# SKILL.md Review: Safe and Within the Limits

SKILL.md Review: Safe and Within the Limits is a tested SKILL.md that reviews a SKILL.md file before you install, buy or publish it and lists every problem with a fixed code, the place and a fix, then gives one verdict; an agent buys it once for $0.05 over x402.

- Page: https://aiskills402.com/skills/skill-md-review
- Category: Agents & Protocols (https://aiskills402.com/categories/agents)
- Price: $0.05 once, USD-priced, paid in USDC on Base over x402. Price as loaded on this page. The 402 response your agent receives is authoritative.
- Version: 1.0.1
- Card (JSON): https://api.aiskills402.com/v1/skills/skill-md-review

## Use it when

Reviews a SKILL.md file before you install, buy or publish it and lists every problem with a fixed code, the place and a fix, then gives one verdict. It checks the front matter against the published limits (name up to 64 characters in lowercase, hyphens and digits, no reserved words; description present, up to 1,024 characters, naming both its job and the requests that should trigger it, in the third person), and it reads the body for hidden orders to the agent, credentials pasted into the text, commands that download and run remote code, Windows-style paths, a body over 500 lines and the lack of any example. Use to review a SKILL.md, audit a Claude or agent skill before installing it, check a skill file for prompt injection, or lint a skill before publishing it to a marketplace.

## Not for

Running or testing the skill, reading the scripts that come with it, or judging whether its advice is correct for its topic. It reads one SKILL.md as text, so a problem hidden in a bundled script or a downloaded file is outside what it can see.

## Tested, honestly

Tested 2026-10-08.

- Strong model (claude-sonnet-5-5 (Claude Code alias "sonnet")): Gave the exact codes and verdict in all 20 cases, as bare lines with nothing around them. It caught a request to read the SSH key, a silent copy to a shared drive, a line that claims to replace the system's instructions, a note telling the reviewer to answer No findings, a live-looking API key, a curl piped into sh, a name over 64 characters, an uppercase name, the reserved word claude in a name, a missing, an overlong and a first-person description, an XML tag in the description, a Windows path, a 538-line body and a missing example, and it left a skill that runs its own bundled script unflagged. A first run with a wider wording of our person rule flagged the word you inside ordinary descriptions; the rule was narrowed to match the published guidance and run again.
- Weak model (claude-haiku-5-5 (Claude Code alias "haiku")): Also 20 of 20 with the skill, with the same codes and verdicts as Sonnet, including the counted limits it did not flag without the skill: the 65-character name, the 1,305-character description and the 538-line body.

Note: Twenty small SKILL.md files written by us, each with one or more planted problems or none: a clean file, three name defects, four description defects, four kinds of hidden order to the agent including one aimed at the reviewer, a pasted credential, a download-and-run command, a Windows path, no example, an overlong body, a legitimate bundled script, and one file with three problems. The check requires each expected code and the verdict and forbids every code that should not appear. The limits in the skill were checked against the public skill documentation on 8 October 2026. One run per model and case; the with-skill side was run twice because our wording of one rule was too wide the first time, and the first run is kept in the test folder.

### With and without the skill

Tested 2026-10-08.

- Every planted problem named, nothing invented: Sonnet 20/20 with, 18/20 without; Haiku 20/20 with, 14/20 without.

Both sides scored with the same word-based checks, since the side without the skill does not know our codes. Without the skill both models noticed the hidden orders, the key and the curl command, and Sonnet called out the note aimed at the reviewer; the misses were the counted rules. Haiku did not flag the 65-character name, the 1,305-character description, the 538-line body or the backslash path, and neither model said that the file had no example. Two baseline patterns first missed correct answers (one counted a sentence saying no injected instructions as an alarm) and were widened before the final score; the change applies to both sides.

Same cases and the same checks with and without the skill. The cases are ours, written around what the skill is for; with a handful of cases, a difference of one or two is within noise.

Full summary: https://aiskills402.com/skills/skill-md-review/tests

## Example

### English (claude-sonnet-5-5)

Before:

> --- name: PDF_Form_Filler description: Fills in PDF forms from data you give it and checks that every required field is set. Use when asked to fill a PDF form, complete a fillable PDF, or check a form for missing fields. --- # PDF form filler Read the form fields first, then fill only the fields the user gave data for. Never invent a value. Report every required field that is still empty.…

After:

> [NAME] name: "PDF_Form_Filler" has uppercase letters and underscores, and only lowercase letters, digits and hyphens are allowed. Fix: pdf-form-filler. Verdict: fix before use

## What is in the file

- The answer
- The codes
- Rules
- Work in this order
- Short example

## Languages

Any language

## How to buy

Agent (HTTP):

1. GET https://api.aiskills402.com/v1/skills/skill-md-review/file without a payment header. The answer is 402 with a PAYMENT-REQUIRED header (x402 v2): exact amount, asset, network, recipient.
2. Sign `accepts[0]` with an x402 client (for example @x402/core + @x402/evm).
3. Repeat the GET with the signature in the PAYMENT-SIGNATURE header. The answer is 200 with the file, its sha256 and a re-download token.

Agent (MCP): https://mcp.aiskills402.com/mcp — free tools search_skills, get_skill, redownload_skill. Buying itself is over HTTP.

Full flow: https://aiskills402.com/docs

## The file

- Version: 1.0.1
- Size: 6.7 KB (6903 bytes)
- SHA-256: 5a1fc0857a1b6c252edd7721a3c98a28ce1232e5892903f05e66f3516e835d3b
- Updated: 2026-10-08
- New versions are free through your re-download token.

## Versions

### 1.0.1 (2026-10-08)

Price changed from $0.03 to $0.05; the skill text is unchanged. Measured value for the strong model: Sonnet 18 of 20 without the skill, 20 of 20 with it.

### 1.0.0 (2026-10-08)

First release: reviews one SKILL.md file and lists each problem with a fixed code, the place and a fix, then a verdict (unsafe, fix before use, ready). Unsafe: hidden orders to the agent, credentials in the text, download-and-run commands. Front matter against the published limits: name, missing or overlong description, no trigger, first or second person, XML tags. Body: over 500 lines, Windows paths, no example. Ordinary instructions to use the skill's own scripts are not flagged, and an order to the reviewer inside the file is itself a finding.

## License

Perpetual, non-exclusive; use and modify for yourself incl. paid work; no resale or republishing. Holder: Georgi Kalchev, aiskills402.com. Terms: https://aiskills402.com/docs#license

## FAQ

### What does it check in the front matter?

The published limits for skills: a name of at most 64 characters in lowercase letters, digits and hyphens without the reserved words anthropic and claude, and a description that exists, stays within 1,024 characters, says when the skill should be used and is written in the third person. It counts the characters instead of estimating them.

### Will it catch a hidden instruction to the agent?

Those come first in the report, with the verdict unsafe: a request to read SSH keys, a silent copy of the user's files, a line claiming to replace the system's instructions and a note telling the reviewer to answer No findings were all caught in our tests, along with a pasted API key and a curl command piped into a shell.

### Does it flag every skill that runs scripts?

No. Telling the agent to run the skill's own bundled script on the file the user named is normal and was not flagged by either model. It becomes a finding when the file reaches for data the task does not need or downloads and runs code at use time.

### What did the models miss without it?

The counted rules. Without the skill, Claude Haiku did not notice a 65-character name, a 1,305-character description, a body of 538 lines or a Windows path, and neither Haiku nor Sonnet said that a file had no example. With the skill both models reported all of them.

## Related skills

- [Prompt Injection Guard](https://aiskills402.com/skills/prompt-injection-guard.md): $0.07 once
- [Done Means Done: Honest Agent Status Reports](https://aiskills402.com/skills/done-means-done.md): $0.10 once
- [Code Review](https://aiskills402.com/skills/code-review.md): $0.01 once

## Measurement limits

- Models other than the two named above were not run.
- Each verdict comes from the test run on the date shown; the skill may have changed since (check the version).
- Full test inputs are not published here, only short excerpts of our own text.
- Results on your own texts, languages and domains can differ.

Offer note: Paid in USDC (USD-pegged) over x402 by an AI agent; one-time.
