skills

open agent tooling · audited

skills

A skill is executable trust — you install someone's instructions and their scripts into an agent that can touch your files, your keys, your machine. A supply chain needs a gate — and good skills to run behind it. Here are both.

score any skill, repo, or agent answer 0–8 with file:line evidence before you trust it

46 skills in 10 categories. The auditors are read-only by design — they never execute the target.
skillcategory
answer-verifier security
dependency-auditor security
mcp-auditor security
prompt-injection-detector security
repo-auditor security
settings-auditor security
skill-auditor security
context-optimization token-efficiency
context-thrift token-efficiency
lean-replies token-efficiency
output-sandbox token-efficiency
composable-wiki-rag rag
layered-agent-memory memory
app-integration apple
app-planning-per-platform apple
apple-fitness apple
healthkit apple
metal-shaders apple
widgets apple
xcode-mcp apple
embedded-swift swift
react-native-to-swift swift
repo-to-swift-native swift
swift-on-android swift
swift-vapor swift
grill-me workflow
superpowers-tdd workflow
superpowers-writing-plans workflow
cli-anything-browser tools-services
cli-anything-chromadb tools-services
cli-anything-exa tools-services
cli-anything-mermaid tools-services
cli-anything-obsidian tools-services
cli-anything-ollama tools-services
cli-anything-zotero tools-services
github-org-automation tools-services
use-cli-anything tools-services
use-crawl4ai tools-services
use-gortex tools-services
use-hermes tools-services
use-n8n tools-services
use-ntfy tools-services
use-tailscale tools-services
seo-white-hat web
web3-wallet-integration web
led-grow-controller iot

An audit is a snapshot of one version on one day — re-run the auditor yourself: How to spot a malicious skill or repo · audit reports