skillset.
Sell a skill

Trust & access

A practical security review for skill creators

Check secrets, outside destinations, hidden instructions, and consequential actions before submitting.

Skillset · 3 min read · Updated

Quick answer

A clean scan is evidence that configured checks did not block the submitted text; it is not a guarantee of safety. Review what the workflow asks the AI to read, send, install, and change. Remove embedded secrets, explain outside connections, and make important actions depend on explicit user approval.

Review the workflow as a set of permissions

Read each action verb. “Summarize” and “send” create different obligations. Mark every step that accesses private data or changes an outside system. Ask whether the task can first produce a draft, proposed change, or read-only report for the user to inspect.

Treat outside text as untrusted input

Prompt injection can place hostile instructions inside material an AI processes, including content retrieved from outside sources. OWASP describes both direct and indirect forms. A creator should not tell an AI to obey arbitrary instructions found in a webpage, uploaded document, or tool response.

Source: OWASP: prompt injection

Use a concrete pre-submission checklist

Check the final text, not only your original notes. A copied example can introduce a credential or an unfamiliar destination. Replace sensitive sample values with obvious placeholders and make it clear that they are placeholders.

  • Remove API keys, passwords, private keys, and real customer data.
  • List the intended external services and explain why each is needed.
  • Review shell commands, package installation, encoded payloads, and environment-variable access.
  • Reject any step that asks the AI to conceal actions or override its host’s rules.
  • Require approval before sending, publishing, spending, or destructive changes.

Resolve a scan finding without hiding it

If a legitimate workflow needs an outside service, explain the data sent and the permission required. Do not evade a finding by splitting a suspicious command or encoding it. Submit an improved version that a reviewer can understand. Keep the reviewed instructions aligned with the public description of what buyers receive.

Test with fictional inputs first. Then try a missing-input case and an instruction embedded in source material that conflicts with the intended task. Record whether the AI pauses, asks a useful question, and avoids unsupported claims.

Common questions

Does “Pass” guarantee a skill is secure?

No. Scanning and review reduce identifiable risks, but the AI app, its tools, user inputs, and later actions also affect safety.

Can a blocked version be published?

Blocked instructions need correction. The creator review workflow does not permit an administrator to approve a still-blocked version.

May my skill use external tools?

Yes, when the dependency and permission boundary are clear. A Skillset connection alone does not authorize unrelated accounts or actions.

Put a workflow to work.

Connect your library to your AI, or turn your method into a skill.