Security Audit Features in the skills CLI: How Gen, Socket, and Snyk Protect Your Code
The skills CLI displays a three-column security audit table showing risk assessments from Gen (ATH), Socket, and Snyk partners when adding or listing skills.
The vercel-labs/skills CLI integrates automated security scanning directly into your workflow. When you install or browse skills, the tool queries three partner audit services—Gen, Socket, and Snyk—and renders a concise table showing vulnerability risks and alert counts. This feature helps developers catch security issues before they reach production, all without blocking the install process.
What the Security Audit Table Displays
The CLI renders a fixed three-column layout every time you run skills add or interact with the skill registry:
| Column | Partner | Data Shown |
|---|---|---|
| Gen | ATH | Risk level: Critical Risk, High Risk, Med Risk, Low Risk, or Safe |
| Socket | Socket | Alert count: N alerts (red if >0, green if 0) |
| Snyk | Snyk | Risk level: Same format as Gen column |
This table appears in src/add.ts via the buildSecurityLines function (lines 109-155), which formats the raw partner data into aligned columns.
How Each Security Audit Partner Works
Gen (ATH) Risk Assessment
The Gen column pulls from the ATH partner's risk evaluation. In src/add.ts, the riskLabel helper (lines 43-48) transforms the raw data.ath.risk value into a color-coded label:
// src/add.ts – risk label helper
function riskLabel(risk: string): string {
switch (risk) {
case 'critical': return pc.red(pc.bold('Critical Risk'));
case 'high': return pc.red('High Risk');
case 'medium': return pc.yellow('Med Risk');
case 'low': return pc.green('Low Risk');
case 'safe': return pc.green('Safe');
default: return pc.dim('--');
}
}
Critical risks appear in bold red, making them impossible to miss during skill installation.
Socket Security Alerts
The Socket column shows the number of security alerts detected by Socket's supply chain security scanning. The socketLabel function in src/add.ts (lines 91-95) handles formatting:
// src/add.ts – socket alert formatter
function socketLabel(audit: PartnerAudit | undefined): string {
if (!audit) return pc.dim('--');
const count = audit.alerts ?? 0;
return count > 0
? pc.red(`${count} alert${count !== 1 ? 's' : ''}`)
: pc.green('0 alerts');
}
Any positive alert count renders in red, while a clean scan shows "0 alerts" in green. This gives immediate visual feedback on supply chain risks.
Snyk Vulnerability Risk
The Snyk column mirrors the Gen column's format, using the same riskLabel helper applied to data.snyk.risk (line 145 in src/add.ts). This consistency makes it easy to compare risk assessments across the two partners side-by-side.
Fetching Security Audit Data: The Backend Flow
The CLI doesn't block your workflow while fetching security data. The fetchAuditData function in src/telemetry.ts (lines 97-123) implements a 3-second timeout to ensure responsiveness:
// src/telemetry.ts – fetching audit data
export async function fetchAuditData(
source: string,
skillSlugs: string[],
timeoutMs = 3000
): Promise<AuditResponse | null> {
if (skillSlugs.length === 0) return null;
const params = new URLSearchParams({ source, skills: skillSlugs.join(',') });
const controller = new AbortController();
const timeout = setTimeout(() => controller.abort(), timeoutMs);
const response = await fetch(`${AUDIT_URL}?${params.toString()}`, {
signal: controller.signal,
});
clearTimeout(timeout);
return response.ok ? (await response.json()) as AuditResponse : null;
}
The function queries https://add-skill.vercel.sh/audit with:
source: Your repository URLskills: Comma-separated skill slugs to audit
If the request times out or fails, the CLI gracefully continues without security data rather than blocking installation.
Rendering the Complete Security Table
Once data is fetched, buildSecurityLines in src/add.ts (lines 109-155) assembles the final output:
- Validates that at least one partner returned data
- Calculates column widths for alignment
- Builds the header row with "Gen", "Socket", "Snyk" labels
- Iterates each skill, formatting:
data?.ath→riskLabeldata?.socket→socketLabeldata?.snyk→riskLabel
- Appends a footer linking to
https://skills.sh/<source>for full details
Example Security Audit Output
When you run skills add, you might see:
Skill Name Gen Socket Snyk
my-cool-skill Critical Risk 2 alerts High Risk
Details: https://skills.sh/github.com/owner/repo
This immediately tells you:
- Gen (ATH): Critical risk detected — highest priority
- Socket: 2 supply chain alerts need investigation
- Snyk: High risk confirms the severity
Key Source Files Reference
| File | Purpose |
|---|---|
src/add.ts |
Renders security table (riskLabel, socketLabel, buildSecurityLines) |
src/telemetry.ts |
Fetches audit data (fetchAuditData), defines AuditResponse type |
src/types.ts |
Type definitions for PartnerAudit and related structures |
src/skill-lock.ts |
Stores source URL used for audit API calls |
Summary
- The skills CLI security audit displays three partner-provided assessments: Gen (ATH), Socket, and Snyk
- Gen and Snyk show color-coded risk labels (
CriticalthroughSafe) - Socket displays supply chain alert counts with visual red/green indicators
- Data fetches from
https://add-skill.vercel.sh/auditwith a 3-second timeout to prevent blocking - The table renders via
buildSecurityLinesinsrc/add.ts, with full details available athttps://skills.sh/<source>
Frequently Asked Questions
How do I read the security audit table when adding a skill?
The three columns show partner security assessments. Gen and Snyk display risk levels from Critical Risk (bold red) to Safe (green). Socket shows supply chain alert counts—any number above zero appears in red. Watch for Critical or High risk labels and non-zero Socket alerts before installing.
What happens if the security audit service is down?
The fetchAuditData function in src/telemetry.ts implements a 3-second timeout using AbortController. If the audit service at add-skill.vercel.sh is slow or unavailable, the request aborts and the CLI continues installation without security data. Your workflow is never blocked by audit failures.
Where is the full security report for a skill?
The CLI outputs a footer link pointing to https://skills.sh/<source> where <source> is your repository URL. This page contains the complete audit details from all three partners. The buildSecurityLines function in src/add.ts appends this link after the security table.
Do I need to configure API keys for Gen, Socket, or Snyk audits?
No configuration is required. The skills CLI queries a centralized audit service at add-skill.vercel.sh that aggregates partner data. Individual API keys for ATH Gen, Socket, or Snyk are handled server-side; the CLI only consumes the unified response through fetchAuditData in src/telemetry.ts.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →