts, binaries, account actions, or credential flows during static review.

Security & Safety Notes

Static review cannot prove runtime behavior or the contents of an opaque remote service. Treat a green validator, marketplace entry, star count, or successful installation as evidence about only that narrow property, never as a safety certificate. Stop if the requested review would require real credentials, production data, or an unapproved external action.

Limitations

  • The audit is evidence-led but bounded by the public revision and files that can be inspected.
  • A missing policy or undocumented data destination remains unresolved; it must not be silently inferred away.
  • Risk severity depends on capability, exposure, control, and reversibility, not on keywords alone.

© sickn33, CC0-1.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/skill-security-audit of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit ec02547

Used in 1 other repository

We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Skill Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Skill Security Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Skill Security Audit this skillsickn33/agentic-awesome-skills47k1 repos~1.4kAutomated safety check: PassCC0-1.0
PolygraphBankrBot/skills1.2k—~3.4kAutomated safety check: PassNone
Forensifyalexgreensh/repo-forensics188—~2.5kAutomated safety check: NotesCustom licence
Plugin Scanneriflytek/skillhub5.2k2 repos~1.1kAutomated safety check: NotesApache-2.0
MCP Server Security Auditawarexone/Agentic-Bug-Hunter5.3k—~1.9kAutomated safety check: WarnMIT
Auditing MCP Servers For Tool Poisoningmukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: WarnApache-2.0

Similar skills

  • Polygraph

    BankrBot/skills

    Behavioral trust grades (A–F) for MCP servers. An agent skill from BankrBot/skills.

    1.2k GitHub stars~3.4k tokensUpdated 3 days ago
    Agent WorkflowsAuto-check passed
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    188 GitHub stars~2.5k tokensUpdated 11 days ago
    SecurityAuto-check: notes
  • Plugin Scanner

    iflytek/skillhub

    Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them.

    5.2k GitHub starsUsed in 2 repos~1.1k tokens
    SecurityAuto-check: notes
  • MCP Server Security Audit

    awarexone/Agentic-Bug-Hunter

    Audits MCP servers and their client configs for tool poisoning, prompt injection, over-privileged tools, injection bugs, secret leaks and missing approval gates.

    5.3k GitHub stars~1.9k tokensUpdated 3 days ago
    SecurityAuto-check: warnings
  • Auditing MCP Servers For Tool Poisoning

    mukul975/Anthropic-Cybersecurity-Skills

    Audit MCP servers for tool poisoning, tool shadowing, rug pulls, SSRF, and unauthenticated exposure using Invariant Labs' mcp-scan for static/runtime scanning plus manual SSRF/auth checks and…

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    SecurityAuto-check: warnings
  • Securing AI Systems

    trilwu/secskills

    Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

    156 GitHub stars~2.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,354 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed
  • Content Creator

    sickn33/agentic-awesome-skills

    Drafts and reviews audience-specific content from supplied brand examples, with local scripts for brand voice and SEO diagnostics, channel templates and a content calendar.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed

Questions about Skill Security Audit

What does Skill Security Audit do?

Audit an Agent Skill, MCP server, connector, or desktop extension before installation by tracing code, dependencies, permissions, credentials, data flow, and irreversible actions. Skill Security Audit is an agent skill from sickn33/agentic-awesome-skills. Audit an Agent Skill, MCP server, connector, or desktop extension before installation by tracing code, dependencies, permissions, credentials, data flow, and irreversible actions.

When should I use Skill Security Audit?

Skill Security Audit fits situations like: tasks that involve Prompt injection and agent security; tasks that involve MCP servers.

How do I install Skill Security Audit in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill skill-security-audit -a claude-code`. Or copy the skill folder (skills/skill-security-audit in sickn33/agentic-awesome-skills) into .claude/skills/skill-security-audit in your project. Claude Code loads it when a task matches its description.

How do I install Skill Security Audit in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill skill-security-audit -a codex`. Or copy the skill folder (skills/skill-security-audit in sickn33/agentic-awesome-skills) into .agents/skills/skill-security-audit in your project. Codex loads it when a task matches its description.

Can I use Skill Security Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill skill-security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/skill-security-audit, .gemini/skills/skill-security-audit, .github/skills/skill-security-audit and .opencode/skills/skill-security-audit in your project.

What does Skill Security Audit need to run?

Going by SKILL.md and its folder, Skill Security Audit needs credentials named API_TOKEN. Our summary lists: A credential in API_TOKEN.

Does Skill Security Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Skill Security Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Skill Security Audit use?

Skill Security Audit is published under the CC0-1.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Skill Security Audit use?

About 1.4k tokens (SKILL.md is roughly 5.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Skill Security Audit?

Skills that share tags, products or a category with Skill Security Audit: Polygraph (BankrBot/skills, 1.2k stars), Forensify (alexgreensh/repo-forensics, 188 stars), Plugin Scanner (iflytek/skillhub, 5.2k stars) and MCP Server Security Audit (awarexone/Agentic-Bug-Hunter, 5.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Skill Security Audit?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,343 GitHub stars. The repository holds 1,354 skills in this directory. The repository was last updated on October 7, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.