Read the skill.md file and any bundled scripts line by line before installing — they are human-readable markdown and shell. Verify the publisher is a known, trusted source. Finally, review the allowed tools field in the front matter to understand exactly what system resources the skill is permitted to access.