Skill Scanner
A security scanner for agent skills: finds prompt injection, data exfiltration and malicious code before you install
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- Reads and analyzes arbitrary code of scanned skills and can clone repositories
- Optional LLM, VirusTotal and cloud engines send content to external services via keys
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add cli/skill-scannerDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Install the tool
pipx install cisco-ai-skill-scannerWithout pipx, pip install cisco-ai-skill-scanner works too.
Install the scanner: uv pip install cisco-ai-skill-scanner or pip install cisco-ai-skill-scanner. Then check a target with skill-scanner scan /path/to/skill, or a repository with skill-scanner scan-repo owner/repo.
Other ways from the author
uv pip install cisco-ai-skill-scannerRecommended via uv. Alternative: pip install cisco-ai-skill-scanner. Needs CPython 3.11 to 3.14.
This is third-party code. Review the repository files before installing.
What it does
Skill Scanner checks agent skills for signs of threats before you install them. It combines several engines: signature detection with YAML and YARA-X rules, AST and dataflow code analysis, an optional LLM-as-a-judge and a bounded CEL decision layer over typed detector facts. It can scan a single skill, a directory recursively or a GitHub repository by the owner/repo shorthand. It offers SARIF output for GitHub Code Scanning, a ready CI workflow, a pre-commit hook and exit codes to fail a build. The authors state plainly that this is best-effort detection, not a security guarantee, and that an empty report does not mean a skill is clean.
Who it is for. For security engineers, maintainers and teams who install or publish agent skills and want to check them before use.
Good fit when
- Before installing a third-party skill from a repository or catalog
- You need to wire skill scanning into CI or a pre-commit hook
- You need a report on potential threats in a skill as SARIF or HTML
Not a fit when
- You want a security guarantee: the scanner gives best-effort detection, not certification
- The target is not an agent skill in the supported formats
Example request
Scan this skill before I install it and show whether there are signs of prompt injection or data exfiltrationLimitations
This is a defensive detection tool: an empty report does not guarantee a skill is safe, coverage is incomplete, false positives and negatives are possible, and manual review remains essential. It needs CPython 3.11 to 3.14, and a source install additionally requires Go to build a helper component. It natively supports the OpenAI Codex and Cursor skill formats per the Agent Skills specification, while non-standard formats such as Claude Code commands are scanned in lenient mode. The LLM engine and cloud checks are enabled by keys and send content to external services, some of which may be unreachable from Russia without a VPN. By the authors' own evaluation the metrics on a locked disjoint split do not yet pass the promotion gate, so the CEL rules ship in shadow mode.
How to disable. Remove the package: pip uninstall cisco-ai-skill-scanner. If you wired a pre-commit hook or CI workflow, remove the corresponding entries from the configuration.
Security check
- Reads and analyzes arbitrary code of scanned skills and can clone repositories
- Optional LLM, VirusTotal and cloud engines send content to external services via keys
README in short
The README describes Skill Scanner as a defensive security scanner for agent skills that looks for prompt injection, data exfiltration and malicious code patterns. It combines YAML and YARA-X signatures, AST and dataflow analysis, an optional LLM-as-a-judge and a CEL decision layer. It natively supports the OpenAI Codex and Cursor formats, with lenient mode for non-standard ones. It provides SARIF output, a ready CI workflow, a pre-commit hook, a REST API and a plugin architecture for custom analyzers. A scope section states plainly that this is best-effort detection, not certification, and reports current detection metrics. The package installs via uv or pip, with a Homebrew formula available.
FAQ
Does an empty report mean the skill is safe?
No. An empty report only says no known threat patterns were found. Coverage is incomplete and manual review remains essential.
Are keys and external services required?
Core scanning runs locally. The LLM engine, VirusTotal and cloud checks are enabled separately by keys and send content to external services.
Related
A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents