iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Before installing an agent skill or letting it work with files, review the complete package as you would a code change: define what the task requires, inspect instructions and executable components, trace their capabilities, and grant only the access needed. A skill’s own assurances are not a security boundary; runtime permissions and review must remain independent of its instructions.
Why a skill deserves a code-level review
An agent skill is not necessarily just a prompt. It may bundle instructions, scripts, dependencies, configuration, and supporting resources that affect what an agent can do. Instructions are also an attack surface: a skill, repository file, pull-request comment, screenshot, or tool output can contain directions designed to redirect the agent or expose data.
Treat the contents as untrusted evidence, not authorization. OpenAI’s prompt-injection guidance recommends limiting an agent to the data it needs: OpenAI prompt-injection safety guidance. Codex policy guidance likewise classifies skills and tool outputs as untrusted evidence: Codex prompt-injection guidance.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteReview the skill before installation or access
1. Define the task and its boundary
Write down the specific job the skill should perform and the files, tools, network destinations, and data it genuinely needs. A narrow task definition makes it easier to spot instructions or permissions that broaden the work beyond the user’s request.
#1 Best Overall
2. Inventory the complete package
Inspect the metadata and full instruction file, every referenced resource, scripts, dependencies, configuration, install or setup steps, and the changes since the last revision. Do not rely on a README or author summary. Agent skills can include executable scripts and supporting files; coding-agent setups may also include hooks, MCP declarations, and other configuration. See the Agent Skills specification and Codex configuration reference.
3. Read instructions as untrusted content
Check for directions to ignore earlier instructions, change the task, hide actions, reveal secrets, access unrelated files, or transmit data. Compare each direction with the user’s request. A skill cannot authorize itself to take actions the user did not authorize.
4. Trace capabilities and side effects
For each script, dependency, tool declaration, or setup action, determine what it can read, write, execute, or send. Check which identity and credentials it can use, where network requests go, whether dependencies are pinned, and whether a broad permission effectively enables arbitrary execution. For workflows, inspect how untrusted values enter shell commands: Codex Action security guidance warns that inserting untrusted GitHub expressions directly into shell scripts can break quoting and execute commands. See Codex Action security guidance.
Use this checklist while tracing behavior:
- Files: Which paths can be read, changed, or deleted? Are access patterns broader than the task requires?
- Processes: Can the skill run shell commands or launch other programs? Are command arguments influenced by untrusted input?
- Network: Which destinations can it contact, and what data could leave the environment?
- Secrets and identity: Can it access credentials, tokens, environment variables, or an identity with broader privileges?
- Dependencies and configuration: Are versions pinned? Do hooks, MCP declarations, or setup steps add capabilities not obvious from the instructions?
5. Compare access with the task
Remove capabilities that are not needed. Start with read-only access or no network access where practical, then add narrowly scoped write or outbound access only if the task requires it. A permission declaration describes a request; it is not enforcement. Codex Action documentation explains that permission profiles constrain commands but do not replace process-level privilege controls. Its guidance is to select the narrowest filesystem and network policy that still completes the task: Codex Action security guidance.
6. Test uncertain behavior in isolation
If static inspection cannot establish what a script or dependency does, run it in an isolated environment with non-sensitive sample data and no real credentials. Observe file, process, and network activity, then compare it with the skill’s stated purpose. Isolation and independent boundaries are supported by the cited guidance, but there is no universal test harness specified for every platform; choose controls appropriate to your environment.
7. Keep review at the runtime tool boundary
Before consequential tool calls, validate the target, action, arguments, identity, and scope. Route ambiguous or high-risk actions for human approval, record the decision, and fail closed if review is unavailable. Agent-level checks alone may not cover every tool call, especially in a multi-agent workflow. OpenAI’s API guide recommends evaluating each sensitive tool call before execution in authorized cybersecurity workflows: OpenAI guardrails and human review guidance.
8. Record the reviewed revision
Keep a record of the exact revision, findings, permissions required, mitigations, and unresolved uncertainty. Re-review when instructions, scripts, dependencies, or permissions change. This record-keeping approach is a practical recommendation based on supply-chain and permission risks, not a universal prescribed format.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →What published security studies can—and cannot—tell you
Two 2026 studies illustrate why package review is worth doing, but their rates describe particular datasets and detection methods; they are not estimates of the chance that a specific skill is unsafe.
Best Value
| Study | Reported result | How to interpret it |
|---|---|---|
| Yi Liu and coauthors, 2026 | 26.1% of 31,132 analyzed agent skills contained at least one vulnerability pattern. The study examined 14 patterns spanning prompt injection, data exfiltration, privilege escalation, and supply-chain risks; its method reported 86.7% precision and 82.5% recall. | These are results for the study’s corpus and method, not a universal failure rate or a guarantee that a scanner will perform similarly on another collection. |
| Benjamin Kapner and coauthors, 2026 | 16.0% of 2,660 multi-component setups had a confirmed security defect, in a study covering 3,171 public repositories. Examples included unpinned MCP versions, overly broad execution grants, and skills that pre-approved shell access. | The result is bounded by the repositories and rule set studied; it does not establish the safety of an individual skill. |
Use such findings as motivation to inspect what a package actually does, not as a verdict about a particular author or skill. Static findings need evidence you can inspect, and any high-impact concern should be validated independently where possible.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

