docs/analysis-pipeline

Understanding Skill Verification

What You Get

When you submit a skill for verification, we run it through a comprehensive security analysis to answer one simple question: Is this safe to use?

📊

Trust Score

A simple 0-100 score showing how safe the skill is. Higher is better.

⚠️

Risk Level

Clear verdict: Safe, needs review, fix required, or do not use.

🔍

Detailed Report

Specific security issues found, exactly where they are, and how to fix them.

How It Works

Your skill goes through 4 security checks:

1. Pattern Detection (YARA)

Scans for known malicious patterns like hardcoded passwords, command injection attempts, and prompt hijacking. Think of it as antivirus for AI skills.

2. Intelligence Analysis (LLM)

An AI reads the entire skill to understand what it's trying to do. Catches sophisticated attacks that hide using clever tricks.

3. False Positive Filter

Double-checks all findings to remove false alarms. We don't want to flag safe code that just happens to contain certain keywords.

4. Live Testing (Sandbox)coming soon

Actually runs the skill in an isolated environment to see what it does. Catches threats that only appear during execution.

Understanding Your Results

ScoreRisk LevelWhat It MeansWhat To Do
80-100LOWNo serious security issues foundSafe to use
60-79MEDIUMSome concerns, but nothing criticalReview findings first
40-59HIGHSerious security risks detectedFix issues before using
0-39CRITICALDangerous vulnerabilities foundDo not use

Pro tip: A score of 80 or higher means the skill passed all major security checks. Anything lower means we found issues that need your attention.

Quick Start

1

Submit Your Skill

Go to the verification page and paste your skill URL or text.

2

Wait for Analysis

Our analysis runs automatically. You'll see progress as each check completes.

3

Review Results

Check your trust score and read any security findings. Each issue includes exactly where it is and how to fix it.

Learn More