Skip to content
kazma.
ع Star 6 Get Started

Security auditing (skills)

Hub validation scores skills for unsafe patterns and weak packaging. Treat this as a local gate, not a substitute for production HITL.

When you run kazma hub validate ./my-skill, the wired validator path checks (among other things):

  • Manifest shape / required fields
  • Entry point presence (when declared)
  • Security lint signals (dangerous patterns, secrets-like strings)
  • Score threshold for “pass” vs review
  • eval / exec / unrestricted shell
  • Hardcoded secrets
  • Over-broad permissions

Offline libraries also exist under kazma_core/security/ (linter, dependency scanner, certification helpers). Not all of those are auto-run on every install — they are available for operators and future wiring. See docs/audits/UNWIRED_INVENTORY.md.

Terminal window
kazma hub validate ./my-skill
kazma hub validate ./my-skill --json
kazma hub check-certification ./my-skill
kazma hub sign ./my-skill # integrity — not the same as a security audit
ScoreGuidance
High (≈90+)Good candidate for sharing
MidReview manually before install
LowDo not install in production

Exact thresholds are enforced in code (SkillValidator / certification check). Re-run after changes.

Runtime safety (more important than hub score)

Section titled “Runtime safety (more important than hub score)”

Even a “clean” skill can register danger tools. At runtime:

  • Graph HITL / swarm bus / pipeline checkpoints still apply
  • MCP tools may be force-danger under KAZMA_PRODUCTION
  • See Security & Safety and Tools catalog