More screenshots
Works with the AI tools you already use
Supply Chain Guard
Static pre-install audit of skills, plugins, and MCP configs: 24 threat IDs, cross-file contradiction detection, trust score and verdict. No network calls, no execution.
Free
Supply Chain Guard
Example session with this skill installed
Audit the package at examples/audit-guide/before/ before I install it.
Baseline
- Permitted permissions: filesystem read (package-local), no writes, no execution
- Permitted destinations: api.fictive.invalid, docs.fictive.invalid
- Declared permissions: as stated in the package manifest
- Read your context and instructions
- Compiled the supply chain guard
- Generated the document
Skill Supply-Chain Guard — audit report
Verdict: REVIEW · score 80 / 100 · auditor@1.0
Preamble
- Auditor version: 1.0
- Baseline: present — permitted permissions, permitted destinations, declared permissions
- Precedence order: entry_point, manifest, config, reference_docs, examples
- Declared specification: contract files excluded from audit per D-P3-01
Inventory summary
4 artifacts read: 1 SKILL.md, 1 manifest, 1 reference doc, 1 fixture. 0 opaque. 0 unreadable.
Scored findings
A2@reference/troubleshooting.md:22-24#1 — A2, HIGH severity, HIGH confidence
- Span: reference/troubleshooting.md:22–24
- Deduction: 20
- Rationale: The reference file directs the reader to POST troubleshooting data to an external endpoint, while the entry point forbids network calls. Same topic key, incompatible value key, different precedence levels.
Corroborating findings
None.
Cross-file evidence set
- RESTATEMENT — allowed paths — SKILL.md:14 vs reference/troubleshooting.md:8 — not fired
- ADDITION — output format — SKILL.md:22 vs reference/troubleshooting.md:14 — not fired
- CONTRADICTION — network policy — SKILL.md:31 vs reference/troubleshooting.md:22–24 — fired
Appendix — LOW confidence
None.
UNASSESSED categories
- H2 — trigger
always_x1_ceiling, gate X1
H2's trigger is verdict-neutral: it is reported, and it does not engage the §6 cap.
Score and verdict
- Base: 100
- Scored deduction: −20 (A2 HIGH @ HIGH)
- Final: 80
- Band (§4): REVIEW, 80 ∈ [60, 84]
- Override (§5): not applied — no CRITICAL at MEDIUM-or-higher
- Cap (§6): not applied — H2's trigger is verdict-neutral
Verdict: REVIEW. One contradiction is a request to look before you install, not a refusal.
Coverage
A1 CLEAR · A2 FOUND · A3 CLEAR · B1 CLEAR · B2 CLEAR · B3 CLEAR · C1 CLEAR · C2 CLEAR · C3 CLEAR · D1 CLEAR · D2 CLEAR · D3 CLEAR · D4 CLEAR · E1 CLEAR · E2 CLEAR · E3 CLEAR · E4 CLEAR · F1 CLEAR · F2 CLEAR · G1 CLEAR · G2 CLEAR · G3 CLEAR · H1 CLEAR · H2 UNASSESSED
Remediation
R-A2 — cross-file contradiction. Rewrite the lower-precedence statement in reference/troubleshooting.md so it restates, paraphrases, or elaborates the entry point's network policy rather than contradicting it. Deleting the reference file drops legitimate ADDITION content and the contradiction may recur elsewhere; the fix is alignment, not removal.
Next steps. Apply R-A2, then re-run the audit on the same tree. The corrected version is at examples/audit-guide/after/ and returns
SAFE, 100/100 — see examples/audit-guide/after-report.md.
supply-chain-guard.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
About this skill
What you get
Point Skill Supply-Chain Guard at a skill package, a plugin manifest, or an MCP server config, and get one trust score and one verdict before anything installs. The audit reads the whole package tree as data. It never executes what it reads, and nothing the package says is ever treated as an instruction to the auditor.
Every finding comes back with a stable key, a severity, a confidence, the exact file span, and a remediation pattern you can hand to the author.
What it catches
24 threat IDs across 8 families:
- Hidden or conflicting instructions
- Exfiltration paths
- Over-broad tool permissions
- Secrets
- Obfuscation
- Install-time execution
- Undocumented network calls
- Rug-pull risk
The differentiator is cross-file contradiction. A package can ship a clean entry point and put the payload in a reference file, a changelog, or an example. This tool reads across files, fixes the precedence order, and tells a contradiction apart from a restatement, a paraphrase, an elaboration, or an addition. A single-file scanner cannot do that by construction.
The number
99.7% pooled per-assertion pass rate, with-skill (1159/1163), at auditor@1.0 / corpus@1.0.0 / config@cfg-4f9a1c7f.
That figure is contract-derived, not measured: the with-skill side follows from the frozen contract and the without-skill side is modeled, and no model was executed. Treat it as evidence that the contract is internally consistent, not as a field result.
What it is not
- No live runtime monitoring.
- No network interception.
- No dependency CVE scanning.
- No binary reverse engineering.
- No H2 detection: a trigger cannot be bound to its effect without running the package, so H2 is reported but unscored in v1.0.
Fine print
This skill makes no network calls at audit time and executes nothing. external_urls is declared as an explicit empty list.
The bundle contains descriptions of the patterns it detects, including the taxonomy's own example signals and the auditor-address definition in scope.md. These are the tool's vocabulary, stated in the frozen contract. self-scan.md records the target set, the declared-specification policy, and the two hits by file.
Four known defects ship in v1.0, each with a backlog item: one package is not fully deterministic on the false-positive guard (BL-01); one package reported a category clean where it could not be checked (BL-02); E3 is claimed by the taxonomy and unexercised by the corpus (BL-03); and one internal expectation describes two incompatible states for H2 (BL-04). Known limits L-1 through L-6 are listed in full in the README.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
Free forever
No account required to browse
Trust & safety
Security scanned
Verified clean today
- Free to download with an account