Use when vetting an external AI agent skill (Claude Code, Codex CLI, Gemini CLI, MCP server, or plugin) before installing — checking for prompt injection, data exfiltration, malicious code, supply-chain risks, credential harvesting, or unsafe permissions. Use when a skill was downloaded from an untrusted source, marketplace, or URL and you need a verdict on whether it is safe to install.