Agent Skill Security Audit: $49
$49 flat. A security audit of one Claude Code agent skill: its SKILL.md, scripts, and bundled files, scanned with dedicated agent-skill scanners plus manual review.
What you get
A findings report on your skill covering:
- Secret and credential exposure: hardcoded API keys, tokens, passwords, or paths that leak them
- Prompt-injection surface: places where untrusted content (tool output, web pages, user files) can steer the skill’s behavior
- Unsafe execution: shell commands built from untrusted input, unpinned downloads, install steps that run code on sight
- Overbroad permissions: file, network, or credential access the skill does not need for its job
- Data handling: what the skill reads, writes, or sends, and where it goes
Each finding names the file and line, carries a severity (critical / high / medium / low), and includes a concrete fix recommendation.
Scope
- One skill directory, up to 30 files
- SKILL.md, scripts, configs, and bundled assets inside it
- Scanners used: Cisco skill-scanner and Snyk agent-scan, plus manual review of everything the scanners flag and a read-through of SKILL.md
Not included
- Fixing the code (a separate service)
- Auditing anything outside the skill directory
- Penetration testing of a live deployment
- Legal or compliance certification of any kind
How it works
- You submit the intake form below with your skill files or a repository link.
- We run the scanners and a manual review pass.
- Report delivered typically within 3 business days as markdown, by email. More than 5 business days late triggers a full refund (see Refunds).
- One clarification round included within 7 days of delivery.
Questions at any point: reply to any email about your order.
Intake form (fields)
| field | required | notes |
|---|---|---|
| yes | delivery and the clarification round go here | |
| skill_files | yes | zip upload of the skill directory, or public repo URL + skill path |
| what_it_does | yes | one or two sentences on the skill’s job |
| known_concerns | no | anything that already worries you |
Acceptance checklist
The report passes if and only if:
- Every file in the submitted skill directory appears in the report’s coverage list
- Each finding names the exact file and line where the issue lives
- Every finding carries a severity, and the severity scale is defined in the report
- Every high or critical finding includes a concrete fix recommendation
- The report states which scanner version or manual pass produced each section
Every deliverable passes a second-model review against the acceptance checklist before it reaches you.
AI disclosure
This service is performed with AI assistance, including automated scanners and AI review. Every deliverable passes a second-model review against the acceptance checklist before it reaches you. Read the full AI disclosure page.
Refunds
- Delivery more than 5 business days late: full refund, no questions asked.
- A file in scope is missing from the coverage list: free re-run covering it, or a full refund if you prefer.
- If the report is not useful, tell us within 7 days of delivery and we will re-run the audit once or refund you. Your choice.