Early preview · Six skills are always free. Paid skills open soon.
How to use AI skills · 2 min read

Inspect an AI skill download before using real documents

Check the archive, license, files, scripts, and data destinations before installing a package.

Editorial illustration of a jewel box opened carefully with a jeweller’s loupe.

Before installing a skill download, inspect its contents in a separate folder and read the license and instructions. Check executable files and network destinations before giving it private documents or account access. The first test should use non-sensitive sample data.

Inventory the archive

List the filenames before opening or running anything. Look for unexpected executables, hidden files, missing references, and instructions that require credentials. Confirm that extraction stays inside the intended folder. Keep the original archive and version so the review can be repeated.

Separate three reviews

ReviewWhat it answers
LicenseMay you use, modify, or redistribute it?
BehaviorWhat do instructions and scripts do?
FitDoes the workflow help with your actual task?

An open-source license answers a permission question. It does not prove the code is secure or the workflow is effective. Conversely, a proprietary package may be readable and inspectable without granting redistribution rights.

Prepare a review checklist

Working template

Review this package without executing it.
List all files and identify instructions, templates, references, and scripts.
For scripts, summarize file access, subprocesses, network requests,
and required credentials.
Check referenced files exist and note the license.
Do not claim safety from the license or popularity alone.
Archive inventory and file contents: [paste]

Test the narrow path first

Use a fictional draft or a small synthetic document. Observe what the workflow asks for and what it produces. If it requests account access that seems unrelated to the task, stop and clarify the reason. Keep permissions aligned with the work rather than granting everything in case it is needed later.

Finally, check the host’s actual installation instructions and support for the package format. A manual copy of instructions can be useful, but it is different from native discovery. Record which path you tested. If you share a modified package, preserve required notices and describe your changes instead of presenting an upstream package as your own original work.

References and further reading

The examples and templates above are original. These references support the definitions and documented behavior discussed in the guide.