Skill Security Audit Scanner
Paste the following prompt into your AI chat to install this skill:
Please follow https://skillhub.cn/install/skillhub.md to install @user_1a470ba8/skill-security-checker.
About this skill
Problem to Solve
Before publishing a Skill, teams need a repeatable security gate. Prompt injection, curl pipeline execution, hard-coded secrets, internal network addresses, risky dependencies, and excessive permissions are hard to catch manually.
How It Works
The skill focuses on static analysis and reads a Skill directory while skipping binaries, Office files, archives, and common dependency folders. Core capabilities include:
- Static risk checks: prompt injection, command injection, SSRF, credential leakage, path traversal, and dangerous functions.
- Dependency audit: scans requirements.txt, package.json, and pyproject.toml, then compares them against cached known CVE data.
- Permission and compliance checks: reviews over-privileged allowed-tools, and validates SKILL.md fields, naming, versioning, error handling, and structure limits.
- Optional add-ons: sandboxed --dynamic execution, YAML --rule-engine rules, --taint-tracking source→sink evidence, and --community-rules.
It does not execute scanned code by default and emits severity-weighted reports with CI exit codes. Caveats: dynamic scanning needs Docker or Windows Sandbox, syscall capture requires elevated permissions, and ML or eBPF support are optional.
Use Cases
- Audit a custom Skill before SkillHub submission to fix prompt injection, hard-coded secrets, and risky dependencies.
- Wire Skill scans into CI and use exit codes to block releases containing severe or high-risk findings.
- Evaluate third-party Skills by checking allowed-tools permissions, dependency CVEs, and SKILL.md completeness.
- Maintain YAML rule packs and .nosec.yml exclusions so team scans match internal compliance requirements.
Best For
- WorkBuddy or SkillHub developers who need pre-release detection of prompt injection, command injection, and over-privileged tools.
- Security engineers auditing third-party Skills for dependency CVEs, hard-coded credentials, and dangerous functions.
- CI/CD engineers integrating security scans into release pipelines using exit codes and structured reports.
- Platform owners enforcing Skill compliance with YAML rule packs and permission audits.
Related Skills
Detects child climbing, leaning out, or gripping window/balcony edges from surveillance video and outputs tiered alerts with historical reports.
For independent developers, automates Git weekly reports, prioritized bug tickets, and project health checks into shareable Markdown.
Scan Windows caches, temporary files, and junk files, show space usage and risk levels, and clean selected items to free disk space.
Deploy a WeChat Service Account backend with Hermes AI, Nginx, systemd, and an admin dashboard on an Ubuntu/Debian VM.