skill-scanner
Scan agent skills for security issues. Use when asked to "scan a skill", "audit a skill", "review skill security", "check skill for injection", "validate SKILL.md", or assess whether an agent skill is safe to install. Checks for prompt injection, malicious scripts, excessive permissions, secret exposure, and supply chain risks.
Security Assessment
Detected risks:
About skill-scanner
Scans agent skills for security issues before they are adopted, detecting prompt injection, malicious scripts, excessive permissions, secret exposure, and supply chain risks. It combines a bundled static analysis scanner with an agent-driven review: the script catches deterministic patterns mechanically and emits structured JSON, while the agent evaluates intent, filters false positives, and reasons about behavior the scanner cannot see. The uv CLI is required for Python package management, and scripts such as scripts/scan_skill.py are run from the skill's own root directory rather than the target repository.
The workflow runs through several phases. Input and discovery locates the target, looking under .agents/skills/<name>/ and other established skill roots, validates that a SKILL.md exists, and supports scanning all skills by discovering every */SKILL.md. The automated static scan runs scripts/scan_skill.py to produce findings with severity levels, URL analysis, and structure information, with a manual Grep fallback if the script fails. Frontmatter validation checks for required name and description fields, name-to-directory consistency, allowed-tools justification, model overrides, and description accuracy.
Deeper phases focus on judgment. Prompt injection analysis distinguishes patterns that perform injection from those that merely discuss or detect it, since security and educational skills legitimately reference such patterns. Behavioral analysis is agent-only: it checks description-versus-instruction alignment, config and memory poisoning (edits to CLAUDE.md, settings.json, .mcp.json, hooks, or allowlists that persist after removal), scope creep, unnecessary information gathering, and structural attacks like symlinks escaping the skill directory, frontmatter hooks, backtick command syntax at load time, auto-discovered test files, npm postinstall hooks, and hidden instructions in image metadata. Script analysis reads every bundled script fully and inspects PEP 723 dependencies for exfiltration, reverse shells, credential theft, and dangerous execution. Supply chain assessment weighs trusted versus untrusted domains and remote instruction loading, and permission analysis applies a least-privilege tier system. Findings are reported with HIGH or MEDIUM confidence levels tied to confirmed patterns and evident intent.
FAQ
What does the scanner check for?
It checks for prompt injection, malicious code, excessive permissions, secret exposure, and supply chain risks. Coverage spans frontmatter validation, behavioral analysis, bundled script analysis, supply chain assessment, and permission analysis.
What does the skill require to run?
It requires the uv CLI for Python package management. The bundled scanner is run as uv run scripts/scan_skill.py against a skill directory, and all scripts are run from the skill's own root directory, not the target repository.
How does it avoid flagging security skills that legitimately discuss injection?
During prompt injection analysis it determines whether each pattern is performing injection (malicious) or discussing or detecting it (legitimate). Skills about security, testing, or education commonly reference injection patterns, and only patterns that would execute against the agent running the skill are flagged.
What structural attacks does the behavioral analysis look for?
It looks for symlinks resolving outside the skill directory, PreToolUse and PostToolUse frontmatter hooks, backtick command syntax that runs at load time, auto-discovered test files like conftest.py, npm postinstall lifecycle hooks, and hidden instructions in PNG metadata chunks.
What happens if the bundled scanner script fails?
The workflow falls back to manual analysis using Grep patterns drawn from the skill's reference files. The reference files for injection patterns, dangerous code patterns, and permission analysis support this manual path.
Install skill-scanner
Quick Setup:
- Copy the skill folder to
.claude/skills/ - Claude will automatically detect and use the skill
Repository
getsentry/skills