Skip to main content
Agent skills are instructions and code executed with your agent’s permissions. The repository validates skill structure, file types and links, scans for prompt injection and suspicious scripts, and restricts script network domains. Release archives carry checksums for the repository’s installers. Report a suspected vulnerability through GitHub private vulnerability reporting. Include the affected skill, impact and reproduction steps. Read the full security policy for supported versions and current controls.