User Guide & Security
Find thousands of AI Agent Skills without treating the internet as trusted code. Browse broadly, install narrowly, and review anything that can touch files, credentials, networks, shells, browsers, databases, cloud accounts or administration.
What the security labels mean
| Label | Meaning | Default CarrySkills action |
|---|---|---|
| Reviewed / lower risk | The source reports a security review and CarrySkills did not find an obvious high-risk signal. | May be considered for My Skills after reading it. |
| Review required | Unreviewed, broad permissions, unclear provenance or another caution signal. | Do not auto-install. |
| Restricted / dual-use | Capabilities may be legitimate for defensive security or administration but can also cause harm. | Quarantine; expert review required. |
| Blocked | Patterns associated with credential theft, malware, ransomware, destructive actions, reverse shells, evasion or similar behavior. | Do not install or execute. |
Third-party Skills are untrusted input. Listing, popularity, publisher verification, or a security-review badge does not guarantee that a Skill is safe for your computer, business, data or accounts. CarrySkills does not automatically execute third-party scripts. Always review the instructions and requested permissions before use. Never approve unexplained secret access, privilege escalation, destructive commands, security-control disabling or data exfiltration.
Simple rule: least privilege
A Skill should receive only the minimum access needed for the task. A writing Skill normally should not need shell access. A calendar Skill normally should not need your full filesystem. A database-analysis Skill normally should not need administrator permissions. Unexpected access is a reason to stop and review.
What CarrySkills checks
CarrySkills uses source provenance, review status, capability indicators and static instruction checks. The gate looks for dangerous patterns such as credential theft, destructive commands, hidden Unicode controls, suspicious encoded commands, local metadata endpoints and other signs of malicious or unsafe behavior. Automated checks can miss problems, so human review remains part of the model.
Source priority
CarrySkills gives highest priority to locally vetted Skills and reputable first-party or security-reviewed sources. Very large public indexes are useful for discovery, but they are not treated as trusted installation feeds. Millions of searchable Skills should not mean millions of executable Skills.
Recommended workflow
Browse → inspect → check source → check permissions → review risk → add to My Skills → run with the smallest permissions possible. Keep important systems backed up, and use isolated/sandboxed environments for unfamiliar or powerful Skills.
Turn vetted Skills into practical agents for Microsoft Copilot, GitHub Copilot, Cursor and other approved runtimes. Includes MDM, IBM MQ, SharePoint/Confluence discovery, current/future architecture, observability, screenshots, versioned ZIPs and rollback.
