How every package is reviewed
A skill file is not just documentation. It is a set of instructions your agent carries out with your permissions. So every package goes through eight automated checks at upload, before it can be published, and the result is shown on that product's page.
1Package structure
A skill has a SKILL.md with name and description in its header, and no file is empty or unusually large.
2File types
Only text files are accepted. Scripts in the package (py, js, ts, sh) are flagged so they are read before being run.
3Dangerous commands
Recursive deletion, running a script fetched from the network, privilege escalation and disk-level operations.
4Keys and secrets
API keys, private keys, tokens and connection strings with embedded passwords, none of which belong in a package.
5Environment variables
Reading many environment variables, or reading a sensitive one in a file that also makes network requests.
6Network access
The list of referenced domains and patterns that send data out.
7Obfuscation
Long encoded strings, eval and string building used to hide what the code does.
8Hidden instructions to the agent
Instructions to ignore earlier guidance, hide actions from the user or move data out.
Scoring
Every package starts at 100. Each check with a serious finding takes off 30 points and each check that needs attention takes off 8.
Review before publishing
An upload is always a private draft. The creator sees the detailed findings in the studio and decides whether to publish. The public page shows only the status of each check, so the text of a paid product cannot leak through the review.
Where this review stops
The automated review looks for known patterns in the text of the files. It is not a specialist code audit and it does not catch every harmful instruction. Files are never executed on this site. Read a package before you use it, and try it first with sample data and limited access.