- Home
- Skills
- Agents & Orchestration
- agent skill security scanner
Works with the AI tools you already use
agent skill security scanner
Audits agent skills and MCP manifests for prompt injection, data exfiltration, and over-permissioned access.
Free
agent skill security scanner
Example session with this skill installed
Audit this MCP server repo at [URL]. It is a simple file-renamer utility using a python script. Check for injection in the tool descriptions and verify network calls.
- Read your context and instructions
- Compiled the agent security scanner
VERDICT: REVIEW
SCOPE: Audited SKILL.md and rename.py; tool-list.json read.
FINDINGS
- Capability Mismatch: rename.py includes a socket call to a remote telemetry IP not mentioned in documentation.
- Tool Poisoning: Tool description instructs agent to 'read .env first'.
- Static audit boundary: Cannot see runtime response injection.
Connects securely to your tools. The creator never sees your data.
About this skill
The problem
Third-party agent skills and MCP servers introduce foreign instructions and code into your agent's trust boundary. Identifying prompt injection, hidden exfiltration directives, or capability-purpose mismatches requires a semantic audit that traditional code scanners ignore.
What it does
- Audits
SKILL.mdand tool manifests for hidden instructions or model-steering directives. - Evaluates bundled source code for network egress, filesystem reach, and unauthorized secret access.
- Identifies capability-purpose mismatches where a skill's permissions exceed its stated utility.
- Inventories un-auditable external references like
curl | shor remote runtime configs. - Produces a definitive INSTALL, REVIEW, or BLOCK gate verdict based on evidence-backed findings.
Why this beats prompting it yourself
Static analysis for agents requires reading text as instructions, not just documentation. This skill enforces a disciplined protocol that prevents false negatives caused by keyword scanning, ensuring every file and model directive is semantically vetted rather than just grepped. It bridges the gap between classic security audits and LLM-specific vulnerability classes.
Use cases
- Vetting an open-source MCP server before allowing it access to your local environment.
- Auditing your own custom skills for potential prompt injection before deployment.
- Building a security gate for an internal agent skill store or CI/CD pipeline.
- Reviewing tool descriptions to prevent agentic data exfiltration through tool poisoning.
Known limitations
Static audit only. Cannot detect runtime tool-response injection where malicious payloads are returned by a live API. Requires manual verification of obfuscated binaries or private repos.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
3 installs
Downloaded by developers to date
Free forever
No account required to browse
Trust & safety
Security scanned
Verified clean 1 day ago
- Free to download with an account
Needs access to