Skip to content

agentichighway/vettd-skills

v0.1.0MIT

Agent-facing skills for vetting AI skills, MCP servers, and agent configs with vettd.

audit-my-agent-environment

Use when an agent needs to inventory and audit its own runtime environment for dangerous or untrusted artifacts. WHEN: audit my environment, what's installed, check my MCP servers, is my setup safe, self-audit. DO NOT USE FOR: vetting one skill before installing (use vet-before-install), publishing checks (use pre-publish-self-check), one finding (use triage-a-flagged-finding), or drift over time (use detect-supply-chain-drift).

browse-directory-api

Use when an agent has only HTTPS access (no vettd binary) and needs to search the public vettd directory, check a skill's grade and findings, or download a skill. WHEN: find a skill without installing anything, is this skill safe (by GitHub URL), look up a skill's grade, download a skill from the directory, browse vettd over HTTP. DO NOT USE FOR: scanning local files (use vet-before-install), auditing your own environment (use audit-my-agent-environment), or anything needing an API key.

detect-supply-chain-drift

Use when a previously-scanned artifact needs to be checked for changes since its last scan — before re-trusting an update, after a dependency bump, or on a schedule. WHEN: has this changed, did this skill change, re-scan after update, verify no drift, monitor for tampering. DO NOT USE FOR: scanning an artifact the first time (use vet-before-install) or triaging one finding (use triage-a-flagged-finding).

find-a-safe-skill

Use when a user or agent needs to find an existing skill that performs a task, before writing one from scratch or grabbing the first search result. WHEN: find a skill for X, is there a skill that does X, search the skill directory, which skill should I use, compare candidate skills for safety. DO NOT USE FOR: scanning a skill you already downloaded or chose (use vet-before-install), auditing your own local agent environment (use audit-my-agent-environment).

pre-publish-self-check

Use when a skill author has finished writing or editing a skill and wants to check it before pushing to GitHub, opening a PR, or sharing it. WHEN: before publishing a skill, before pushing to GitHub, self-review of a skill I wrote, checking my own skill directory. DO NOT USE FOR: scanning someone else's skill before installing (use vet-before-install), or an environment sweep (use audit-my-agent-environment).

setup-vettd

Use when the vettd binary is missing, unauthenticated, or unreachable, or when a command from another vettd skill fails because vettd itself isn't set up. WHEN: vettd not found, command not found vettd, install vettd, configure vettd, vettd auth, connection refused from vettd, vettd endpoint wrong. DO NOT USE FOR: scanning anything (use vet-before-install or audit-my-agent-environment).

triage-a-flagged-finding

Use when handed one or more specific scan findings and needing to decide whether to remediate, remove, or accept-with-justification. WHEN: triage this finding, what do I do about this flagged rule, decide on this security finding, handed a finding from vettd, resolve this flagged rule ID. DO NOT USE FOR: running the initial scan that produces findings (use vet-before-install or audit-my-agent-environment), or searching for a new skill to install (use find-a-safe-skill).

vet-before-install

Use when about to install, adopt, or wire in a skill, MCP server, or agent config from an external source. WHEN: install this skill, add this MCP server, adopt this agent config, pull in this skill, before trusting a new integration. DO NOT USE FOR: artifacts already live (use audit-my-agent-environment), your own skill before publishing (use pre-publish-self-check), or findings you already have (use triage-a-flagged-finding).