Whole-Payload Skill Review
Review the complete shipped skill payload before trusting its loaded entrypoint.
These examples and illustrative results are independently authored teaching materials, not measured model results.
Use case
A third-party skill has benign entry prose plus hooks/helpers/dependency lifecycle behavior. A teaching helper may read environment values and send requests; SKILL.md alone does not cover the package.
Mechanism
Freeze version/digest and inventory files/references, distinguishing docs, executables, binaries and external dependencies. Trace input/files/secrets/network/subprocesses and establish installation boundary, lockfile and lifecycle policy. Read untrusted code statically, recording binaries/dynamic gaps before loading/installing. Verify actual package-manager contracts separately.
Bad example
Useful SKILL.md means safe; perform an ordinary install to discover script behavior.
Good example
Inventory the fixed package including hooks/helpers/manifests/install scripts. Trace environment reads to destinations and record binaries/download gaps. Prepare later verification under a checked script-deny policy; do not execute untrusted payloads or claim whole-package safety from entry review.
Why the change matters
Installation/loading behavior can sit outside prose. Full inventories and effect paths bring executable payloads into review instead of trusting documentation appearance.
Observable expectation
Every teaching file has type/review status and helper destinations link input origin. Entry success cannot approve the whole package. Changed versions/dependency graphs invalidate inventories.
Limits
Static review cannot prove full supply-chain safety; downloads/configuration can change. Verify versioned installation controls/defaults, not frozen command matrices as current guarantees. No package was installed/executed here.
Sources and evidence
- addyosmani/agent-skills · Review installation scripts before first execution
File at this version9d0c60d406b4