skill-scanner
Scan Agent Skills for injection, exfiltration, and malicious code patterns.
- Stars
- 2,352
- Forks
- 289
- Updated
- Updated Jul 14, 2026
Scan Agent Skills for injection, exfiltration, and malicious code patterns.
Skill Scanner checks individual skills, directories, or repositories with static rules, shell-pipeline taint analysis, Python dataflow analysis, and optional LLM or cloud engines. It can produce SARIF or HTML reports and run in CI or pre-commit workflows with custom policies. Results are best effort: finding nothing does not certify a skill as safe, so human review remains necessary.
Resource types
Use cases
Platforms
Connect to GlobalProtect VPNs on Linux through a CLI or GUI.
Scan Electron applications for insecure settings and implementation anti-patterns.
Runtime
Capabilities
Public GitHub facts last synced Jul 14, 2026.
Scan agent skills with static checks, semantic review, and sandbox execution.
Block prompt injection, secret leaks, exfiltration, and risky tool calls locally.