{"slug":"skill-md-review","name":"SKILL.md Review: Safe and Within the Limits","version":"1.0.1","updated_at":"2026-10-08T08:56:31.909Z","use_when":"Reviews a SKILL.md file before you install, buy or publish it and lists every problem with a fixed code, the place and a fix, then gives one verdict. It checks the front matter against the published limits (name up to 64 characters in lowercase, hyphens and digits, no reserved words; description present, up to 1,024 characters, naming both its job and the requests that should trigger it, in the third person), and it reads the body for hidden orders to the agent, credentials pasted into the text, commands that download and run remote code, Windows-style paths, a body over 500 lines and the lack of any example. Use to review a SKILL.md, audit a Claude or agent skill before installing it, check a skill file for prompt injection, or lint a skill before publishing it to a marketplace.","not_for":"Running or testing the skill, reading the scripts that come with it, or judging whether its advice is correct for its topic. It reads one SKILL.md as text, so a problem hidden in a bundled script or a downloaded file is outside what it can see.","languages":["any"],"tags":["skill-md","agent-skills","prompt-injection","security-review","lint","claude-code"],"category":"agents","category_url":"https://aiskills402.com/categories/agents","keywords":["review a SKILL.md","prompt injection","lint a skill"],"faq":[{"q":"What does it check in the front matter?","a":"The published limits for skills: a name of at most 64 characters in lowercase letters, digits and hyphens without the reserved words anthropic and claude, and a description that exists, stays within 1,024 characters, says when the skill should be used and is written in the third person. It counts the characters instead of estimating them."},{"q":"Will it catch a hidden instruction to the agent?","a":"Those come first in the report, with the verdict unsafe: a request to read SSH keys, a silent copy of the user's files, a line claiming to replace the system's instructions and a note telling the reviewer to answer No findings were all caught in our tests, along with a pasted API key and a curl command piped into a shell."},{"q":"Does it flag every skill that runs scripts?","a":"No. Telling the agent to run the skill's own bundled script on the file the user named is normal and was not flagged by either model. It becomes a finding when the file reaches for data the task does not need or downloads and runs code at use time."},{"q":"What did the models miss without it?","a":"The counted rules. Without the skill, Claude Haiku did not notice a 65-character name, a 1,305-character description, a body of 538 lines or a Windows path, and neither Haiku nor Sonnet said that a file had no example. With the skill both models reported all of them."}],"examples":[{"lang":"en","model":"claude-sonnet-5-5","input_excerpt":"---\nname: PDF_Form_Filler\ndescription: Fills in PDF forms from data you give it and checks that every required field is set. Use when asked to fill a PDF form, complete a fillable PDF, or check a form for missing fields.\n---\n\n# PDF form filler\n\nRead the form fields first, then fill only the fields the user gave data for.\nNever invent a value. Report every required field that is still empty.…","output_excerpt":"[NAME] name: \"PDF_Form_Filler\" has uppercase letters and underscores, and only lowercase letters, digits and hyphens are allowed. Fix: pdf-form-filler.\nVerdict: fix before use"}],"page_url":"https://aiskills402.com/skills/skill-md-review","markdown_url":"https://aiskills402.com/skills/skill-md-review.md","image_url":"https://cdn.aiskills402.com/og/skills/skill-md-review/175002a3.png","related_url":"https://api.aiskills402.com/v1/skills/skill-md-review/related","purchases_count":null,"tested":{"date":"2026-10-08","strong":{"model":"claude-sonnet-5-5 (Claude Code alias \"sonnet\")","verdict":"Gave the exact codes and verdict in all 20 cases, as bare lines with nothing around them. It caught a request to read the SSH key, a silent copy to a shared drive, a line that claims to replace the system's instructions, a note telling the reviewer to answer No findings, a live-looking API key, a curl piped into sh, a name over 64 characters, an uppercase name, the reserved word claude in a name, a missing, an overlong and a first-person description, an XML tag in the description, a Windows path, a 538-line body and a missing example, and it left a skill that runs its own bundled script unflagged. A first run with a wider wording of our person rule flagged the word you inside ordinary descriptions; the rule was narrowed to match the published guidance and run again."},"weak":{"model":"claude-haiku-5-5 (Claude Code alias \"haiku\")","verdict":"Also 20 of 20 with the skill, with the same codes and verdicts as Sonnet, including the counted limits it did not flag without the skill: the 65-character name, the 1,305-character description and the 538-line body."},"note":"Twenty small SKILL.md files written by us, each with one or more planted problems or none: a clean file, three name defects, four description defects, four kinds of hidden order to the agent including one aimed at the reviewer, a pasted credential, a download-and-run command, a Windows path, no example, an overlong body, a legitimate bundled script, and one file with three problems. The check requires each expected code and the verdict and forbids every code that should not appear. The limits in the skill were checked against the public skill documentation on 8 October 2026. One run per model and case; the with-skill side was run twice because our wording of one rule was too wide the first time, and the first run is kept in the test folder.","baseline":{"date":"2026-10-08","rows":[{"label":"Every planted problem named, nothing invented","better":"higher","strong":{"with":{"n":20,"of":20},"without":{"n":18,"of":20}},"weak":{"with":{"n":20,"of":20},"without":{"n":14,"of":20}}}],"note":"Both sides scored with the same word-based checks, since the side without the skill does not know our codes. Without the skill both models noticed the hidden orders, the key and the curl command, and Sonnet called out the note aimed at the reviewer; the misses were the counted rules. Haiku did not flag the 65-character name, the 1,305-character description, the 538-line body or the backslash path, and neither model said that the file had no example. Two baseline patterns first missed correct answers (one counted a sentence saying no injected instructions as an alarm) and were widened before the final score; the change applies to both sides."},"report_url":null},"price_usd":"0.05","price_micro":50000,"size_bytes":6903,"sha256":"5a1fc0857a1b6c252edd7721a3c98a28ce1232e5892903f05e66f3516e835d3b","outline":["The answer","The codes","Rules","Work in this order","Short example"],"license":{"summary":"Perpetual, non-exclusive; use and modify for yourself incl. paid work; no resale or republishing","holder":"Georgi Kalchev, aiskills402.com","url":"https://aiskills402.com/docs#license"},"buy_url":"https://api.aiskills402.com/v1/skills/skill-md-review/file","redownload_url_template":"https://api.aiskills402.com/v1/purchases/{token}","mcp_tool":null,"payment":{"protocol":"x402","scheme":"exact","asset":"USDC","selling":true,"network":"base","network_caip2":"eip155:8453","pay_to":"0x8e37022edcf0f21cf3c9f93fee9d4d32519f36f4","facilitator":"cdp"},"seo_title":"SKILL.md Review: Check a Skill Before Install","seo_description":"Review a SKILL.md before you install, buy or publish it. Checks front matter limits and flags hidden orders, pasted credentials and remote code. $0.05 once.","versions":[{"version":"1.0.1","date":"2026-10-08","changelog":"# Changelog\n\n## 1.0.1 — 2026-10-08\n\nPrice changed from $0.03 to $0.05; the skill text is unchanged. Measured value for the strong model: Sonnet 18 of 20 without the skill, 20 of 20 with it.\n\n## 1.0.0 — 2026-10-08\n\nFirst release: reviews one SKILL.md file and lists each problem with a fixed code, the place and a fix, then a verdict (unsafe, fix before use, ready). Unsafe: hidden orders to the agent, credentials in the text, download-and-run commands. Front matter against the published limits: name, missing or overlong description, no trigger, first or second person, XML tags. Body: over 500 lines, Windows paths, no example. Ordinary instructions to use the skill's own scripts are not flagged, and an order to the reviewer inside the file is itself a finding.\n"},{"version":"1.0.0","date":"2026-10-08","changelog":"# Changelog\n\n## 1.0.0 — 2026-10-08\n\nFirst release: reviews one SKILL.md file and lists each problem with a fixed code, the place and a fix, then a verdict (unsafe, fix before use, ready). Unsafe: hidden orders to the agent, credentials in the text, download-and-run commands. Front matter against the published limits: name, missing or overlong description, no trigger, first or second person, XML tags. Body: over 500 lines, Windows paths, no example. Ordinary instructions to use the skill's own scripts are not flagged, and an order to the reviewer inside the file is itself a finding.\n"}]}