askill
skill-decompile

skill-decompileSafety 92Repository

Decompile any SKILL.md into deterministic YAML for structural security analysis. Extracts permissions, surfaces, risk signals, and produces a scored verdict.

1 stars
1.2k downloads
Updated 3/20/2026

Package Files

Loading files...
SKILL.md

Skill Decompile — SKILL.md Security Scanner

Converts freeform SKILL.md files into normalized, machine-auditable YAML structures. Bridges the gap between human-authored skill definitions and deterministic security scanning.

Usage

# Single file
python3 ~/.agents/skills-db/security/skill-decompile/decompile.py ~/.agents/skills/auth-sniffer/SKILL.md

# Single file, JSON output
python3 ~/.agents/skills-db/security/skill-decompile/decompile.py ~/.agents/skills/auth-sniffer/SKILL.md --output json --verbose

# Scan entire skills directory with summary report
python3 ~/.agents/skills-db/security/skill-decompile/decompile.py --dir ~/.agents/skills/ --report

# Full directory scan as YAML
python3 ~/.agents/skills-db/security/skill-decompile/decompile.py --dir ~/.agents/skills/ --output yaml

What It Extracts

CategoryDetails
metaname, description, skill_type, source (local/external)
permissionsallowed_tools, requests for bash/write/network/env
surfacesURLs, shell commands, env vars, file paths
risk_signalseval, base64, obfuscation, exfil patterns, prompt injection
complexityline count, code blocks, reference files, decision tree depth
verdictrisk_score (0-100), risk_level, specific flags

Risk Scoring

  • 0-20: safe — no concerning patterns
  • 21-40: low — minor signals, likely benign
  • 41-60: medium — review recommended
  • 61-80: high — manual audit required
  • 81-100: critical — block until reviewed

When to Use

  • Before installing a third-party skill
  • Periodic security audit of skill inventory
  • CI/CD gate for skill contributions
  • Comparing skill versions for permission drift

Install

Download ZIP
Requires askill CLI v1.0+

AI Quality Score

79/100Analyzed 3/28/2026

Well-structured technical reference skill for SKILL.md security analysis. Provides clear usage examples, extraction categories with tables, risk scoring methodology, and when-to-use triggers. Missing actual code/implementation details but provides sufficient reference information for a tool-oriented skill. Located in dedicated skills folder (skills-db/security/skill-decompile). The self-referencing path hints at internal tooling context but the security scanning concept is universally applicable.

92
85
72
70
78

Metadata

Licenseunknown
Version-
Updated3/20/2026
Publisherlev-os

Tags

ci-cdpromptingsecurity