Audits an agent skill (or plugin/MCP) for security risk and assigns a 0–8 danger score with evidence. Use when asked to review, vet, audit, or score the safety of a skill, plugin, hook, or MCP server before installing or trusting it. Triggers include "is this skill safe", "audit this skill", "score this skill", "check this plugin for malicious behavior".