Pre-install security check for agent skills

Is this skill safe to install?

Scan a Claude Code, Codex or MCP skill for prompt injection, data exfiltration and dangerous code before it runs on your machine. Your scans stay private to your account.

How it works

  1. 01

    Paste a link

    A GitHub, GitLab, Bitbucket or Hugging Face repository or folder, a single SKILL.md, or an MCP server’s name.

  2. 02

    We inspect it

    More than 20 analyzers read the skill for hidden instructions, exfiltration and dangerous code.

  3. 03

    Get a verdict

    Safe, review first, or do not install, with every finding explained and a fix suggested.

An example result

A real scan of a skill written to be malicious, from skillspector’s test suite. Every finding says where it is, why it matters and how to fix it; on the result page you filter, sort and group them.

  • HighPrompt injectionSKILL.md:10“ignore previous instructions”Tries to override the agent’s instructions or safety rules.
  • HighMCP tool poisoningSKILL.md:1Hidden HTML comment in tool metadataInvisible to people, but read by the agent: a place to hide instructions.
  • HighMCP tool poisoningSKILL.md:1Look-alike letters in a tool nameCyrillic or Greek letters that make a malicious tool pass for a trusted one.
And six more: “Ignore all safety rules”, privilege escalation (“grant full access”), analysis evasion, a YARA match and more tool poisoning.

What a scan checks

  • Prompt injection

    Hidden instructions, anti-refusal tricks, system-prompt leaks and memory poisoning.

  • Data exfiltration

    Reading secrets or agent data and sending it elsewhere, including server-side requests.

  • Dangerous code

    Privilege escalation, tool misuse, unsafe deserialization, malware signatures and code-flow analysis.

  • Supply chain & MCP

    Tampered artifacts, risky dependencies, and MCP tools that are poisoned, over-privileged or change later.

Every scan runs more than 20 static analyzers from NVIDIA/skillspector. AI review adds a semantic read of what the skill is trying to do.

What you can scan

  • Links

    A repository, one folder in it, or a single skill file, on GitHub, GitLab, Bitbucket or Hugging Face.

  • Uploads

    Drop a .zip of a skill, or its SKILL.md, to check one you haven’t published. The file is deleted once it’s scanned.

  • Private GitHub repositories

    Connect GitHub, choose the repositories it may read, and scan them like any link. The result stays yours.

  • Repositories with several skills

    Each skill gets its own verdict and report, under one overall result.

  • MCP servers

    Enter a server’s name from the MCP Registry to check its posture: pinned packages with valid hashes, a source repository, an active status and HTTPS endpoints.

  • Optional AI review

    A deeper, semantic read of the skill with your own Claude key, saved to your account or pasted once. The skill’s content goes to Anthropic, and only when you ask.

Keep track

Skills change. See what a new version brings, and focus on what’s new.

  • History

    Your scans in one list you can sort and filter, each target’s lined up as a timeline. Follow a scan’s steps and log while it runs.

  • Rescans, and what changed

    Scan a skill again: findings are marked new, fixed or unchanged, with the change in score and verdict.

  • Baselines

    Accept the findings you’ve reviewed, and see only what’s new on the next scan. A skill can ship a baseline of its own, applied only if you ask.

Share and automate

  • Export

    Download a report as skillspector’s JSON, or as SARIF for GitHub code scanning and other SARIF tools.

  • Share links

    A read-only link to a result that works without signing in, until you revoke it.

  • A status badge

    Show a skill’s verdict in its README: the badge links to the result you put on it.

  • A GitHub Action

    Scan the skills a pull request changes, fail the check on a risky one, comment with each verdict, and send the findings to code scanning.

  • API tokens

    Start and read scans from scripts and CI, with tokens you create, name and revoke on your account page.

Private by default

  • Your scans and their reports are yours alone, until you share one.
  • An uploaded skill is deleted as soon as it’s scanned.
  • A Claude key you save is checked, encrypted, and never shown again.
  • AI review runs only when you turn it on, and the skill goes only to the provider you chose.
  • You can delete your account, and everything of yours goes with it.
Read the privacy policy

Open source

Skillspector Web is MIT-licensed and built on NVIDIA’s skillspector, run as a library. Run your own with Docker Compose, with accounts or without, or on Vercel, where every scan runs in its own microVM.

Questions

Which agents does it work with?

Any that load agent skills, a folder with a SKILL.md: Claude Code, Codex and others. It also checks MCP servers listed in the MCP Registry. A scan reads the skill’s files, so it doesn’t matter which agent will run them.

How far can I trust a verdict?

It’s a strong first check, not a guarantee. More than 20 analyzers look for known techniques, and the optional AI review reads the skill as a whole; each finding is explained so you can judge it yourself. “Safe to install” means nothing it knows of was found: read the findings, and the code, before giving a skill access to your machine.

What does it cost, and how much can I scan?

It’s free to use. AI review runs on your own Claude key, so what it costs is between you and Anthropic. Each account can run 10 scans a day, and 2 at once.

Can I run it myself?

Yes. Skillspector Web is open source under the MIT licence. Run it with Docker Compose on your own server, with accounts or without, or as one Vercel project where every scan runs in its own microVM. Admins get a backoffice with users, an activity log, a health panel, rate limits, quotas and a switch that pauses new scans, and alerts to Slack, Discord, any webhook or email when scans fail.

Check the next skill before you install it.

Create an account in a few seconds: your scans stay private to it.