Scan AI agent skills for threats before they run.
Threat Detection
What it catches
29 rules across 5 categories. Every pattern that makes AI agent skills dangerous.
Prompt Injection
Override system prompts to hijack agent behavior
Secret Leaks
Hardcoded API keys, tokens, and credentials
Dangerous Code
Shell commands that execute arbitrary remote code
Data Exfiltration
Attempts to extract environment variables and secrets
Hidden Instructions
Zero-width characters and invisible unicode smuggling
Getting Started
Three steps to secure your skills
Scan locally
One command. No config needed. Scans all skill files in the directory.
Add to CI
Block dangerous skills in pull requests. GitHub annotations built in.
Ship with confidence
Get a status badge for your README. Show users your skills are safe.
CI / CD
GitHub Actions in 30 seconds
Copy this workflow. Every push and PR gets scanned. Findings appear as GitHub annotations.
name: Security Scanon: [push, pull_request]
jobs: skscan: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - name: Run skscan run: npx skscan ci .Compatibility
Works with every AI coding agent
skscan is agent-agnostic. If it reads skill files, skscan can scan them.
Open Source
Built in the open. MIT licensed.
The scanner engine, CLI, and this website are all open source. Read the code, report issues, contribute rules.