Semia
Audit agent skills for commands, network access, secrets, and tools without executing them.
- Stars
- 553
- Forks
- 59
- Updated
- Updated Jul 11, 2026
Audit agent skills for commands, network access, secrets, and tools without executing them.
Semia analyzes an Agent Skill before the user decides to trust or run it. The scanner reads the skill as data and never executes its embedded commands, then identifies possible actions, effects, network access, secret reads, and tool invocations with evidence tied to source lines. It can be used through a Python CLI or installed as a plugin for Codex, Claude Code, or OpenClaw. A configured LLM provider is required for the full prepare, synthesize, detect, and report workflow.
Resource types
Use cases
Platforms
Scan agent skills for malicious instructions, unsafe code, and supply-chain risks
Scan local agents, MCP servers, and skills for security risks.
Runtime
Capabilities
Public GitHub facts last synced Jul 14, 2026.
Scan Claude Skills for risky network, file, command, and injection patterns.
Prove which AI agent wrote each line of code with signed Git records.