A practical checklist for installing skills
Inspect first
Read SKILL.md and any scripts before running them. Check that requested permissions match the task.
Verify the package
Compare the SHA-256 digest shown on the detail page with your downloaded ZIP.
Keep licenses
Retain the original license and attribution when sharing an open-source skill.
Update deliberately
Review changes before replacing a workflow you rely on.