How the scan works

SkillsVetted downloads a skill's files from GitHub at a specific commit and checks every line against a set of rules for known risky patterns. Nothing is executed.

The grade

Every skill starts at 100. Each finding subtracts points by severity: critical 35, high 15, medium 6, low 2. Only the two most severe hits of any single rule count, so one noisy pattern can't sink a score on its own.

GradeScoreMeaning
A90–100No significant risks found
B75–89Minor patterns worth a glance
C55–74Review the findings before installing
D35–54Several risky patterns
F0–34, or any critical findingDo not install without a careful review

Findings inside Markdown files are usually documentation, so most rules drop one severity level there. Rules aimed at the AI itself, like prompt injection and hidden characters, keep full severity everywhere, because Markdown is exactly where those attacks live.

What we check

Hidden characters

Zero-width spaces, bidirectional overrides and Unicode tag characters that hide text from people but not from models.

Prompt injection

Secrets & credentials

Network access

Code execution

Obfuscation

Destructive commands

Persistence

Install scripts

Structure and maintenance

What a scan can't tell you

Pattern matching finds known techniques. It can't judge intent, follow logic across files, or see what a script downloads at runtime. A clean result lowers risk; it does not prove a skill is safe. For anything that will touch sensitive data, get a full human review.