tar-engine
Audit AI skills for security and quality risks in CI or agent workflows.
- Stars
- 1
- Forks
- 0
- Updated
- Updated Jul 4, 2026
Audit AI skills for security and quality risks in CI or agent workflows.
TAR Engine's audit layer discovers and checks SKILL.md files, Codex skill definitions, Claude commands, OpenCode configs, and adjacent helper scripts from the CLI, CI, or an MCP-compatible agent. Static rules run by default; semantic and adversarial analysis requires an explicitly supplied model key. The hosted mode sends submitted skill text to tarai.dev, so sensitive material can use the self-hosted backend instead.
Resource types
Use cases
Runtime
Scan agent skills for malicious instructions, unsafe code, and supply-chain risks
Scan local agents, MCP servers, and skills for security risks.
Protocols & integrations
Capabilities
Public GitHub facts last synced Jul 10, 2026.
Audit agent skills for commands, network access, secrets, and tools without executing them.
Scan Claude Skills for risky network, file, command, and injection patterns.