Assess ANY agent skill (Claude Code / Cursor / Copilot / plugin skill, marketplace or bespoke, local or cloned) as a senior security and AI architect and produce a standardized, risk-rated assessment. Covers BOTH execution surfaces - the agent-execution surface (SKILL.md instructions and the scripts the agent invokes - prompt injection, tool poisoning, memory-file poisoning) AND the developer-execution surface (bundled test files, git hooks, and npm/pip lifecycle scripts that auto-run on npm test / git commit / npm install, outside the agent, with the developer's own permissions - a surface skill scanners cover only partly). Use when someone asks to review, assess, vet, a…