Back to browse
GitHub Repository

Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.

1 starsTypeScript

SkillsGuard – static scanner for malicious AI agent skills

by teycir·Jun 19, 2026·2 points·0 comments

AI Analysis

●●SolidSolve My ProblemShip It

Catches malicious AI skill scripts when Semgrep and Snyk miss the format.

Strengths
  • Recursive decoding handles base64 and hex blobs generic scanners often skip.
  • MCP stdio server integration allows agents to audit themselves before execution.
  • Zero runtime dependencies reduces supply chain risk for the scanner itself.
Weaknesses
  • Not on npm registry yet, requiring manual build and link for installation.
  • Rule set is opaque; 100+ rules claims lack public documentation.
Category
Target Audience

AI agent developers, Security engineers

Similar To

Semgrep · TruffleHog · Snyk

Similar Projects

Security●●●Banger

A security scanner for AI Agent Skills

Docker sandbox execution catches runtime threats static analysis alone misses.

Big BrainBold Bet
mayziem
502mo ago