Skill Scanner

A security scanner for agent skills: finds prompt injection, data exfiltration and malicious code before you install

CLI

Medium risk

We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.

Why this level

  • Reads and analyzes arbitrary code of scanned skills and can clone repositories
  • Optional LLM, VirusTotal and cloud engines send content to external services via keys
All reasons and checks

cisco-ai-defense/skill-scanner

Install

In your terminal, with SkillFoxx CLI

npx skillfoxx add cli/skill-scanner

Detects the agents on your machine, checks the risk and pins the version.

Other ways to install

Install the tool

pipx install cisco-ai-skill-scanner

Without pipx, pip install cisco-ai-skill-scanner works too.

You will need: pipx

Checked against the repository on Sep 25, 2026, commit 4f8bec3.

Text for your agent

Install the scanner: uv pip install cisco-ai-skill-scanner or pip install cisco-ai-skill-scanner. Then check a target with skill-scanner scan /path/to/skill, or a repository with skill-scanner scan-repo owner/repo.

Other ways from the author
uv pip install cisco-ai-skill-scanner

Recommended via uv. Alternative: pip install cisco-ai-skill-scanner. Needs CPython 3.11 to 3.14.

This is third-party code. Review the repository files before installing.

What it does

Skill Scanner checks agent skills for signs of threats before you install them. It combines several engines: signature detection with YAML and YARA-X rules, AST and dataflow code analysis, an optional LLM-as-a-judge and a bounded CEL decision layer over typed detector facts. It can scan a single skill, a directory recursively or a GitHub repository by the owner/repo shorthand. It offers SARIF output for GitHub Code Scanning, a ready CI workflow, a pre-commit hook and exit codes to fail a build. The authors state plainly that this is best-effort detection, not a security guarantee, and that an empty report does not mean a skill is clean.

Who it is for. For security engineers, maintainers and teams who install or publish agent skills and want to check them before use.

Good fit when

  • Before installing a third-party skill from a repository or catalog
  • You need to wire skill scanning into CI or a pre-commit hook
  • You need a report on potential threats in a skill as SARIF or HTML

Not a fit when

  • You want a security guarantee: the scanner gives best-effort detection, not certification
  • The target is not an agent skill in the supported formats

Example request

Scan this skill before I install it and show whether there are signs of prompt injection or data exfiltration

Limitations

This is a defensive detection tool: an empty report does not guarantee a skill is safe, coverage is incomplete, false positives and negatives are possible, and manual review remains essential. It needs CPython 3.11 to 3.14, and a source install additionally requires Go to build a helper component. It natively supports the OpenAI Codex and Cursor skill formats per the Agent Skills specification, while non-standard formats such as Claude Code commands are scanned in lenient mode. The LLM engine and cloud checks are enabled by keys and send content to external services, some of which may be unreachable from Russia without a VPN. By the authors' own evaluation the metrics on a locked disjoint split do not yet pass the promotion gate, so the CEL rules ship in shadow mode.

How to disable. Remove the package: pip uninstall cisco-ai-skill-scanner. If you wired a pre-commit hook or CI workflow, remove the corresponding entries from the configuration.

Security check

  • Reads and analyzes arbitrary code of scanned skills and can clone repositories
  • Optional LLM, VirusTotal and cloud engines send content to external services via keys

README in short

The README describes Skill Scanner as a defensive security scanner for agent skills that looks for prompt injection, data exfiltration and malicious code patterns. It combines YAML and YARA-X signatures, AST and dataflow analysis, an optional LLM-as-a-judge and a CEL decision layer. It natively supports the OpenAI Codex and Cursor formats, with lenient mode for non-standard ones. It provides SARIF output, a ready CI workflow, a pre-commit hook, a REST API and a plugin architecture for custom analyzers. A scope section states plainly that this is best-effort detection, not certification, and reports current detection metrics. The package installs via uv or pip, with a Homebrew formula available.

FAQ

Does an empty report mean the skill is safe?

No. An empty report only says no known threat patterns were found. Coverage is incomplete and manual review remains essential.

Are keys and external services required?

Core scanning runs locally. The LLM engine, VirusTotal and cloud checks are enabled separately by keys and send content to external services.

Editors’ pick

A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor

SkillMedium riskNo VPN needed22.6KRepository stars
Editors’ pick

NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference

CLIHigh risk22.6KRepository stars
Editors’ pick

Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install

CLIMedium riskNo VPN needed18.5KRepository stars
Official

Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents

CLIMedium risk16.8KRepository stars
Foxx AISkill Scanner

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.