Audit Shrimp 3: Security Vetting for AI Agent Skills
Paste the following prompt into your AI chat to install this skill:
Please install @user_d93c4aed/qmi-skill-vetter according to https://skillhub.cn/install/skillhub.md.
About this skill
The Problem
Third-party AI agent skills combine prompts, scripts, and external tool calls. Installing an unknown SKILL.md can expose credentials, read local data, or execute system-level actions. Audit Shrimp 3 treats “vet before install” as a mandatory security workflow, giving engineers a repeatable static review process before introducing unfamiliar skills.
How It Works
The skill provides a structured vetting protocol rather than generic security advice:
- Source check: evaluate whether the skill comes from an official source, a high-star repository, a known author, or an unknown origin, then adjust scrutiny accordingly.
- Mandatory code review: read all files in the skill and look for concrete red flags instead of relying on descriptions alone.
- Permission scope assessment: inspect whether the skill touches file operations, browsers, APIs, credentials, trading, or system capabilities.
- Risk classification: map the skill into low, medium, high, or extreme risk tiers, with corresponding actions such as basic review, full code review, human approval, or do-not-install.
- Vetting report: produce a structured summary that makes the decision easier to audit and revisit.
Boundaries and Caveats
It is intended for pre-installation review of AI agent skills shared through ClawdHub, GitHub repositories, or other agents. It relies on the model actually reading the skill files and executing the checks; it does not replace runtime sandboxes, dependency scanning, credential management, or organizational security policy. When a skill involves credentials, trading, system permissions, or security configuration, human judgment is required. For ambiguous sources or unclear behavior, the default action is not to install.
Use Cases
- Review an unfamiliar GitHub agent skill before installation to detect credential access or system commands.
- Assess a ClawdHub-shared skill and decide whether it can be installed or requires human approval by risk tier.
- Inspect API calls and browser actions in skill files to confirm the permission scope is within expectations.
- Produce a vetting report that records source, red flags, and actions for later review.
Best For
- Engineers managing AI agent workflows who need security review before adding third-party skills.
- DevOps engineers evaluating GitHub-hosted skills who need to spot risky permissions and red flags.
- Product owners running internal agent platforms who require auditable conclusions before skill approval.
- Developers using multi-agent collaboration who need to check whether shared skills request credentials.
Related Skills
Turn vague requests into structured prompts with role, task, context, and constraints, outputting only usable prompts without executing the task.
A skill for game NPC and enemy AI that separates decision, steering, and pathfinding, covering FSMs, behavior trees, A*, path caching, and pitfalls.
Provides multi-turn emotional companion chat through a third-party Agent API and supports continuing sessions via session_id.
An evaluation-driven workflow for diagnosing, optimizing, validating, and logging Agent Skills based on design patterns and anti-patterns.