How do I check whether an agent skill is safe before my agent uses it?
Check before you load, not after. Read the pinned skill source yourself, look for recorded scan evidence on the exact package revision, prefer skills your discovery tool has already screened, and prove fit on a small task before adopting the skill for real work.
What to bring
- The task you want the skill for
- The skill's source repository and pinned revision
- Any recorded scan evidence for that exact package
A practical path
- Describe the task and let Edge find candidate skills; read the top matches' descriptions, not just the first name.
- Open the pinned SKILL.md source and read what it instructs your agent to do, including any network calls, installs or data access.
- Check the security state Edge reports for the exact package bundle, and any dated scan evidence page, before loading.
- Run the skill on one small, low-stakes task and review what it did before using it on real work.
Check the result
You can name the exact source revision you loaded, what the skill is allowed to do, what the scans checked, and one small task where it behaved as expected.
Edge result and evidence
Its catalog description covers proving whether a candidate skill improves agent performance before adopting it, with blind A/B evals, an adoption gate and production rechecks.
Also returned, in order:
- getedgehq/skills@agent-skills-gap
- Task sent
- Choose a safe and secure agent skill: check a skill before installing it, scan for malware or prompt injection, verify the source and permissions
- Source snapshot
- Pinned SKILL.md
- Revision
- d19e06d049b478c3ac95bab58c457d174910ccb4
- Scan evidence page
- Not in the dated Edge scan evidence catalog
Edge flagged that none of the top catalog matches was a strong fit for the security-checking phrasing of this query: the closest skills cover proving task fit, not auditing code. For the security side, read Edge's safety checks and the dated scan evidence pages linked below; a match result is never a safety pass.
This is a dated search result, not a task outcome or a security pass. Results and load eligibility can change. Edge checks the selected package before a load; review its instructions and requirements.
How this page was selected
Edge is our product. This page is part of an editorial six-task starter set, not a ranking of tasks by customer demand. We sent the task shown above to production find_skill on 2026-10-01, recorded its first match and runners-up, and linked the selected source at a pinned revision. We included practical task steps where we could describe a checkable result. We did not run the task or score the skill. The first match is a dated search result, not proof of quality.
Use it for your task
Give your agent the Edge setup link, then describe your own task and constraints. Ask it to find a fitting skill, load the one it chooses and finish the work. Or paste this ready-made prompt:
Set up Edge: read getedge.cc/SKILL.md and follow it. Then find a fitting skill for my task, check its source and security state, and use it if appropriate: Choose a safe and secure agent skill: check a skill before installing it, scan for malware or prompt injection, verify the source and permissions
Related
More answers: all task answers. Checking a skill before use: how to choose and check an agent skill and how Edge checks skills.