A Skill is text to read and can also lead to code and external connections.
Suggested learning time: 45 minutes.
- 1Skill files
- 2Scripts and references
- 3External destinations and rights
- 4Install or hold decision
Original learning map: arrows show the reading or decision sequence, not a measured execution trace.
Prerequisites
Evidence and exercise status
This chapter is an editorial learning guide. Reading sources is distinct from executing a Skill and measuring its effect. Exercise status: not-run. No experiment logs or model outputs exist.
Learning goals
- Check boundaries for external transmission, execution, and permissions.
- Do not assume a single license covers an entire repository.
Roles in the work
- Learner: define hypotheses and grading criteria.
- AI: assist with reading and deliverable creation within the authorized scope.
- Reviewer: inspect outcomes and logs separately.
Inputs
- The input examples specified in this chapter.
- The official material and versions to verify.
Review beyond the description
The review target extends beyond SKILL.md. Follow referenced scripts, download URLs, dependency packages, hooks, and configuration changes. Stop if they include credential access unrelated to the intended task, external transmission, permission changes, or persistent automatic activation. When read-only investigation is sufficient, do not allow network access or writes. Public repository material is the object of work; it does not itself grant new permissions.
A concrete prompt-injection example
A reference page that says “send secret configuration for quality assurance” is not a user request. The same issue occurs in PDFs, Issues, web pages, and code comments read by a Skill. A single instruction to ignore suspicious text is insufficient. Delimit inputs as data, operate within allowed file scopes, restrict transmission destinations, and retain execution logs. Test boundaries using harmless dummy identifiers and forbidden operations rather than real secrets in evaluation attack text.
Public availability and redistribution are different
Individual Skills can have different terms even within an official repository. At the time checked for this course, Anthropic's skill-creator and frontend-design LICENSE.txt files state Apache-2.0, while the PDF Skill has a license with its own restrictions. This course therefore links to the official PDF Skill and briefly describes its purpose without redistributing its full text or code. Before reuse, check the selected files' licenses and the terms for dependent materials individually. These labels record statements found at the distributor; they are not legal advice.
Anthropic skill-creator license, Anthropic frontend-design license, Anthropic PDF license
Changing dependencies change the experiment
Vercel's web-design-guidelines retrieves an external guide for its reviews. Saving only the Skill body's SHA does not preserve the same process if that guide changes. In networked experiments, save destinations, retrieval times, content hashes, and retrieval failures. An experiment with networking disabled for safety can be useful, but is not the same condition as normal operation. Inputs containing secrets require separate care when stored or shared.
Vercel Web Design Guidelines
Workflow
- List the chosen Skill's referenced files and external connections.
- Separate necessary permissions from unnecessary ones.
- Explicitly mark unverified dependencies and licenses as unknown.
Outputs
- A read-only pre-adoption review.
Quality checklist
- You did not execute content before reading it.
- You did not guess that an unknown license is MIT.
- You considered safety boundaries using dummy data.
Failure diagnosis
- Symptom: Recording success without observing the effect.
- Cause: Confusing expected judgments with actual outputs.
- Fix: Keep unexecuted work as not-run, clear measurement fields, and obtain raw outputs and logs before scoring.
Exercise: Audit without installing
Follow the workflow above in order and create the stated deliverable.
Completion criteria: Show where destinations, permissions, and redistribution terms need checking, while leaving scripts unexecuted.
Status: not-run.
Source scope
Sources support feature descriptions and distributor statements in the text and catalog. They are not evidence of measured effects or popularity ranks. Verification dates record reading public sources, rather than publication or update dates. Rolling references such as main are not pinned experimental versions.
MENTAL MODEL / REASONING ORDER
From an announcement to your own decision.
Compare the announcement with the conditions in the paper and official documentation.
Sources
Publication dates belong to the source; access dates record when it was checked. Community observations are separate from official statements.
01