Security auditing (skills)
Security auditing (skills)
Section titled “Security auditing (skills)”Hub validation scores skills for unsafe patterns and weak packaging. Treat this as a local gate, not a substitute for production HITL.
What validation covers
Section titled “What validation covers”When you run kazma hub validate ./my-skill, the wired validator path checks (among other things):
- Manifest shape / required fields
- Entry point presence (when declared)
- Security lint signals (dangerous patterns, secrets-like strings)
- Score threshold for “pass” vs review
Patterns typically flagged
Section titled “Patterns typically flagged”eval/exec/ unrestricted shell- Hardcoded secrets
- Over-broad permissions
Offline libraries also exist under kazma_core/security/ (linter, dependency scanner, certification helpers). Not all of those are auto-run on every install — they are available for operators and future wiring. See docs/audits/UNWIRED_INVENTORY.md.
Running checks
Section titled “Running checks”kazma hub validate ./my-skillkazma hub validate ./my-skill --jsonkazma hub check-certification ./my-skillkazma hub sign ./my-skill # integrity — not the same as a security auditSecurity score (guidance)
Section titled “Security score (guidance)”| Score | Guidance |
|---|---|
| High (≈90+) | Good candidate for sharing |
| Mid | Review manually before install |
| Low | Do not install in production |
Exact thresholds are enforced in code (SkillValidator / certification check). Re-run after changes.
Runtime safety (more important than hub score)
Section titled “Runtime safety (more important than hub score)”Even a “clean” skill can register danger tools. At runtime:
- Graph HITL / swarm bus / pipeline checkpoints still apply
- MCP tools may be force-danger under
KAZMA_PRODUCTION - See Security & Safety and Tools catalog