Agent Skills are instruction packages and deserve code-like review. A malicious or careless Skill can induce destructive commands, credential disclosure, unauthorized publication, or untrusted code execution even when it contains only Markdown.
The installed dsh-plugin-development directory intentionally contains only SKILL.md and agents/openai.yaml. It has no executable helper, MCP server, hook, dependency, install script, credential request, or embedded DSH checkout. Repository maintenance scripts are not part of the selected Skill directory. The scheduled workflow receives only read access to repository contents and write access to issues; it never modifies compatibility claims.
Report prompt-injection paths, destructive worktree instructions, credential handling, misleading endorsement or compatibility claims, and workflow supply-chain issues through a private GitHub security advisory when possible. For non-sensitive correctness problems, open a normal issue.
Do not include credentials, private prompts, proprietary plugin source, or captured LLM request/response bodies in a report. Provide the smallest synthetic reproduction.