Security Audit
anysiteio/agent-skills:skills/skill-audit
github.com/anysiteio/agent-skillsTrust Assessment
anysiteio/agent-skills:skills/skill-audit received a trust score of 10/100, placing it in the Untrusted category. This skill has significant security findings that require attention before use in production.
SkillShield's automated analysis identified 8 findings: 5 critical, 1 high, 2 medium, and 0 low severity. Key findings include System prompt override / policy bypass, Persistence / self-modification instructions, File read + network send exfiltration.
The analysis covered 4 layers: dependency_graph, llm_behavioral_safety, manifest_analysis, static_code_analysis. The manifest_analysis layer scored lowest at 0/100, indicating areas for improvement.
Last analyzed on February 8, 2026 (commit 34bedfab). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings8
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| CRITICAL | System prompt override / policy bypass Ignore/disregard previous instructions pattern Remove or rewrite any instructions that attempt to override system behavior. Legitimate skills should not contain phrases like 'ignore previous instructions' or 'new system prompt'. | Unknown | /tmp/skillscan-clone-04kd3dz0/repo/skills/skill-audit/SKILL.md:25 | |
| CRITICAL | System prompt override / policy bypass Override/supersede system policy Remove or rewrite any instructions that attempt to override system behavior. Legitimate skills should not contain phrases like 'ignore previous instructions' or 'new system prompt'. | Unknown | /tmp/skillscan-clone-04kd3dz0/repo/skills/skill-audit/SKILL.md:203 | |
| CRITICAL | Persistence / self-modification instructions Shell RC file modification for persistence Remove any persistence mechanisms. Skills should not modify system startup configurations, crontabs, LaunchAgents, systemd services, or shell profiles. | Unknown | /tmp/skillscan-clone-04kd3dz0/repo/skills/skill-audit/SKILL.md:172 | |
| CRITICAL | Persistence / self-modification instructions Shell RC file modification for persistence Remove any persistence mechanisms. Skills should not modify system startup configurations, crontabs, LaunchAgents, systemd services, or shell profiles. | Unknown | /tmp/skillscan-clone-04kd3dz0/repo/skills/skill-audit/SKILL.md:193 | |
| CRITICAL | File read + network send exfiltration AI agent config/credential file access Remove access to sensitive files not required by the skill's stated purpose. SSH keys, cloud credentials, and browser data should never be read by skills unless explicitly part of their declared functionality. | Unknown | /tmp/skillscan-clone-04kd3dz0/repo/skills/skill-audit/SKILL.md:38 | |
| HIGH | Sensitive path access: AI agent config Access to AI agent config path detected: '~/.claude/'. This may indicate credential theft. Verify that access to this sensitive path is justified and declared. | Unknown | /tmp/skillscan-clone-04kd3dz0/repo/skills/skill-audit/SKILL.md:38 | |
| MEDIUM | Persistence mechanism: Shell RC file modification Detected Shell RC file modification pattern. Persistence mechanisms allow malware to survive system restarts. Review this persistence pattern. Skills should not modify system startup configuration. | Unknown | /tmp/skillscan-clone-04kd3dz0/repo/skills/skill-audit/SKILL.md:172 | |
| MEDIUM | Persistence mechanism: Shell RC file modification Detected Shell RC file modification pattern. Persistence mechanisms allow malware to survive system restarts. Review this persistence pattern. Skills should not modify system startup configuration. | Unknown | /tmp/skillscan-clone-04kd3dz0/repo/skills/skill-audit/SKILL.md:193 |
Scan History
Embed Code
[](https://skillshield.io/report/17a1e853a3eee37a)
Powered by SkillShield