The hard part with agent skill is that "read this file and run these tools" basically makes your repo content part of what the agent has to trust. Static inspection is useful, but I wonder how much malicious behaviour can realistically be detected before runtime?