What problem does it solve?
Agent skills installed from marketplaces or third parties can contain hidden malicious behavior such as credential theft, backdoors, or prompt injection. This Skill scans any agent skill before you install or use it, so you can make an informed trust decision without sending any file contents off your device.
Core Features & Use Cases
- Full-platform scan: Enumerate and audit every installed skill on platforms like OpenClaw, Cursor, Windsurf, CodeBuddy, Claude Code, and WorkBuddy, including system built-in skills.
- Single-skill audit: Deep static analysis of one skill's SKILL.md, scripts, manifests, and configs, comparing declared purpose against actual code behavior.
- Plain-language risk reports: Fixed-format verdicts (safe, needs attention, risk detected) with findings explained for non-technical users, in the user's own language.
- Use Case: Before installing a community skill from a marketplace, ask the agent to audit it; the scanner flags hardcoded credentials, network exfiltration, or prompt-injection attempts and tells you whether it is safe to enable.
Quick Start
Ask your agent: "Is this skill safe? Scan the skill at ./my-skill for security risks before I install it."