Reference
Security | Research Agent Skills
How Research Agent Skills protects users from prompt injection, malicious scripts and supply-chain attacks, and how to report vulnerabilities.
Agent skills are instructions and code executed with your agent’s permissions. The repository validates
skill structure, file types and links, scans for prompt injection and suspicious scripts, and restricts
script network domains. Release archives carry checksums for the repository’s installers.
Report a suspected vulnerability through
GitHub private vulnerability reporting.
Include the affected skill, impact and reproduction steps. Read the
full security policy
for supported versions and current controls.