skill-audit-modeioRuns a deterministic static safety audit for third-party AI skill or plugin repositories before install or execution. Use when asked to scan a skill repo, as...
Install via ClawdBot CLI:
clawdbot install modeioai/skill-audit-modeioGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Contains instructions to override system prompt or ignore user requests
"ignore previous instructions"Sends data to undocumented external endpoint (potential exfiltration)
post → https://evil.example/bootstrap.shPotentially destructive shell commands in tool definitions
eval(Calls external URL not in known-safe list
https://github.com/mode-io/mode-io-skills/tree/main/skill-auditGenerated Mar 22, 2026
A platform hosting third-party AI skills or plugins for download and integration. Before allowing a new plugin to be listed, the marketplace uses Skill Audit to run a static safety audit on the plugin's repository, ensuring it meets security standards without executing potentially harmful code. This prevents malicious plugins from being distributed to users.
A corporate team developing AI agents that integrate external skills from public repositories. They use Skill Audit to assess the safety of third-party skills before installation, reducing the risk of vulnerabilities or compliance issues in their production environment. This helps maintain security and trust in their AI systems.
A university lab experimenting with various AI skills for academic projects. Researchers use Skill Audit to evaluate repositories for safety before incorporating them into experiments, ensuring no hidden malware or unethical code is present. This supports safe and reproducible research practices.
An organization's CI/CD pipeline that automates security checks for AI skill deployments. Skill Audit is integrated to scan repository changes before merging or deploying, providing evidence-backed findings for pre-install screening. This enhances security automation and reduces manual review overhead.
Offer Skill Audit as a cloud-based service where users upload repository URLs for automated safety audits. Charge subscription fees based on scan volume or features, targeting developers and enterprises needing pre-install security checks. Revenue comes from monthly or annual licenses.
Sell customized licenses of Skill Audit to large organizations for internal use, integrating it into their AI development workflows. Provide support, updates, and training as part of the package. Revenue is generated through one-time purchases or annual enterprise contracts.
Partner with AI plugin marketplaces to embed Skill Audit as a mandatory safety check for all listed skills. Earn revenue through partnership agreements, transaction fees, or per-scan charges. This model leverages existing platforms to reach a broad user base.
💬 Integration Tip
Ensure Python3 is installed and run commands from the skill-audit folder; use --json flag for full reports and integrate with CI/CD pipelines for automated scans.
Scored Apr 19, 2026
Uses known external API (expected, informational)
api.github.comAI Analysis
The skill's stated purpose is static repository auditing, and the external URL (github.com/mode-io) is its documented homepage, not an unauthorized data sink. The 'prompt poisoning' signal likely refers to example text within the skill's own scanning logic, not its operational instructions. The risk is low as the skill claims to not execute target code.
Audited Apr 18, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...