Statically audit an untrusted Agent Skill, plugin, MCP package, bootstrap script, or skill repository before installation by reviewing metadata, executable files, permissions, network behavior, credential access, global configuration writes, prompt injection, dependency provenance, and update risk without executing the package.