CarrySkills — User Guide & Security

CARRYSKILLS

User Guide & Security

Find thousands of AI Agent Skills without treating the internet as trusted code. Browse broadly, install narrowly, and review anything that can touch files, credentials, networks, shells, browsers, databases, cloud accounts or administration.

1. FindSearch the full catalog by task or category.
2. Check trustLook at publisher, review status, permissions and CarrySkills risk level.
3. Add carefullyOnly reviewed, lower-risk Skills should normally enter My Skills.
4. Stop on dangerDo not approve destructive, credential-stealing, evasive or unexplained privileged behavior.

What the security labels mean

Label Meaning Default CarrySkills action
Reviewed / lower risk The source reports a security review and CarrySkills did not find an obvious high-risk signal. May be considered for My Skills after reading it.
Review required Unreviewed, broad permissions, unclear provenance or another caution signal. Do not auto-install.
Restricted / dual-use Capabilities may be legitimate for defensive security or administration but can also cause harm. Quarantine; expert review required.
Blocked Patterns associated with credential theft, malware, ransomware, destructive actions, reverse shells, evasion or similar behavior. Do not install or execute.
Important security disclaimer

Third-party Skills are untrusted input. Listing, popularity, publisher verification, or a security-review badge does not guarantee that a Skill is safe for your computer, business, data or accounts. CarrySkills does not automatically execute third-party scripts. Always review the instructions and requested permissions before use. Never approve unexplained secret access, privilege escalation, destructive commands, security-control disabling or data exfiltration.

Simple rule: least privilege

A Skill should receive only the minimum access needed for the task. A writing Skill normally should not need shell access. A calendar Skill normally should not need your full filesystem. A database-analysis Skill normally should not need administrator permissions. Unexpected access is a reason to stop and review.

What CarrySkills checks

CarrySkills uses source provenance, review status, capability indicators and static instruction checks. The gate looks for dangerous patterns such as credential theft, destructive commands, hidden Unicode controls, suspicious encoded commands, local metadata endpoints and other signs of malicious or unsafe behavior. Automated checks can miss problems, so human review remains part of the model.

Source priority

CarrySkills gives highest priority to locally vetted Skills and reputable first-party or security-reviewed sources. Very large public indexes are useful for discovery, but they are not treated as trusted installation feeds. Millions of searchable Skills should not mean millions of executable Skills.

Recommended workflow

Browse → inspect → check source → check permissions → review risk → add to My Skills → run with the smallest permissions possible. Keep important systems backed up, and use isolated/sandboxed environments for unfamiliar or powerful Skills.

New: Enterprise Agent Playbooks

Turn vetted Skills into practical agents for Microsoft Copilot, GitHub Copilot, Cursor and other approved runtimes. Includes MDM, IBM MQ, SharePoint/Confluence discovery, current/future architecture, observability, screenshots, versioned ZIPs and rollback.

Open Agent Playbooks

CarrySkills Recovery Guard v3.6.1 is live and healthy. CarrySkills v3.7.0 is the validated Bring Your Own Account (BYOA) and portable-AI target. CarrySkills is a discovery, trust, prompt-building and portable Skill export platform. Security screening reduces risk but cannot eliminate it. Users remain responsible for deciding what third-party instructions and permissions are appropriate for their environment.