For the practitioner
Anyone can write an AI skill. Running ten of them safely is your problem now.
Track 2 · Your skills path is one click away. The story below is depth; the path names what to learn.
Build the defender’s skills →Each skill is easy to judge alone.
Together, the risk hides in the combination — and when something fires, nobody can name the chain.
56 skills
in the public reference repo alone — each one readable in minutes and harmless by itself. The risk isn’t any single file; it’s what three of them can do in sequence.
the SkillGuard scan of the reference repo — literal scanner output, reproducible
Anyone can write a skill. Running several of them safely is the actual problem.
The discipline is three moves: scan everything before it runs, judge combinations as chains, keep the set small enough to see.
“How do I run skills without losing track of where the risk is?”
Scan everything before it runs. Judge combinations as chains. Keep the set small enough to see.
Three moves, one per beat — with the scanner doing the first one live.
Scan everything
Read for what it can touch, before it runs.
Every skill gets read the way you’d read a diff from a stranger: what can it reach, what does it ask for, what would it exfiltrate if it lied. Verdicts land per skill, with the reason written down.
Findings aren’t vibes — each one is triaged with a written rationale, and the whole scan re-runs from the repo.
Read: Every skill is read before anything runs — capabilities extracted, nothing executed.
The real scan on the public reference repo — the same instrument SkillGuard runs.
The chain is the threat
Judge combinations, not files.
A skill that reads your calendar is fine. A skill that posts to a webhook is fine. Installed together, they’re an exfiltration path — and no per-file review will ever say so.
So combinations get judged as chains: what the set can do end-to-end, not what each link looks like alone.
A set you can track
Small enough to see, curated by workflow.
The full library is raw material, not a recommendation. What you run is a tracked set: the curated few per workflow, each scanned, each chain-checked, each with a reason it’s there.
When the set grows, the scan grows with it — that’s the whole deal.
Your reskilling list
113 controls have your name on them.
The work itself, regrouped for AI: what you watch, what you respond to, what you hunt, what you hold.
1 to build · 46 to coordinate with a provider · 66 to verify, not build. Nobody reskills for what the provider already owns.
See what the AI is doing
15 controls · 15 gate the climb
Respond when it goes wrong
6 controls · 6 gate the climb
Hunt and fix the weaknesses
7 controls
Control identity and access
14 controls
Protect the data
8 controls
Hold the keys
19 controls
Harden the ground it runs on
38 controls
Keep it running
6 controls
This is the same spine the assessment reads. Score your mastery on four concrete rungs per prompt, or run the function diagnostic — every gap lands on this list: the named skill, the group it belongs to, and who learns it.
Browse skills personalities →Run the diagnostic. Your gaps land on this list →
56 skills scanned. 3 findings. 0 open.
Every finding triaged with a written reason — literal scanner output, reproducible from the repo.
Not your role?
Each role has its own way in. Here is where the others start.