Before an AI agent runs a Skill, make the evidence stronger than the marketing.
Most static checks can tell you what looks suspicious. Production readiness also requires installation, real tool invocation, approvals, failure recovery and repeatable results. Here is a usable release gate, not a promise of perfect security.
1. Verify the package before executing anything
Inventory every script and asset, preserve originals and SHA-256 hashes, validate SKILL.md metadata and check links, licensing and compatibility. Treat hidden binaries and symlinks as review tasks, not automatically safe content.
2. Scan deeply, then review the findings
Run independent tooling such as Cisco Skill Scanner. Its free analyzers inspect more than a single pasted Markdown file. Then inspect suspicious network, credential and execution paths yourself; a clean static report is not a runtime certificate.
3. Run real authorized tests on your target platform
- Read-only task: correct result and no unexpected side effect.
- Approval gate: simulate publish/delete/payment and confirm the agent stops before it acts.
- Recovery: simulate one timeout and replay, verify bounded retries and no duplicate operation.
- Rollback: disable the skill and prove the host no longer invokes it.
4. Measure buyer value against the strongest free option
On identical test cases, count true/false alerts, critical misses, setup minutes, task completion rate, human intervention and full cost. Document the exact host, versions and hardware. If a paid kit does not make the complete buyer workflow measurably easier or more reliable, do not market it as superior.
What is available here today?
| Free resource | Verified purpose |
|---|---|
| Browser preflight | Quick static pattern checks on pasted SKILL.md. Local processing in the browser, not a full security scanner. |
| Human Gate Router | Readable skill instructions separating automated, assisted and owner-only steps. |
| Release checklist | Free four-stage acceptance process with limitations clearly stated. |
Expanded professional kit: under independent comparative and platform testing, not currently for sale. No prices, checkout links or reservation list.
Guía práctica en español
Antes de utilizar una skill con tu agente: inventaría archivos y licencias, valida su estructura, analiza riesgos con una herramienta independiente como Cisco Skill Scanner y revisa manualmente los hallazgos. Después prueba la ejecución real en tu plataforma con datos sintéticos.
- Una tarea de lectura sin efectos secundarios.
- Una acción sensible simulada que se detenga antes de ejecutarse y solicite aprobación.
- Un fallo transitorio y una repetición controlada sin operaciones duplicadas.
- Desactivación y restauración comprobadas.
Compara los mismos casos con alternativas gratuitas antes de afirmar una ventaja. El kit ampliado aún no se vende. La herramienta gratuita es una revisión preliminar, no una certificación de seguridad.