Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseOpenClawOpenClaw+21 more

    ShadowAPIGuard

    1

    Audit AI-generated code for hidden API calls, license conflicts, and copyleft obligations.

    $19

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    Security scanned
    ShadowAPIGuard

    ShadowAPIGuard

    Example session with this skill installed

    Audit this AI-generated auth middleware. Our project is MIT.

    // SPDX-License-Identifier: GPL-3.0-or-later
    function auth(req, res, next) { 
      fetch('https://api.unknown-proxy.io/v1/verify');
      next(); 
    }
    
    • Read your context and instructions
    • Compiled the shadowapiguard

    The compliance audit for the provided auth middleware is complete. A critical conflict and a shadow API call were detected.

    Compliance Audit Report

    {
      "risk_assessment": {
        "overall_status": "BREACH",
        "highest_risk_level": "HIGH"
      },
      "detected_markers": {
        "spdx_identifiers": [
          "GPL-3.0-or-later"
        ],
        "copyleft_alerts": [
          "GPL-3.0"
        ],
        "copyright_notices": [
          "none"
        ],
        "shadow_api_calls": [
          "https://api.unknown-proxy.io/v1/verify"
        ]
      },
      "compliance_signals": [
        {
          "trigger": "Copyleft marker SPDX-License-Identifier: GPL-3.0-or-later detected in block",
          "risk": "HIGH",
          "action_required": "GPL-3.0 is incompatible with your MIT project license. You cannot merge this code without triggering copyleft obligations for the entire repository. Rewrite the middleware logic from scratch."
        },
        {
          "trigger": "Hardcoded third-party API endpoint detected",
          "risk": "MEDIUM",
          "action_required": "The endpoint 'api.unknown-proxy.io' is not an approved internal service. Investigate the source of this call and replace with authorized internal auth providers."
        }
      ]
    }
    

    Next steps

    1. Quarantine the current code block and do not merge it into the main branch.
    2. Regenerate the middleware ensuring no GPL-licensed patterns are used.
    3. Review the api.unknown-proxy.io endpoint to ensure no sensitive credentials were leaked during the generation process.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Audit AI code for GPL/copyleft conflicts before merging into proprietary repos.Identify hidden third-party API calls in generated backend logic.Generate compliance JSON reports for AI-delivered agency work.Prevent prompt injection attempts that target system IP.

    About this skill

    Shipping AI-generated code into production creates massive IP risks, from hidden API calls to copyleft license violations. This skill acts as a compliance gate, scanning code blocks for legal and technical liabilities before they hit your repository.

    What it does

    • Shadow API Detection identifies hardcoded third-party endpoints or proxy calls that could leak data or bypass internal infrastructure.
    • License Scanning flags SPDX identifiers, copyright notices, and copyleft markers like GPL, AGPL, or SSPL.
    • Conflict Analysis compares incoming code against your project license to prevent accidental license contamination.
    • Injection Prevention blocks prompt patterns designed to make agents reveal system prompts or sensitive IP.
    • Risk Reporting generates structured JSON reports with LOW, MEDIUM, or HIGH risk signals for human reviewers.

    How it works

    1. Context Initialization confirm the target project license (e.g., MIT, Apache 2.0, or Proprietary) to establish a baseline for conflicts.
    2. Static Code Audit scan the submitted code block for license headers, copyright strings, and hardcoded API strings.
    3. Risk Categorization evaluate findings against the project license to determine if the code is a CLEAR, WARNING, or BREACH.
    4. Report Generation output a technical JSON audit report detailing every trigger and required remediation step.

    Frameworks & tools

    Works with any programming language or framework. The skill focuses on SPDX identifiers, hardcoded string analysis, and license-to-license compatibility logic.

    Why this beats prompting it yourself

    Standard prompts often ignore the nuance between permissive and copyleft licenses or miss obfuscated API calls. This skill uses a structured compliance logic that forces a project-license check, ensuring every audit is grounded in your specific legal requirements rather than general knowledge.

    Use cases

    • Auditing AI-written database wrappers for copyleft contamination.
    • Scanning third-party prompt templates for hidden telemetry or shadow API calls.
    • Generating a defensible compliance trail for AI agency deliverables.
    • Verifying that generated components do not carry external copyright notices.

    Known limitations

    This skill provides a technical compliance signal based on markers and patterns. It does not provide legal advice, legal opinions, or guaranteed verbatim match detection against global codebases.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 1 day ago

    • Passed all security checks, Safe to install

    Listed1 day ago

    What's inside

    Frequently Asked Questions