AI Agent Hub
Back to skills
🔒

Skill Security Audit Scanner

IT Ops & Security Updated 2026.08.30

Paste the following prompt into your AI chat to install this skill:

Please follow https://skillhub.cn/install/skillhub.md to install @user_1a470ba8/skill-security-checker.

About this skill

Problem to Solve

Before publishing a Skill, teams need a repeatable security gate. Prompt injection, curl pipeline execution, hard-coded secrets, internal network addresses, risky dependencies, and excessive permissions are hard to catch manually.

How It Works

The skill focuses on static analysis and reads a Skill directory while skipping binaries, Office files, archives, and common dependency folders. Core capabilities include:
- Static risk checks: prompt injection, command injection, SSRF, credential leakage, path traversal, and dangerous functions.
- Dependency audit: scans requirements.txt, package.json, and pyproject.toml, then compares them against cached known CVE data.
- Permission and compliance checks: reviews over-privileged allowed-tools, and validates SKILL.md fields, naming, versioning, error handling, and structure limits.
- Optional add-ons: sandboxed --dynamic execution, YAML --rule-engine rules, --taint-tracking source→sink evidence, and --community-rules.

It does not execute scanned code by default and emits severity-weighted reports with CI exit codes. Caveats: dynamic scanning needs Docker or Windows Sandbox, syscall capture requires elevated permissions, and ML or eBPF support are optional.

Use Cases

  • Audit a custom Skill before SkillHub submission to fix prompt injection, hard-coded secrets, and risky dependencies.
  • Wire Skill scans into CI and use exit codes to block releases containing severe or high-risk findings.
  • Evaluate third-party Skills by checking allowed-tools permissions, dependency CVEs, and SKILL.md completeness.
  • Maintain YAML rule packs and .nosec.yml exclusions so team scans match internal compliance requirements.

Best For

  • WorkBuddy or SkillHub developers who need pre-release detection of prompt injection, command injection, and over-privileged tools.
  • Security engineers auditing third-party Skills for dependency CVEs, hard-coded credentials, and dangerous functions.
  • CI/CD engineers integrating security scans into release pipelines using exit codes and structured reports.
  • Platform owners enforcing Skill compliance with YAML rule packs and permission audits.