Skip to content
TrustedSkillsbeta
Developer

The Automated Safety Pass: What "Checked" Actually Means

Exactly what the TrustedSkills automated safety scan looks for in every skill — credential access, undeclared network calls, obfuscated payloads, pipe-to-shell installers — how it decides, and what it cannot tell you.

Last updated 27 September 2026

⚡ Quick Answer

Checked means we pulled the skill's files at a specific commit and statically scanned them for six things: a manifest that parses, no reads of credential stores, no network calls to undeclared hosts, no encoded payloads that get executed, no curl … | sh installers, and a recorded commit SHA. Every individual result — pass or fail, with the line that decided it — is printed on the skill's page. It is a machine reading code. Nobody ran the skill, and nothing here says it is any good.

Most skill directories tell you how many people installed something. That is a popularity number, not a safety signal. The question you actually have before you let a skill run inside your agent is narrower: does this thing read my keys, and does it phone somewhere I didn't agree to? Those two questions can be answered by a machine, on every skill, every day — so we do that, and we publish the working.

Why the old badges meant nothing

Until this pass shipped, 92% of the catalogue carried a "Community" badge. That was not a review. It was the fallback value in the crawler — the label a skill got when nothing was known about it. Any directory can generate a badge like that, which is exactly why a badge like that is worthless.

The rule now: a tier states something a reader could check for themselves, and the page shows what it is based on.

The tiers

TierWhat it assertsWho decides
ListedThe skill exists, we resolved where it comes from, and we recorded how to install it. Nobody looked at the code.Automatic
CheckedPassed all six automated checks below, at a named commit.Automatic, re-run as the upstream repository moves
PinnedInstalls resolve to one recorded commit rather than whatever the repository holds today.Automatic, where we hold a snapshot
OfficialPublished by the GitHub organisation that builds the underlying product. A statement about the publisher, not the code.Organisation matching
FeaturedAn editorial pick — a good place to start. Not a security claim.Us, by hand

A skill carrying Official or Featured still gets scanned, and its check results still appear on its page. Who published a skill and what its code does are different questions.

The six checks

1. Declares what it does

SKILL.md exists, its YAML frontmatter parses, and it carries a name and a description with a real body behind it.

Fails when: there is no manifest, the frontmatter is malformed, or the entry is a stub with nothing to review. A skill that cannot say what it does cannot be checked against what it does.

2. No undeclared network calls

Every host the skill dials must be either well-known infrastructure — package registries, GitHub, first-party model APIs — or declared in its own frontmatter (allowed-domains).

Fails when: a script, a config endpoint, or a command the manifest tells the agent to run contacts a host outside that set. The skill page lists the hosts and the exact lines.

Does not fail on: links in documentation. A README that links to react.dev is not contacting react.dev. Counting links as calls is the difference between a check and a noise generator.

3. No obfuscated payloads

Looks for the shapes used to hide code from a reader: base64 or hex blobs that get decoded and executed, eval(atob(…)), exec(compile(…)), PowerShell -EncodedCommand, strings assembled from character codes, long encoded literals.

Passes: ordinary encoding. base64.b64encode(data) on its way into a request body is normal work; decoding a blob and running it is not.

4. No credential access

Flags reads of SSH private keys, ~/.aws/credentials, gcloud and Kubernetes config, ~/.npmrc tokens, .netrc, stored git credentials, the GitHub CLI token store, OS keychains and credential managers, GnuPG keyrings, password-manager vaults, browser cookie and login databases, crypto wallet files, and environment files outside the project.

It also flags the exfiltration shape directly: the environment being dumped into an outbound request on one line.

And it reads the instructions, not just the code. For an agent skill the prose is the payload — a manifest that tells the agent to read ~/.ssh/id_rsa and post it somewhere is dangerous even though it ships no code at all. So SKILL.md prose is scanned for credential paths next to imperative verbs. A README that warns you never to commit your .env is documentation and does not fail.

5. No pipe-to-shell installers

curl … | sh, bash <(curl …), iwr … | iex, pip install straight from a URL: anything that fetches code at run time and executes it unseen. Checked in the code and in the manifest's instructions.

Passes: npm install, pip install ruff, and other installs that resolve through a package registry.

6. Pinned to a commit

The result records the repository and the exact commit SHA that was read, and the skill page links to it. Without that, "we scanned it" refers to nothing in particular — the repository may have changed an hour later.

What the scan cannot tell you

This is the part most badge systems leave out.

  • It does not run the skill. Behaviour that only appears at run time is invisible to it.
  • It does not read dependencies. A clean skill that installs a compromised npm package is still a problem.
  • It cannot judge intent. A skill can pass every check and still be useless, wrong, or subtly bad advice to an agent.
  • It can be evaded. Static analysis catches known shapes. A novel encoding, or a payload pulled from a host that looks like infrastructure, can get through — which is why Checked is a floor, not an endorsement.
  • A failure is not an accusation. Plenty of flagged skills are honest tools that talk to their own API without declaring it. Read the finding; it names the file and the line.

When a skill cannot be scanned

Some skills show no check results at all. The usual reasons: the upstream repository was deleted or made private, the skill's directory was renamed or removed after the registry indexed it, or the repository has no SKILL.md. Those skills stay Listed. We would rather show nothing than imply a check that never ran.

How often it runs

The scan runs daily and is incremental: a repository whose head commit hasn't moved keeps its stored result, and one that has moved is re-read and re-scanned. Because the tier is recomputed from the stored results on every build, a skill that stops passing loses the Checked label rather than keeping a badge it earned six months ago.

If you think a result is wrong

Both directions are worth reporting. A false pass is a defect in the checks; a false failure means an honest skill is being misrepresented. Open a report on GitHub with the skill slug and the commit shown on its page.

Skill authors: the cheapest way to pass the network check is to declare your own hosts in your frontmatter. allowed-domains is read as a declaration, and a declared host is not a finding.


Frequently Asked Questions

Does "Checked" mean a skill is safe?

No. It means six specific dangerous patterns were not found in the code as published at a named commit. It is a floor. Nobody ran the skill, and no human reviewed it.

Why did a skill I trust get flagged?

Most often because it calls its own API and does not declare that host in its frontmatter. The finding on the skill page names the file, the line and the host, so you can judge it yourself in about ten seconds.

Do Official and Featured skills get scanned?

Yes. Every skill we can resolve to a repository is scanned, whatever its tier, and the results are shown on its page.

Is the scanner open to inspection?

The checks are described above in the same terms the scanner implements them, including what each one deliberately ignores. If a description here and the result on a skill page disagree, that is a bug worth reporting.

TT

TrustedSkills Team

The TrustedSkills team maintains the TrustedSkills index of AI agent skills. The index records where each skill comes from and how to install it. It does not review or audit skill code.