Skill Spector

Security guides

Review AI agent skills before they get local authority.

Short, practical references for developers checking SKILL.md files, MCP servers, scripts, downloads, and data access before installation.

Review checklist

How to review a SKILL.md file before installing it

A practical checklist for reviewing AI agent skill instructions, scripts, tools, files, and trust boundaries before installation.

Read guide

Unsafe patterns

Common unsafe patterns in AI agent skills

Examples of AI skill patterns that deserve manual review, including shell execution, remote downloads, broad file reads, and credential handling.

Read guide

MCP security

MCP server security checklist for agent users

A checklist for reviewing MCP server commands, configuration, permissions, local file access, network access, and exposed tool surfaces.

Read guide