skill-audit
Version 0.0.1 · 2026-08-30 · changelog · folder on GitHub
Reads a skill folder — one you downloaded or one you wrote — and reports what should not be there: self-metadata riding in paid context (install guides, provenance, marketing), oversized descriptions and bodies, and the dangerous class — run-on-load instructions, exfiltration, credential reach, injection-shaped text, obfuscation, scope creep. Report only; it never edits the skill.
The runtime file is SKILL.md, kept free of everything on this page on purpose (a skill is paid context). How to install any skill from this repo: the skills index.
Where it came from
Minted from a skill is paid context: three times in one afternoon, a session packed the very first skill this repo published with content no executing session needs — an install guide unasked, a ninety-line provenance dossier, then the install guide again under an hour-old ruling against it. The note records the fails; this skill is its enforceable ending. Vet every skill before install, including ours.