Vet a Skill Before You Install It
Vet a Skill Before You Install It
An artifact is a folder: a knowledge.md file with metadata and a written body, and optionally a hooks file, a definition of background services, and workflow files. The body reads like documentation. The sibling files can run commands and reach the network.
The project ships a scanner, validate --security, precisely because that gap is exploitable. It looks for prompt injection, dangerous hook commands, dangerous service commands, credential-shaped environment variables, and invisible Unicode. The prompt in this exercise walks the same ground in plain language so you can do it without installing anything — but it is a reading aid, not the scanner, and neither one is the last word.
Both are a floor. Neither can tell you whether guidance is sound, whether an author is who they say, or whether a file changed since you last approved it. Run what you have, then read anyway.
Get the raw text
Note what this prompt does not use. The catalog tool you used in Exercise 2 returns an artifact's knowledge.md and nothing else — and the files beside it are precisely where a skill gains the ability to run commands and reach the network. So read the folder, not the catalog entry, and read the copy that actually landed on your machine.
Find the review-ai-research-output artifact in the context-bazaar plugin you installed. It is the folder kanon/knowledge/review-ai-research-output/ inside the installed plugin; if you cannot locate it on disk, read the same folder in https://github.com/jhu-sheridan-libraries/agentic-skill-library Show me the full text of knowledge.md. Then list every other file in that folder and show me the contents of each one, especially any hooks file or MCP server definition. Show the text as it is written. Do not summarise, tidy, or skip anything.
You have the artifact body in front of you, plus the contents of every file packaged with it.