Audit claude-skills with systematic 9-phase review: standards compliance, official docs verification, code accuracy, cross-file consistency, and version drift detection. Use when investigating skill issues, major updates detected, skill not verified >90 days, or before marketplace submission.
Security
1 medium severity finding. This skill can be installed but you should review these findings before use.
The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.
Third-party content exposure detected (high risk: 0.90). The SKILL.md and README explicitly state the workflow uses WebFetch/Context7, GitHub, npm, official docs and production repositories (e.g., "Official Docs: WebFetch/Context7 verify API patterns, GitHub updates, npm versions, production repos" in SKILL.md and similar lines in README) to read and act on third‑party web content, which could contain untrusted/user-generated instructions that influence fixes and automated actions.
fa91c34
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.