← Skill Risk CheckCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to Skill Risk Check
Snapshot Sep 30, 2026 · 23:15 UTC · version 0.1.5
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"name": "agent-skillguard",
"description": "Use before installing an agent skill or plugin. Scan local files for risky instructions, broad permissions, suspicious downloads, prompt-injection patterns, and possible secret exposure; return file-and-line findings and remediation without running, uploading, or certifying the target.",
"included_files": [],
"skill_md_contents": "---\nname: agent-skillguard\ndescription: Use before installing an agent skill or plugin. Scan local files for risky instructions, broad permissions, suspicious downloads, prompt-injection patterns, and possible secret exposure; return file-and-line findings and remediation without running, uploading, or certifying the target.\n---\n\n# Skill Risk Check\n\nUse this skill when the user asks whether an agent skill or plugin should be trusted, installed, reviewed, or admitted.\n\n## Non-negotiable boundary\n\nScanning is read-only. Never execute, source, import, install, or enable the target artifact during review. A clean report is not proof that an artifact is safe, and a finding is not proof of malicious intent.\n\n## Workflow\n\n1. Identify the exact local target and its provenance.\n2. Run `skillguard scan <path> --format markdown` before any installation step.\n3. Review every active finding at its exact file and line.\n4. Separate confirmed behavior, ambiguous behavior, and false positives.\n5. If a false positive is accepted, suppress only its exact fingerprint, rule ID, and rule version with a concrete reason.\n6. Re-run the scan and report both active and suppressed counts.\n7. Stop before installation or permission grants unless the user separately authorized them.\n8. When evaluating the scanner itself, require the public positive/negative fixture corpus and non-coverage registry to pass `tools/verify_rule_corpus.py`.\n\n## Exit codes\n\n- `0`: no active findings at or above the selected severity.\n- `1`: at least one active finding requires review.\n- `2`: the scan could not be completed reliably.\n\nExit `0` means only that the configured deterministic rules found no active match. It is not a safety certification.\n"
}SHA-256: 305cc3a8f5c5fba917e26348d451e0c7189bdd1203a258a1722fa4e04ad84d7b