How to Check an AI Skill Before You Trust It

A skill runs inside your AI assistant — with your assistant's permissions. That is what makes skills powerful, and it is exactly why a five-minute safety check is worth it before you install one.

The 5-minute check

  1. Permissions: does it ask for only what it needs? A calendar skill needs your calendar. It does not need your files, your inbox, or your browsing history. Broad or unexplained permissions are the biggest red flag there is.
  2. Code: can you read it? Open-source skills let you inspect SKILL.md and any scripts before installing. You do not need to understand every line — look for network calls to strange domains and anything that reads files unrelated to the task.
  3. Author: who made this? A named author with a public repo, a website, or a track record beats an anonymous upload. Check how long they have been around.
  4. Reviews: what do users say? Look for specific, detailed feedback — not just star counts. Complaints about unexpected behavior matter more than praise.
  5. Creator: is the ✓ there? A ✓ next to the creator's name means Skill Harbor confirmed who they are — not what their code does. It is one signal among the four above, never a substitute for checking yourself.

Red flags

  • Asks for permissions unrelated to its job.
  • No author information at all.
  • Obfuscated code or downloads from unlisted URLs.
  • Promises that sound too good ("completely free premium API access!").
  • Pressure tactics — countdowns, "only 3 left" — on a digital download.

What Skill Harbor's ✓ actually means

On Skill Harbor, the ✓ is about the person, not the code: it means we confirmed the creator's identity. It is not a code review, a security audit, or a guarantee — treat every skill as untrusted until you have checked it yourself.

Frequently asked questions

Are AI skills safe to install?
Most are. But a skill runs with your assistant's permissions, so check permissions, code, author, and verification status first.
What permissions should an AI skill ask for?
Only what its job requires. Broad or unexplained permissions are a red flag.
What does the ✓ next to a creator's name mean?
It means their identity was confirmed. It says nothing about the code itself.
Can I inspect a skill's code myself?
For open-source skills, yes. For closed-source ones, rely on reputation, reviews, and the ✓ creator badge.

Browse skills