agentichighway/vettd-skills
Agent-facing skills for vetting AI skills, MCP servers, and agent configs with vettd.
Use when an agent needs to inventory and audit its own runtime environment for dangerous or untrusted artifacts. WHEN: audit my environment, what's installed, check my MCP servers, is my setup safe, self-audit. DO NOT USE FOR: vetting one skill before installing (use vet-before-install), publishing checks (use pre-publish-self-check), one finding (use triage-a-flagged-finding), or drift over time (use detect-supply-chain-drift).
Use when an agent has only HTTPS access (no vettd binary) and needs to search the public vettd directory, check a skill's grade and findings, or download a skill. WHEN: find a skill without installing anything, is this skill safe (by GitHub URL), look up a skill's grade, download a skill from the directory, browse vettd over HTTP. DO NOT USE FOR: scanning local files (use vet-before-install), auditing your own environment (use audit-my-agent-environment), or anything needing an API key.
Use when a previously-scanned artifact needs to be checked for changes since its last scan — before re-trusting an update, after a dependency bump, or on a schedule. WHEN: has this changed, did this skill change, re-scan after update, verify no drift, monitor for tampering. DO NOT USE FOR: scanning an artifact the first time (use vet-before-install) or triaging one finding (use triage-a-flagged-finding).
Use when a user or agent needs to find an existing skill that performs a task, before writing one from scratch or grabbing the first search result. WHEN: find a skill for X, is there a skill that does X, search the skill directory, which skill should I use, compare candidate skills for safety. DO NOT USE FOR: scanning a skill you already downloaded or chose (use vet-before-install), auditing your own local agent environment (use audit-my-agent-environment).
Use when a skill author has finished writing or editing a skill and wants to check it before pushing to GitHub, opening a PR, or sharing it. WHEN: before publishing a skill, before pushing to GitHub, self-review of a skill I wrote, checking my own skill directory. DO NOT USE FOR: scanning someone else's skill before installing (use vet-before-install), or an environment sweep (use audit-my-agent-environment).
Use when the vettd binary is missing, unauthenticated, or unreachable, or when a command from another vettd skill fails because vettd itself isn't set up. WHEN: vettd not found, command not found vettd, install vettd, configure vettd, vettd auth, connection refused from vettd, vettd endpoint wrong. DO NOT USE FOR: scanning anything (use vet-before-install or audit-my-agent-environment).
Use when handed one or more specific scan findings and needing to decide whether to remediate, remove, or accept-with-justification. WHEN: triage this finding, what do I do about this flagged rule, decide on this security finding, handed a finding from vettd, resolve this flagged rule ID. DO NOT USE FOR: running the initial scan that produces findings (use vet-before-install or audit-my-agent-environment), or searching for a new skill to install (use find-a-safe-skill).
Use when about to install, adopt, or wire in a skill, MCP server, or agent config from an external source. WHEN: install this skill, add this MCP server, adopt this agent config, pull in this skill, before trusting a new integration. DO NOT USE FOR: artifacts already live (use audit-my-agent-environment), your own skill before publishing (use pre-publish-self-check), or findings you already have (use triage-a-flagged-finding).