Read-only safety inspection of a third-party agent skill or plugin BEFORE it is installed or trusted. Reads every file in the candidate directory (SKILL.md plus auxiliary and test files, not just the body), compares declared behavior against what the files actually do, scans for exfiltration, secret access, config or agent-instruction modification, shell execution, and hidden Unicode, and returns an install/decline/sandbox verdict for a human to approve. Never installs, never auto-trusts. Use when evaluating an external skill, plugin, or marketplace entry before adopting it. Do not use to author or audit a first-party Fhorja skill (those are generated by build-agent-skill…