AI skill security scanner CLI
1.0K
Security scanner for AI agent skills and MCP tool bundles. Detects prompt injection, malware patterns, IOC matches, supply chain risks, and skill graph vulnerabilities before they reach your agents.
Works with skills from skills.sh, ClawHub, and any SKILL.md-based or MCP-compatible skill package.
# Scan a skills directory
docker run --rm -v "$PWD:/work" kurtpayne/skillscan-security scan /work/skills/
# Include ML-based prompt injection detection
docker run --rm -v "$PWD:/work" kurtpayne/skillscan-security scan /work/skills/ --ml-detect
# Include skill graph analysis (remote .md loads, tool grant escalation, memory poisoning)
docker run --rm -v "$PWD:/work" kurtpayne/skillscan-security scan /work/skills/ --graph
# JSON output for CI / SARIF upload
docker run --rm -v "$PWD:/work" kurtpayne/skillscan-security scan /work/skills/ --format json
docker run --rm -v "$PWD:/work" kurtpayne/skillscan-security scan /work/skills/ --format sarif
╭─────────────────────────────── Verdict: BLOCK ───────────────────────────────╮
│ Target: skills/data-exfil-skill │
│ Policy: strict │
│ Score: 85 │
│ Findings: 3 │
╰───────────────────────────────────────────────────────────────────────────────╯
Top Findings:
PINJ-001 CRITICAL Prompt injection: instruction override attempt
PINJ-GRAPH-001 HIGH Skill loads remote .md file at runtime (dead-drop pattern)
IOC-IP-001 HIGH Known malicious IP referenced: 185.220.101.47
Prompt injection (PINJ-*): instruction override, role confusion, jailbreak patterns, Unicode homoglyph attacks, zero-width character injection, base64-encoded instructions, action chain abuse.
Skill graph (PINJ-GRAPH-*, --graph flag): remote .md instruction loading, tool grant escalation without declared purpose, memory file poisoning (SOUL.md, MEMORY.md, AGENTS.md).
IOC matching: known malicious IPs, domains, and URLs from the SkillScan threat intel feed, updated automatically on each scan.
Supply chain: unpinned dependency versions, binary artifacts, executable blobs, compromised package patterns.
ML detection (--ml-detect): DeBERTa-based classifier fine-tuned on 100+ real injection examples. Downloads the model on first use (~45MB).
# Strict (default) — block on any HIGH or CRITICAL finding
docker run --rm -v "$PWD:/work" kurtpayne/skillscan-security scan /work --policy strict
# Balanced — block on CRITICAL only
docker run --rm -v "$PWD:/work" kurtpayne/skillscan-security scan /work --policy balanced
# Custom policy file
docker run --rm -v "$PWD:/work" kurtpayne/skillscan-security scan /work \
--policy /work/my-policy.yaml
# GitHub Actions with SARIF upload to Security tab
jobs:
skillscan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Scan skills
run: |
docker run --rm -v "${{ github.workspace }}:/work" \
kurtpayne/skillscan-security scan /work/skills/ \
--format sarif > skillscan.sarif
- name: Upload SARIF
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: skillscan.sarif
Or use the reusable workflow:
jobs:
skillscan:
uses: kurtpayne/skillscan-security/.github/workflows/skillscan-reusable.yml@main
with:
scan-path: ./skills
The scanner ships with a built-in threat intel feed covering 100+ rules and 10+ IOCs, updated automatically. You can also add custom intel sources:
docker run --rm -v "$PWD:/work" -v "$HOME/.skillscan:/root/.skillscan" \
kurtpayne/skillscan-security intel sync
The ML classifier model is downloaded on first use. To pre-pull it:
docker run --rm -v "$HOME/.skillscan:/root/.skillscan" \
kurtpayne/skillscan-security model sync
pip install skillscan-securityContent type
Image
Digest
sha256:56b4abf80…
Size
201.1 MB
Last updated
6 months ago
docker pull kurtpayne/skillscan-security