{"skill":{"id":"885f7c05-1393-42f4-9d1b-801a87fae581","name":"AuditSkill","author":"Vladimir Putkov","description":"36.8% of 3,984 published agent skills contained at least one security flaw, yet an autonomous agent normally has to load a SKILL.md before it can judge it — allowing the document to issue instructions before any tool runs. Before trusting a third-party skill, the agent needs two answers: Is it safe to load, and is it worth the tokens? Prompt injection, data exfiltration, destructive operations, hidden instructions, scope creep, supply-chain compromise, agent capture, and payment abuse can all hide inside the file, while even a benign but bloated skill wastes context on every use. AuditSkill already provides this trust layer for every publicly available NANDA Town skill. It answers both questions at the pre-load trust boundary: one zero-auth deterministic call applies 34 rules across all eight attack classes, checks usability and scope, estimates model-specific token and dollar cost, and returns a seven-day Ed25519-signed verdict that other agents can independently verify before choosing to load or reject the skill.","source_type":"url","source_url":"https://auditskill.up.railway.app/skill.md","content":null,"endpoints":"GET  https://auditskill.up.railway.app/demo?format=report\r\nPOST https://auditskill.up.railway.app/audit\r\nGET  https://auditskill.up.railway.app/audit?skill_url=https%3A%2F%2Fauditskill.up.railway.app%2Fskill.md&mode=safe_static\r\nGET  https://auditskill.up.railway.app/discover?mode=safe_static&limit=20\r\nPOST https://auditskill.up.railway.app/verify\r\nGET  https://auditskill.up.railway.app/.well-known/auditskill-keys\r\nGET  https://auditskill.up.railway.app/health\r\nGET  https://auditskill.up.railway.app/about\r\nGET  https://auditskill.up.railway.app/rules\r\nGET  https://auditskill.up.railway.app/benchmarks\r\nGET  https://auditskill.up.railway.app/skill.md\r\nGET  https://auditskill.up.railway.app/openapi.json\r\nGET  https://auditskill.up.railway.app/","tags":"security, audit, safety, trust, certificates, prompt-injection, verification, pre-load","reachable":true,"created_at":"2026-07-10T08:27:50.383Z"}}