Security Audit Features in the skills CLI: How Gen, Socket, and Snyk Protect Your Code

The skills CLI displays a three-column security audit table showing risk assessments from Gen (ATH), Socket, and Snyk partners when adding or listing skills.

The vercel-labs/skills CLI integrates automated security scanning directly into your workflow. When you install or browse skills, the tool queries three partner audit services—Gen, Socket, and Snyk—and renders a concise table showing vulnerability risks and alert counts. This feature helps developers catch security issues before they reach production, all without blocking the install process.

What the Security Audit Table Displays

The CLI renders a fixed three-column layout every time you run skills add or interact with the skill registry:

Column Partner Data Shown
Gen ATH Risk level: Critical Risk, High Risk, Med Risk, Low Risk, or Safe
Socket Socket Alert count: N alerts (red if >0, green if 0)
Snyk Snyk Risk level: Same format as Gen column

This table appears in src/add.ts via the buildSecurityLines function (lines 109-155), which formats the raw partner data into aligned columns.

How Each Security Audit Partner Works

Gen (ATH) Risk Assessment

The Gen column pulls from the ATH partner's risk evaluation. In src/add.ts, the riskLabel helper (lines 43-48) transforms the raw data.ath.risk value into a color-coded label:

// src/add.ts – risk label helper
function riskLabel(risk: string): string {
  switch (risk) {
    case 'critical': return pc.red(pc.bold('Critical Risk'));
    case 'high':     return pc.red('High Risk');
    case 'medium':   return pc.yellow('Med Risk');
    case 'low':      return pc.green('Low Risk');
    case 'safe':     return pc.green('Safe');
    default:         return pc.dim('--');
  }
}

Critical risks appear in bold red, making them impossible to miss during skill installation.

Socket Security Alerts

The Socket column shows the number of security alerts detected by Socket's supply chain security scanning. The socketLabel function in src/add.ts (lines 91-95) handles formatting:

// src/add.ts – socket alert formatter
function socketLabel(audit: PartnerAudit | undefined): string {
  if (!audit) return pc.dim('--');
  const count = audit.alerts ?? 0;
  return count > 0
    ? pc.red(`${count} alert${count !== 1 ? 's' : ''}`)
    : pc.green('0 alerts');
}

Any positive alert count renders in red, while a clean scan shows "0 alerts" in green. This gives immediate visual feedback on supply chain risks.

Snyk Vulnerability Risk

The Snyk column mirrors the Gen column's format, using the same riskLabel helper applied to data.snyk.risk (line 145 in src/add.ts). This consistency makes it easy to compare risk assessments across the two partners side-by-side.

Fetching Security Audit Data: The Backend Flow

The CLI doesn't block your workflow while fetching security data. The fetchAuditData function in src/telemetry.ts (lines 97-123) implements a 3-second timeout to ensure responsiveness:

// src/telemetry.ts – fetching audit data
export async function fetchAuditData(
  source: string,
  skillSlugs: string[],
  timeoutMs = 3000
): Promise<AuditResponse | null> {
  if (skillSlugs.length === 0) return null;
  const params = new URLSearchParams({ source, skills: skillSlugs.join(',') });
  const controller = new AbortController();
  const timeout = setTimeout(() => controller.abort(), timeoutMs);
  const response = await fetch(`${AUDIT_URL}?${params.toString()}`, {
    signal: controller.signal,
  });
  clearTimeout(timeout);
  return response.ok ? (await response.json()) as AuditResponse : null;
}

The function queries https://add-skill.vercel.sh/audit with:

  • source: Your repository URL
  • skills: Comma-separated skill slugs to audit

If the request times out or fails, the CLI gracefully continues without security data rather than blocking installation.

Rendering the Complete Security Table

Once data is fetched, buildSecurityLines in src/add.ts (lines 109-155) assembles the final output:

  1. Validates that at least one partner returned data
  2. Calculates column widths for alignment
  3. Builds the header row with "Gen", "Socket", "Snyk" labels
  4. Iterates each skill, formatting:
    • data?.ath → riskLabel
    • data?.socket → socketLabel
    • data?.snyk → riskLabel
  5. Appends a footer linking to https://skills.sh/<source> for full details

Example Security Audit Output

When you run skills add, you might see:


Skill Name          Gen                Socket               Snyk
my-cool-skill       Critical Risk      2 alerts             High Risk

Details: https://skills.sh/github.com/owner/repo

This immediately tells you:

  • Gen (ATH): Critical risk detected — highest priority
  • Socket: 2 supply chain alerts need investigation
  • Snyk: High risk confirms the severity

Key Source Files Reference

File Purpose
src/add.ts Renders security table (riskLabel, socketLabel, buildSecurityLines)
src/telemetry.ts Fetches audit data (fetchAuditData), defines AuditResponse type
src/types.ts Type definitions for PartnerAudit and related structures
src/skill-lock.ts Stores source URL used for audit API calls

Summary

  • The skills CLI security audit displays three partner-provided assessments: Gen (ATH), Socket, and Snyk
  • Gen and Snyk show color-coded risk labels (Critical through Safe)
  • Socket displays supply chain alert counts with visual red/green indicators
  • Data fetches from https://add-skill.vercel.sh/audit with a 3-second timeout to prevent blocking
  • The table renders via buildSecurityLines in src/add.ts, with full details available at https://skills.sh/<source>

Frequently Asked Questions

How do I read the security audit table when adding a skill?

The three columns show partner security assessments. Gen and Snyk display risk levels from Critical Risk (bold red) to Safe (green). Socket shows supply chain alert counts—any number above zero appears in red. Watch for Critical or High risk labels and non-zero Socket alerts before installing.

What happens if the security audit service is down?

The fetchAuditData function in src/telemetry.ts implements a 3-second timeout using AbortController. If the audit service at add-skill.vercel.sh is slow or unavailable, the request aborts and the CLI continues installation without security data. Your workflow is never blocked by audit failures.

Where is the full security report for a skill?

The CLI outputs a footer link pointing to https://skills.sh/<source> where <source> is your repository URL. This page contains the complete audit details from all three partners. The buildSecurityLines function in src/add.ts appends this link after the security table.

Do I need to configure API keys for Gen, Socket, or Snyk audits?

No configuration is required. The skills CLI queries a centralized audit service at add-skill.vercel.sh that aggregates partner data. Individual API keys for ATH Gen, Socket, or Snyk are handled server-side; the CLI only consumes the unified response through fetchAuditData in src/telemetry.ts.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →