- Why vet skills at all?
- Because the marketplace is measurably hostile: Snyk's ToxicSkills audit (Feb 2026) found 76 confirmed malicious payloads across 3,984 public agent skills, with 13.4% carrying at least one critical flaw. Free scanners detect; what nobody ships is the decision procedure — who approves adoption, what gets rotated after exposure, when a skill must be re-vetted. That procedure is this pack.
- Does the scanner approve or reject a skill?
- No. It records files, digests, capability signals, and a provisional tier so a human reviewer can inspect the relevant source and own the decision. A low tier is not proof of safety.
- Does it execute the skills it reviews?
- No. Inventory, assessment, and comparison read bounded local files without following symlinks, installing packages, calling a network service, or running the reviewed code.
- What changes trigger another review?
- Source digest, dependency, install hook, tool, permission, network domain, secret access, runtime, ownership, incident, and approved-use changes are all explicit re-vetting triggers.
- How is it delivered?
- After Stripe verifies the exact current payment, the browser opens the checksum-matched private ZIP and the same recovery link is sent by email. Refunds and disputes withdraw access.