skill-audit: Open-source pre-install auditor targets rising agent skill supply-chain risk

masiha97 · reddit · 2026-09-26

The author argues agent skills are becoming the next MCP-style supply chain risk: skills are executable instructions that can bundle scripts, hit the network, and read your files, while directories like skills.sh now list hundreds of thousands of entries with mostly automated vetting.

They open-sourced skill-audit, a SKILL.md playbook plus an offline Python checker offering:

It's read-only by design, makes no network calls, and never executes the skill under audit. Framed as a checklist rather than a scanner replacement, with contributions of real-world malicious patterns welcome. Install: npx skills add movahedi-ca/skill-audit.

Original post →

More from coding & agent

coding & agent channel →