Scan a skill before you install it
A skill is a prompt your agent will follow. Paste the GitHub URL of any public skill — the repository, or the link to its folder — and we run the same deterministic prompt-injection screen every listing here goes through: hidden characters, chat-role and system-prompt markers, instruction overrides, and credential paths near a network call. No model reads it, so nothing in it can talk its way past.