Edge checks forknown risks first.
Edge checks available provider evidence and its own scan of the exact bundle before serving a skill. A clean scan lowers the risk. It is not a promise.
What a scan can and can’t tell you
It looks for known risks
Scanners check a skill’s text and files for risky patterns they know about.
It can miss new tricks
A scanner only knows what it was built to look for. Read a skill before letting your AI run its scripts.
Edge never runs skills
Edge hands your AI text. Your AI decides what to do with it.
Are all skills audited?
No. The index and the scan evidence are different sets. A skill with too little current evidence may still appear with a security note. Edge checks its exact bundle before loading it.
What if a skill changes?
Edge checks the exact bundle before loading it and can reuse a current audit of that bundle. A changed bundle must satisfy the gate again.
Can a scan promise safety?
No. Automated checks look for known risks. Review third-party instructions and commands before your AI follows them.
Can I ask Edge to scan one?
scan_skill checks a catalog skill. The local connector can check a skill on your machine. See exact inputs.
For developers: exact-bundle admission
Policy 2026-09-27.1 requires current Edge checks of the exact bundle before load. Edge may reuse a matching audit or scan the pinned bundle on demand. A high or critical finding, or failures from two providers, withholds it. A single failure is disclosed as disputed. Current evidence is at most 30 days old. scan_skill reports the decision and findings for a catalog skill; local scans run in the npm connector.