SkillsGuard – static scanner for malicious AI agent skills
Catches malicious AI skill scripts when Semgrep and Snyk miss the format.

Scans package.json to recommend installable agent skills from the skills.sh ecosystem.
Developers building with AI agents, specifically skills.sh users
skills.sh · LibHunt · StackShare
Just provide your package.json, and StackSkills will analyze your dependencies, identify the technologies in your stack and recommend installable skills from the skills.sh ecosystem
Catches malicious AI skill scripts when Semgrep and Snyk miss the format.
npm for AI agent prompts with commit-pinned lockfiles, but still early and experimental.
Dependency-to-skills recommender that drives skills.sh ecosystem adoption.
OCI-based agent skill packaging, but limited adoption and niche audience versus established agent frameworks.
Scans MCP servers and agent packages for security risks before you install.
Yet another security scanner in a crowd of established tools like Snyk and Dependabot.