skill-security-scan
Scan Claude Skills for risky network, file, command, and injection patterns.
- Stars
- 159
- Forks
- 12
- Updated
- Updated Jul 11, 2026
Scan Claude Skills for risky network, file, command, and injection patterns.
This command-line scanner reviews third-party Claude Skills before installation for suspicious network access, sensitive file operations, dangerous commands, dynamic execution, and injection patterns. It can produce HTML, console, or JSON reports and supports custom rules and allowlists, while performing static analysis without executing the skill code. Its findings are a review aid rather than a guarantee that every security risk will be detected.
Resource types
Use cases
Operating systems
Scan agent skills for malicious instructions, unsafe code, and supply-chain risks
Scan local agents, MCP servers, and skills for security risks.
Runtime
Public GitHub facts last synced Jul 14, 2026.
Audit agent skills for commands, network access, secrets, and tools without executing them.
Prove which AI agent wrote each line of code with signed Git records.