Scan an AI Agent Skill
Analyze a skill before installing it: prompt injection, hidden instructions and exfiltration.
Paste the contents of a SKILL.md to scan it instantly.
Pasted content, the folder, or the .zip never leaves your browser — the rule scan is 100% local.
Nothing to scan yet
Paste a SKILL.md, drop a folder/.zip, or paste a GitHub repo URL to get started.
How do you check if an AI agent skill is safe before installing it?
Paste the SKILL.md contents, drop the skill's folder or a full .zip, or paste the URL of a public GitHub repo, and within seconds you'll see every known risk pattern highlighted right on the file's own text — with the exact line and an explanation of what it means. The rule engine is inspired by NVIDIA SkillSpector and Cisco Skill Scanner (both Apache-2.0) and covers thirteen categories: prompt injection, data exfiltration, privilege escalation, memory poisoning, rogue-agent behavior that tries to persist itself on your machine, system prompt leakage, snooping on other AI agents' local config, excessive agency, SSRF, unsafe handling of the model's own output, hidden Unicode (invisible or bidirectional-override characters), and misleading triggers or descriptions. If it detects a package.json or requirements.txt, it also checks every dependency against the public OSV.dev vulnerability database. The analysis is purely lexical — regular expressions over text, with no code ever executed or interpreted — and runs entirely in your browser, except when you bring in a GitHub repo, which needs the network to read its files. No findings does not mean the skill is safe to install: this is one layer of defense in depth, not a substitute for human review or a real execution sandbox. Free, no signup, no usage limit.
How to use Scan an AI Agent Skill
- Pick how to bring in the skill: paste the SKILL.md contents, drop the folder or a full .zip, or paste the URL of a public GitHub repository.
- The rule engine scans every text file and sorts findings by severity (critical, high, medium, low), tagged with a category and the exact line.
- Pick a file from the list to see its content with every match highlighted right inside the text, including invisible characters shown as a «U+200B» placeholder.
- Read the explanation attached to each finding, then copy the report if you need to document the review before deciding whether to install the skill.
Common use cases
Vet a skill before installing it from a repo you've never heard of
Before you hand an AI agent execution access to instructions you didn't write yourself, paste the GitHub repo URL or the SKILL.md and check for language that overrides the system prompt, exfiltrates data, or tries to persist itself on your system.
Audit the skills you already have installed in Claude, Codex, or Gemini
Drop the folder of skills you use every day to check whether any of them reference another agent's config directory, an MCP config file, or try to enumerate every other skill you have installed.
Check a SKILL.md someone dropped in Slack or Discord before you copy it
Paste the text straight into the scanner to catch instructions hidden in HTML comments, base64 blobs, or invisible Unicode characters — none of which show up when you just read the message, but a model would still process them.
Verify dependencies before trusting a skill's package.json or requirements.txt
If the skill ships a dependency manifest, every package and version gets checked against OSV.dev's public vulnerability database so you know if any of them carry a known CVE.
Run a security pass before publishing your own skill for others to install
Scan your own skill before sharing it to confirm no leftover debug snippet, forgotten comment, or invisible character made it into the final file.
Frequently asked questions
Is it safe to paste or upload the content of a skill I don't know?
Yes, for pasted text or an uploaded folder/.zip — the rule scan runs entirely in your browser with zero network calls, which you can verify yourself by opening the Network panel in DevTools. The exception is bringing in a repo by URL, which does request the file tree and file contents from the public GitHub API, and — if a dependency manifest is present — each package's name and version (never the code) gets checked against the OSV.dev API.
What patterns does the scanner detect?
Thirteen risk categories: prompt injection (including known jailbreaks like DAN), data exfiltration to external destinations, privilege escalation, persistent memory poisoning, rogue-agent behavior that tries to persist itself (crontab, shell startup files, systemd), system prompt leakage, snooping on other installed AI agents' configuration, excessive agency without human confirmation, SSRF toward cloud metadata IPs or internal network addresses, unsafe handling of the model's own output, hidden Unicode, instructions concealed in comments or base64, and misleading triggers or descriptions.
If nothing turns up, does that mean the skill is safe to install?
No. The ruleset covers known, documented abuse patterns, but a well-built malicious skill can avoid all of them. Treat this as one layer of defense in depth, not a security certification — keep applying the same judgment you'd use before running any code from an unknown source.
Does the scanner actually run or interpret the skill's code the way a real agent would?
No. It's a purely lexical scan: regular expressions over each file's text, with no Python AST parsing and nothing ever executed. It is not a substitute for real code review or an execution sandbox before granting a skill broad permissions.
Why does it need an internet connection if dropping a folder is local?
Only the GitHub repo mode needs the network, because it has to ask the GitHub API for the file listing and each file's content. If you want to keep everything local, download the repo as a .zip and upload it through the folder/.zip option instead of pasting the URL.
What happens if the skill has a lot of files or is very large?
When you upload a folder or .zip, up to 200 text files or 5 MB of content get scanned, whichever limit is hit first — the rest is skipped, with a notice shown on screen. When you bring in a GitHub repo, a very large repo can truncate the file listing, and GitHub's unauthenticated API caps you at 60 requests per hour per IP address.