Safely audit an Agent Skill, skill pack, or coding-agent plugin before installation or update: inspect instructions/scripts/hooks/MCP declarations as untrusted data, detect risky permissions and remote dependencies, fingerprint the reviewed revision, and produce an install/rollback recommendation without executing candidate content.