agentsclimarketplace

Smartbrain skill auditor

Skill smartbrainactivity/smartbrain-skill-auditor

A universal, dependency-free Node.js tool to statically audit AI Skills and local agents for malicious patterns.From its SKILL.md

Install
npx -y skills add smartbrainactivity/smartbrain-skill-auditor

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

2 things to look at

  • 4 stars4 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
  • runs commandsInstructs the agent to run 2 commands, including `node {workspaceRoot}/smartbrain-skill-auditor/bin/audit.js "C:/path/to/target/skill"` and 1 more.

SKILL.md

1.3 KB, 260 tokens by cl100k_base, as published. Nobody here has run it

ai-skill-auditor

This skill provides the AI Assistant the capability to automatically audit and review local code directories (such as other downloaded AI Skills) looking for standard malicious patterns (eval, destructive child_process, hidden HTTP requests) before running them.

Instructions for the AI Assistant:

When the user asks you to "audit a skill", "check a folder for security", or "verify the integrity of this downloaded repo":

  1. Use the run_command tool to execute the central audit script.

  2. The argument is the path the user wants to audit.

    • Example 1: node {workspaceRoot}/smartbrain-skill-auditor/bin/audit.js "C:/path/to/target/skill"
    • Example 2 (If auditing the current folder): node {workspaceRoot}/smartbrain-skill-auditor/bin/audit.js .
  3. Wait for the terminal output.

  4. If it returns 0 vulnerabilities, tell the user the audit passed and provide them with the SMARTbrain Security Badge returned by the console.

  5. If it returns vulnerabilities, explicitly list the files and the malicious patterns found so the user can review them manually. DO NOT run any script in that folder without user consent.

What ships with it: 9 files

36.9 KB alongside SKILL.md, 1 of them executable

assets/

bin/

config/

Keep looking

Skills are one crate of 325,949. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.