skill-security
Audit AI Agent Skills Before Installation
Unvetted agent skills can hide prompt injection, credential theft, persistence, or unsafe dependencies. This skill combines offline scanning with guided semantic review.
自分のエージェントでインストール
このリクエストをエージェントにコピーしてください。正規の Skill ページとマニフェストが含まれています。
Review the Skillstore skill "skill-security" from https://skillstore.io/skills/superagent-ai-skill-security.md and its manifest at https://skillstore.io/api/skills/superagent-ai-skill-security/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.エージェントは引き続き計画を提示し、セキュリティポリシーで必要な確認を求める必要があります。
エージェントが読めるリソース
AI エージェント、クローラー、スクリプトがページ全体ではなく整理されたコンテキストを必要とする場合は、これらのリンクを使ってください。
テストする
「skill-security」を使用しています。 Audit a documentation skill that contains no scripts or external dependencies.
期待される結果:
- Verdict: likely safe after manual review.
- The declared purpose matches the observed Markdown-only behavior.
- No confirmed credential, network, persistence, or execution findings were found.
「skill-security」を使用しています。 Audit a skill whose script reads environment secrets and sends them to an unknown endpoint.
期待される結果:
- Verdict: do not install.
- A confirmed secret-to-network flow creates a credential exfiltration risk.
- Remove the transmission behavior and rotate any exposed credentials.
「skill-security」を使用しています。 Audit a build skill that invokes a fixed compiler command.
期待される結果:
- Verdict: review manually.
- The command invocation supports the declared build purpose and uses fixed arguments.
- Confirm dependency integrity and restrict writable paths before installation.
セキュリティ監査
中リスクAll 146 static alerts are false positives caused by scanning defensive documentation, signatures, detector source, or Markdown syntax as payload behavior. The scanner makes no network requests or secret reads, but archive extraction lacks resource limits and permits disk exhaustion.
確認済みのセキュリティ上の懸念 (1)
リスク要因
⚡ スクリプトを含む (9)
⚙️ 外部コマンド (31)
🌐 ネットワークアクセス (8)
📁 ファイルシステムへのアクセス (11)
このレポートを共有・引用
バージョン付き評価レポート、中立的なバッジ、埋め込みカード、引用を共有できます。Skillstore は証拠を報告しますが、この Skill が安全かどうかは判断しません。
レポートリンクをコピー
https://skillstore.io/skills/superagent-ai-skill-security/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdownバッジ
[](https://skillstore.io/skills/superagent-ai-skill-security?utm_source=security_passport_badge)HTMLバッジ
<a href="https://skillstore.io/skills/superagent-ai-skill-security?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/superagent-ai-skill-security/security.svg" alt="Skillstore security assessment" loading="lazy"></a>埋め込みカード
<iframe src="https://skillstore.io/embed/skills/superagent-ai-skill-security.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>学術引用 (APA · BibTeX · CFF)
APA形式の引用
superagent-ai. (2026). skill-security security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/superagent-ai-skill-security/audits/1BibTeX形式の引用
@techreport{superagent-ai-superagent-ai-skill-security-2026,
author = {superagent-ai},
title = {skill-security security audit report (audit version 1)},
institution = {Skillstore},
year = {2026},
number = {1},
url = {https://skillstore.io/skills/superagent-ai-skill-security/audits/1},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "skill-security security audit report (audit version 1)"
version: "unspecified"
type: report
authors:
- name: "superagent-ai"
date-released: "2026-08-13"
url: "https://skillstore.io/skills/superagent-ai-skill-security/audits/1"
identifiers:
- type: other
value: "skillstore:superagent-ai-skill-security:audit:1"
description: "Skillstore immutable audit report identifier"
Skillstore スコア
このスコアの理由 証拠の信頼度: 中作成できるもの
Vet a Downloaded Skill
Review a local skill before granting it access to developer files and tools.
Review Marketplace Submissions
Triage submitted skills and investigate high-risk findings before publication.
Add Security Checks to CI
Generate SARIF findings for skill repositories during automated validation.
これらのプロンプトを試す
Audit the skill at [local path]. Explain whether it is safe to install and cite each confirmed finding.
Scan [archive path] and separate confirmed risks from false positives. Include practical remediation for each confirmed issue.
Audit [skill path]. Compare its declared purpose with filesystem, network, environment, and command behavior. Highlight any mismatch.
Perform a publication audit of [skill path]. Review all executable files, assess supply-chain risks, and provide a concise release recommendation.
ベストプラクティス
- Scan an immutable local copy before installing or executing the target skill.
- Read every flagged file and all executable files before deciding the verdict.
- Treat scanner output as evidence and verify intent, data flow, and declared behavior.
回避
- Do not publish a skill solely because its numeric score is low.
- Do not execute suspicious scripts to determine what they do.
- Do not dismiss quoted prompt injection without checking its surrounding context.
よくある質問
Does this skill execute the target?
Which target formats are supported?
Does it require network access?
Why is manual review still required?
Can it produce CI-compatible results?
Does a clean result guarantee safety?
開発者情報
作成者
superagent-aiライセンス
MIT
Skillstore リビジョン
r1
バージョンに関する注意
作者はバージョンを宣言していません。
参照
b855ff950d61b6aa57ef643d2f8c3c50a5745db8
メンテナンスの新しさ
2026/8/13
利用状況
0 ダウンロード · 0 閲覧