P67 · Safety & trust

Whole-Payload Skill Review

Review the complete shipped skill payload before trusting its loaded entrypoint.

Editorially reviewed

These examples and illustrative results are independently authored teaching materials, not measured model results.

Use case

A third-party skill has benign entry prose plus hooks/helpers/dependency lifecycle behavior. A teaching helper may read environment values and send requests; SKILL.md alone does not cover the package.

Mechanism

Freeze version/digest and inventory files/references, distinguishing docs, executables, binaries and external dependencies. Trace input/files/secrets/network/subprocesses and establish installation boundary, lockfile and lifecycle policy. Read untrusted code statically, recording binaries/dynamic gaps before loading/installing. Verify actual package-manager contracts separately.

Bad example

Useful SKILL.md means safe; perform an ordinary install to discover script behavior.

Good example

Inventory the fixed package including hooks/helpers/manifests/install scripts. Trace environment reads to destinations and record binaries/download gaps. Prepare later verification under a checked script-deny policy; do not execute untrusted payloads or claim whole-package safety from entry review.

Why the change matters

Installation/loading behavior can sit outside prose. Full inventories and effect paths bring executable payloads into review instead of trusting documentation appearance.

Observable expectation

Every teaching file has type/review status and helper destinations link input origin. Entry success cannot approve the whole package. Changed versions/dependency graphs invalidate inventories.

Limits

Static review cannot prove full supply-chain safety; downloads/configuration can change. Verify versioned installation controls/defaults, not frozen command matrices as current guarantees. No package was installed/executed here.

Sources and evidence

Read the editorial criteria

Related methods