For creators
Prepare a skill for security review
Submit instructions a reviewer can inspect, with clear data destinations and approval boundaries.
Quick answer
Before submitting, inspect every step that reads private information, sends data, installs software, or changes an external system. Remove secrets and explain legitimate dependencies plainly. Skillset scans each submission and requires human review before publication; a clean scan alone does not publish a skill, and still-blocked instructions cannot be approved.
Review the final text as a data journey
Take a fictional campaign-summary workflow that reads a supplied CSV, groups campaign results, and drafts an explanation. List the data it receives, where analysis happens, and what leaves the conversation. If the method asks the AI to send the CSV to an outside service, explain that destination and why it is needed.
A named dependency is not consent to use it. The buyer must supply the data or authorize the relevant connection in their AI app. Consider whether a pasted summary can satisfy the first version without introducing another service. Never include a working credential just to make a demonstration easier.
Check examples as carefully as instructions
A copied terminal command, sample configuration, or customer note can introduce risk even when the main procedure is reasonable. Replace real secrets with obvious placeholders. Inspect commands that read environment variables, retrieve remote code, or send requests to a network address. Do not disguise an action to make a scan stop detecting it.
Outside source material can contain instructions designed to redirect an AI. OWASP describes indirect prompt injection through external content. Tell the workflow to treat a campaign note or webpage as evidence, not as authorization to ignore the user’s task or send their information elsewhere.
Source: OWASP: prompt injection
Give important actions a review checkpoint
For the campaign example, the default deliverable can be a report draft, missing-data notes, and proposed next steps. Publishing the report or changing ad spend is a separate action requiring the user’s approval. Write that boundary next to the action, where it will be encountered during the procedure.
Test an ordinary CSV, a file missing a necessary column, and a note containing an unrelated instruction to export data. The last case should not become a new task. Record the observed result and fix the instructions if the boundary is unclear.
Understand the submission outcome
Use Save draft for unfinished work and Submit for review for the candidate you want assessed. A blocked scan rejects the candidate; other submissions enter review. Read the scan findings in Versions and review, correct the underlying issue, and submit an improved version rather than trying to hide the flagged text.
Approval also requires verified creator payment onboarding before a new skill can go live, including a free listing. This is separate from the safety decision. A published Pass status means the listing cleared the platform’s process; it does not guarantee every future input, host app, or external action is safe.
Common questions
May I use a legitimate external API?
Yes, with a clear purpose, stated dependency, and appropriate user authorization. Explain what information is sent; do not embed credentials in the skill.
Can an administrator approve a blocked version anyway?
No. Still-blocked content must be corrected. A reviewer can assess findings, but the workflow prevents publishing an instruction set that remains blocked.
Does passing review certify my skill’s results?
No. Security review and usefulness are different questions. Test the promised output separately and avoid presenting a review badge as a measured success rate.
Put a workflow to work.
Connect your library to your AI, or turn your method into a skill.