Skills
Skill Security Auditor
A practice-area skill: it carries legal knowledge — a doctrine, a regime, a review standard — and applies it to your material.
What this skill does
Audit an AI agent skill before installing it. Use proactively whenever the user is about to add, install, enable, or evaluate an unfamiliar skill — including phrases like "audit this skill", "is this skill safe", "scan skill before install", "check skill for malicious code", "review this plugin", or any pre-install gate on an untrusted, third-party, or community-distributed skill bundle. Runs ten categories of static checks (code execution, network exfiltration, credential harvesting, persistence, prompt injection, supply-chain hooks, obfuscation, destructive filesystem ops, secrets, Trojan Source / homoglyphs) and emits a PASS / WARN / FAIL verdict.
- Security
- Auditor
Free, and published by its author - not by HAQQ. The link leaves this site.
Where it runs, and how to install it
Agent Skills are a format, not a product feature: a folder with a SKILL.md and whatever files it needs. Nothing inside one is model-specific.
- Claude
- Drop the skill folder into ~/.claude/skills/, or upload it in Settings → Capabilities. Claude loads it when the description matches what you asked for.
- Claude Code
- Same folder, per-project instead: .claude/skills/ inside the repository, so the skill travels with the work rather than with the machine.
- Any agent that reads SKILL.md
- A skill is a folder with a SKILL.md and whatever files it needs. Nothing in the format is model-specific, so a runtime that reads the file reads the skill.
More from Antoine Louis
- Tabular ReviewGuide to analyze multiple documents (PDF, DOCX) against user-defined columns and produce a structured Excel output with citations. Use when the user wants to: (1) Extract specific information from multiple documents into a table, (2) Compare clauses or provisions across contracts, (3) Create a document review matrix with source citations.
- Word EditorEdit, query, and transform Word documents (.docx) with the SuperDoc CLI. Use when the user asks to read, search, modify, format, comment, track changes, or review changes in .docx files. Triggers on any task involving Word documents — text replacement, redlining, contract markup, template filling, bulk edits, content extraction, or document review.
- VS Code ExtensionBuild VS Code extensions from scratch or convert existing JS/React/Vue apps. Supports commands, webviews (React/Vue), custom editors, tree views, and AI agent integration via file-bridge IPC. Use when user wants to create a VS Code extension, convert a web app to an extension, add webviews or custom UIs to VS Code, implement tree views, build custom file editors, integrate with AI agents, or packa
Skills that do related work
- Security ReviewPerform language and framework specific security best-practice reviews and suggest improvements. Covers Python, JavaScript/TypeScript, and Go. Use when the user
- Agent Authority Charter BuilderCreates an Agent Authority Charter for enterprise or regulated AI agents before deployment. Use this Skill when a user needs to define what an AI agent is allow
- Agentic Delegation AuditUse when a lawyer, legal team, or client needs to assess AI agents that can act on someone's behalf: send messages, search, draft, file, pay, delete, connect to
- AI Audit TrailThis skill builds a structured audit trail of an AI-assisted task: what the tool was asked to do, what materials it was given, what it produced, how the output
- AI Governance ReviewerConduct AI governance, legal-risk, privacy, compliance, procurement, or vendor-risk reviews of internal AI use cases, AI product features, LLM workflows, or thi
- Ai InventoryEU AI Act per-system inventory — track each AI system's role (provider, deployer, importer, distributor, authorized representative, product manufacturer) and ri