AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified CC0-1.0 Self-run

Skill Security Audit

skill-sandbaseai-awesome-workbuddy-skill-security-audit · by sandbaseai

Audit a third-party Agent Skill, MCP server, connector, or desktop extension before installation by tracing instructions, executable code, dependencies, permissions, credentials, data flow, and irreversible actions.

— No reviews yet
0 installs
2 views
0.0% view→install

Install

$ agentstack add skill-sandbaseai-awesome-workbuddy-skill-security-audit

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • ✓ Prompt-injection patterns
  • ✓ Secret / credential exfiltration
  • ✓ Dangerous shell & filesystem operations
  • ✓ Untrusted network calls
  • ✓ Known-malicious package signatures

What it can access

  • ✓ Network access No
  • ✓ Filesystem access No
  • ● Shell / process execution Used
  • ✓ Environment & secrets No
  • ✓ Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-sandbaseai-awesome-workbuddy-skill-security-audit)

Reliability & compatibility

✓ Security review passed
0 installs to date
— no reviews yet
● 14d ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Skill Security Audit? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Skill Security Audit

Assess the supplied project using repository contents and primary documentation. The default audit is read-only: do not install dependencies, execute project code, sign in, provide credentials, or connect the project to a real Agent or account.

Audit

  1. Record the exact repository, revision or release, license, archive status, latest meaningful update, and files reviewed. If the audited revision is unclear, state that limitation.
  2. Read the complete SKILL.md or equivalent instructions and every file it directly invokes. Follow references to scripts, hooks, manifests, package install steps, binaries, remote URLs, environment variables, and bundled assets.
  3. Build a capability inventory: local file access, command execution, network access, browser control, account actions, publishing, messaging, deletion, payment, credential access, persistence, and self-update behavior.
  4. Trace sensitive data from its source to every local store, subprocess, log, model, API, MCP server, analytics service, or other network destination. Missing documentation is an unresolved question, not proof that data stays local.
  5. Inspect dependency manifests, lockfiles, install scripts and release provenance. Note unpinned remote execution, opaque binaries, broad transitive dependencies, or mismatches between source and distributed artifacts.
  6. Apply the [risk signals and severity model](references/risk-signals.md). A risky capability can be legitimate when it is necessary, disclosed, narrowly scoped, reversible, and confirmation-gated.
  7. Separate confirmed findings from contextual risks and unanswered questions. Cite file paths, lines, configuration fields, commands, or primary documentation for every material claim.

Output

Begin with the audited identity and one verdict:

  • Lower observed risk: no material concern was found in the reviewed scope, but this is not a guarantee.
  • Review required: important behavior, provenance, permissions, or data flow remains unclear.
  • High observed risk: confirmed behavior could expose sensitive data, weaken account or device security, cause irreversible action, or bypass informed control.

Provide these sections:

  1. Scope and limitations.
  2. Capability and permission table.
  3. Data-flow table.
  4. Findings ordered by severity, each with evidence, impact, and mitigation.
  5. Unanswered questions.
  6. A minimal-permission test plan using disposable data or accounts.

Do not label a project safe, malicious, official, or compliant without evidence sufficient for that specific claim. Static review cannot prove runtime behavior or the contents of an opaque remote service.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.