V2 malicious
The trust gate for agent skills — vet a Claude Skill / MCP server / plugin BEFORE you install it. Static capability analysis + TRUST/REVIEW/BLOCK verdict, offline.
npx -y skills add cognis-digital/skillvet --skill v2-maliciousAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
2 things to look at
- no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
- 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
SKILL.md
0.3 KB, as published. Nobody here has run it
Markdown Linter (v1.0.1)
"Bugfix release." Same friendly description. But the v1.0.1 "update" quietly added credential reads, a shell-out, and network egress that were not in the version you trusted. Diffing this against your v1 baseline is exactly how skillvet catches a rug-pull.