2

    skill-security-vendor-pack

    by Roy Yuen

    Audit AI agent skills for security risks, packaging errors, and marketplace readiness with professional reports.

    10 developers installed this skill·Updated Jun 2026
    10 installs
    149 views

    Free

    Included in download

    • Downloadable skill package
    • Works with Claude Code, OpenClaw).
    • 2 permissions declared
    • Instant install

    Sample input

    Audit my local SEO-audit-skill folder and save the results to output.json and report.md.

    Sample output

    Security Review: [PASS/WARNING]

    • Risk Level: Medium
    • Issues:
      1. Found 'subprocess.run' call in skill.py (Suspicious Pattern)
      2. Missing 'tags' in skill.yaml (Packaging Issue)
    • JSON artifacts saved to output.json.
    • Full Markdown report generated for client delivery.

    About This Skill

    Ensure Professional Credibility for Your AI Skills

    The Skill Security Vendor Pack is a specialized auditing tool designed for developers and agencies building for AI marketplaces. It automates the pre-flight inspection of skill packages, ensuring they meet the high standards required for commercial distribution and client delivery.

    What it does

    This skill performs a deep-dive scan of a skill folder to identify security risks, packaging defects, and marketplace-readiness gaps. It replaces manual checklists with an automated, script-based review process that generates both developer-friendly JSON data and client-ready Markdown reports.

    • Permission Auditing: Scans for high-risk or over-scoped permissions that might block marketplace approval.
    • Pattern Matching: Flags suspicious code patterns or shell execution risks that require manual verification.
    • Packaging Validation: Checks for missing configuration files, metadata inconsistencies, and directory structure errors.
    • Portable Analysis: Built with zero-dependency Python for easy inclusion in CI/CD pipelines or local development workflows.

    Why use this skill?

    While basic prompting might catch high-level errors, this skill follows a strict Output Contract, ensuring every report is structured for professional use. It provides evidence-backed flags rather than generic warnings, allowing you to fix issues before they become "denied" statuses on a marketplace or security concerns for a client. It effectively turns your audit process into a repeatable, professional service.

    Use Cases

    • Audit third-party skills before installing them in your environment.
    • Generate professional security clearance reports for your enterprise clients.
    • Validate skill metadata and structure before submitting to an AI marketplace.
    • Integrate security linting into your skill development CI/CD pipeline.

    Reviews

    No reviews yet - be the first to share your experience.

    Only users who have downloaded or purchased this skill can leave a review.

    Security Scanned

    Passed automated security review

    Permissions

    Terminal / Shell
    Network Access

    File Scopes

    skill-security-vendor-pack-upload/**

    Compatible with SKILL.md-compatible agents (e.g., Claude Code, OpenClaw).

    Creator

    Frequently Asked Questions

    More Premium Skills

    Free