
#221 by installsSecurity & compliance
skill-security
Scan agent skills for security risks before installation—catches malware, exfiltration, and backdoors
7.3K
183
77
Jun 1, 2026
Install
npx skills add https://github.com/superagent-ai/skills --skill skill-securityWhat it does
Audits untrusted skills using deterministic scanning (regex, AST analysis, taint tracking, YARA) plus human semantic judgment to catch prompt injection, credential theft, persistence mechanisms, and intent mismatches. Use this whenever evaluating a skill, plugin, or agent tool from any source—local folder, .skill file, or repo—to decide if it's safe to install.
- Scans for credential exfiltration, prompt injection, persistence/backdoors, and memory poisoning patterns
- Two-stage audit: fast mechanical scanner (0–100 risk score) + your contract-check judgment on intent
- Analyzes Python AST, shell/JS heuristics, Unicode homoglyphs, supply-chain dependencies, and YARA signatures
- Reads SKILL.md and flagged code to catch description-vs-behavior mismatches and coordinated attack campaigns