Skip to content

Audit a third-party Skill

Goal: decide whether a Skill or plugin package is trustworthy enough to adopt, based on evidence rather than popularity or labels. Skill: Security (skills submode) · Procedure: Skill Audit · Walkthrough: WT-09

Point the agent at one specific package directory or archive you have obtained:

Assess only this supplied Skill package against AST01–AST10. Inspect text without installing or executing it.

The agent will not enumerate your global plugin directories, install the package, run its scripts, or probe URLs it references. Scripts are read as text.

AST risk What the assessment looks for
AST01 Malicious Skills Purpose versus instructions and harmful requested effects
AST02 Supply Chain Compromise Source and publisher provenance, and changes
AST03 Over-Privileged Skills Requested access versus actual task need
AST04 Insecure Metadata Honest metadata versus supported schema and payload
AST05 Untrusted External Instructions README, issues, web, tool output, or Memory directing the agent
AST06 Weak Isolation Required host controls, or a hold on dependent execution
AST07 Update Drift Version, content, and permission changes before adopting an update
AST08 Poor Scanning Separation of static inspection, behavioral evaluation, and their gaps
AST09 No Governance Owner, approval, inventory, and revocation process
AST10 Cross-Platform Reuse Each host’s controls and unsupported gaps, checked independently

The mapping and its controls are on Agentic Skill security.

Report statement Meaning
Signature NOT_VERIFIED No signature could be checked. That is not evidence of safety or of malice
Metadata mismatch The manifest claims differ from what the payload actually requests
Authority escalation attempt Instructions try to read credentials, widen access, or skip approval
No findings in inspected scope Clean within limits; clean sections do not prove safety

Every finding names an owner category (Kiyo guidance, host-native security, developer release process, or human organization process), plus impact, confidence, and a mitigation.

Adoption is your decision. If your organization tracks Skills, the neutral templates under templates/skill-governance/ can help:

  • inventory;
  • approval;
  • revocation;
  • incident.

A revocation document is not a kill switch. Removal happens through the host’s own uninstall mechanism.