User Guide & Security
Find thousands of AI Agent Skills without treating the internet as trusted code. Browse broadly, install narrowly, and review anything that can touch files, credentials, networks, shells, browsers, databases, cloud accounts or administration.
What the security labels mean
| Label | Meaning | Default CarrySkills action |
|---|---|---|
| Reviewed / lower risk | The source reports a security review and CarrySkills did not find an obvious high-risk signal. | May be considered for My Skills after reading it. |
| Review required | Unreviewed, broad permissions, unclear provenance or another caution signal. | Do not auto-install. |
| Restricted / dual-use | Capabilities may be legitimate for defensive security or administration but can also cause harm. | Quarantine; expert review required. |
| Blocked | Patterns associated with credential theft, malware, ransomware, destructive actions, reverse shells, evasion or similar behavior. | Do not install or execute. |
Third-party Skills are untrusted input. Listing, popularity, publisher verification, or a security-review badge does not guarantee that a Skill is safe for your computer, business, data or accounts. CarrySkills does not automatically execute third-party scripts. Always review the instructions and requested permissions before use. Never approve unexplained secret access, privilege escalation, destructive commands, security-control disabling or data exfiltration.
Three ways to use a Skill
Choose a security-reviewed catalog entry. SD1 checks source, risk and capabilities, imports only the SKILL.md instruction file, hashes it, and places it in My Skills.
Upload or paste your own SKILL.md into the manual-import lane. Treat it as untrusted until it passes the same static scan and human review. Manual files never inherit a Reviewed badge automatically.
For a selected Skill, use the portable handoff for ChatGPT, Claude, Microsoft Copilot, GitHub Copilot, Cursor, Gemini or Codex. SD1 packages instructions for your own authorized account; normal BYOA use does not require an SD1-paid model API.
Simple rule: least privilege
A Skill should receive only the minimum access needed for the task. A writing Skill normally should not need shell access. A calendar Skill normally should not need your full filesystem. A database-analysis Skill normally should not need administrator permissions. Unexpected access is a reason to stop and review.
What CarrySkills checks
CarrySkills uses source provenance, review status, capability indicators and static instruction checks. The gate looks for dangerous patterns such as credential theft, destructive commands, hidden Unicode controls, suspicious encoded commands, local metadata endpoints and other signs of malicious or unsafe behavior. Automated checks can miss problems, so human review remains part of the model.
Source priority
CarrySkills gives highest priority to locally vetted Skills and reputable first-party or security-reviewed sources. Very large public indexes are useful for discovery, but they are not treated as trusted installation feeds. Millions of searchable Skills should not mean millions of executable Skills.
Recommended workflow
Browse → inspect → check source → check permissions → review risk → add to My Skills → run with the smallest permissions possible. Keep important systems backed up, and use isolated/sandboxed environments for unfamiliar or powerful Skills.
The product stays provider-neutral: discover and vet broadly, keep selected SKILL.md files portable, then hand them to the approved AI/runtime that fits the job. Enterprise examples remain supporting case studies rather than the main product experience.
