Audit a third-party Skill
Goal: decide whether a Skill or plugin package is trustworthy enough to adopt, based on evidence rather than popularity or labels. Skill: Security (skills submode) · Procedure: Skill Audit · Walkthrough: WT-09
1. Supply the package, not your machine
Section titled “1. Supply the package, not your machine”Point the agent at one specific package directory or archive you have obtained:
Assess only this supplied Skill package against AST01–AST10. Inspect text without installing or executing it.The agent will not enumerate your global plugin directories, install the package, run its scripts, or probe URLs it references. Scripts are read as text.
2. What gets checked
Section titled “2. What gets checked”| AST risk | What the assessment looks for |
|---|---|
| AST01 Malicious Skills | Purpose versus instructions and harmful requested effects |
| AST02 Supply Chain Compromise | Source and publisher provenance, and changes |
| AST03 Over-Privileged Skills | Requested access versus actual task need |
| AST04 Insecure Metadata | Honest metadata versus supported schema and payload |
| AST05 Untrusted External Instructions | README, issues, web, tool output, or Memory directing the agent |
| AST06 Weak Isolation | Required host controls, or a hold on dependent execution |
| AST07 Update Drift | Version, content, and permission changes before adopting an update |
| AST08 Poor Scanning | Separation of static inspection, behavioral evaluation, and their gaps |
| AST09 No Governance | Owner, approval, inventory, and revocation process |
| AST10 Cross-Platform Reuse | Each host’s controls and unsupported gaps, checked independently |
The mapping and its controls are on Agentic Skill security.
3. Interpret the result
Section titled “3. Interpret the result”| Report statement | Meaning |
|---|---|
Signature NOT_VERIFIED |
No signature could be checked. That is not evidence of safety or of malice |
| Metadata mismatch | The manifest claims differ from what the payload actually requests |
| Authority escalation attempt | Instructions try to read credentials, widen access, or skip approval |
| No findings in inspected scope | Clean within limits; clean sections do not prove safety |
Every finding names an owner category (Kiyo guidance, host-native security, developer release process, or human organization process), plus impact, confidence, and a mitigation.
4. Decide and record
Section titled “4. Decide and record”Adoption is your decision. If your organization tracks Skills, the neutral templates under templates/skill-governance/ can help:
- inventory;
- approval;
- revocation;
- incident.
A revocation document is not a kill switch. Removal happens through the host’s own uninstall mechanism.