agentsclimarketplace

Skill security

Skill suryast/free-ai-agent-skills/skill-security

Security audit tool for AI agent skills. Scans for credential harvesting, code injection, network exfiltration, obfuscation. ALWAYS run before installing any new skill from external sources. Triggers on: new skill installation, skill audit, security scan, skill review, before loading external skill.From its SKILL.md

Install
npx -y skills add suryast/free-ai-agent-skills --skill skill-security

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

2 things to look at

  • 2 stars2 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
  • runs commandsInstructs the agent to run 4 commands, including `./skill-security/audit.sh /path/to/skill` and 3 more.

SKILL.md

3.0 KB, 759 tokens by cl100k_base, as published. Nobody here has run it

Skill Security Scanner

Security audit tool for AI agent skills. Run before installing any new skill.

Quick Audit

# Audit a skill directory
./skill-security/audit.sh /path/to/skill

# Audit all installed skills
./skill-security/audit-all.sh

What It Checks

CheckRisk LevelPattern
Network Exfiltration🚨 HIGHrequests., urllib, http.client, socket., fetch(, axios
Credential Harvesting🚨 HIGH.ssh/, .aws/, pass , keyring, credential, secret, token file reads
Code Injection🚨 CRITICALexec(, eval(, compile(, Function(, __import__
Obfuscation⚠️ MEDIUMbase64.decode, atob, encoded payloads
Env Dumping⚠️ MEDIUMos.environ, process.env, getenv bulk access
Subprocess Abuse⚠️ MEDIUMsubprocess.run, os.system, child_process with credentials

Severity Levels

  • CRITICAL (🚨): Block installation, report to owner
  • HIGH (πŸ”΄): Requires manual review before use
  • MEDIUM (🟑): Note but allow if from trusted source
  • LOW (🟒): Informational only

Safe Skill Checklist

Before using any skill:

  1. βœ… Is it from a trusted source? (official OpenClaw, known publisher)
  2. βœ… Is the code readable (not obfuscated)?
  3. βœ… Does it document why it needs network/credential access?
  4. βœ… Does it scope file access to its own directory?
  5. βœ… Has it been audited by the community?

Integration with AGENTS.md

Add this to your workflow:

## Skill Installation Protocol

Before loading any new skill:
1. Run `./skill-security/audit.sh <skill-path>`
2. If CRITICAL/HIGH findings β†’ STOP, alert the user
3. If MEDIUM findings β†’ Review manually, proceed if justified
4. If CLEAN β†’ Safe to use

Automatic Protection

The scanner creates a blocklist at ./blocklist.txt. Skills with CRITICAL findings are automatically added.

Manual Override

If a skill is flagged but you've verified it's safe:

echo "skill-name:verified:YYYY-MM-DD:reason" >> allowlist.txt

Premium Skills

Like this? Check out our premium skills at skillpacks.dev:

  • πŸ›‘οΈ Security Suite β€” Full PII scanning, secrets detection, prompt injection defense β€” $9.90
  • 🧠 Structured Memory β€” Three-tier memory replacing flat MEMORY.md β€” $9.90
  • πŸ“‹ Planning & Execution β€” Systematic task plans with batch execution β€” $9.90
  • πŸ’Ž Bundle β€” all 3 for $24.90

What ships with it: 5 files

8.7 KB alongside SKILL.md, 3 of them executable

Keep looking

Skills are one crate of 325,949. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.