// Skill inspection dossier

Inspect agent skills before you install them.

SkillScan files a security dossier on any AI agent skill — flagging prompt injection, data exfiltration, supply-chain tampering and 60+ other patterns — and serves it as Model Context Protocol tools.

CASE FILE#SS-0000
Subjectagent skill
Methodstatic analysis
EngineSkillSpector port / TS
HostCloudflare edge
StatusAwaiting input
64patterns
17categories
4MCP tools
~0msedge cold-start
01

File an inspection

real engine · runs on the edge · nothing stored

EXHIBIT A — SKILL.MD (UNTRUSTED INPUT)
Verdict will be stamped here.
Load a sample, then run — or press ⌘⏎.
02

The instruments

4 MCP tools · one endpoint

1
scan_skill

Inspect skill files you pass inline — SKILL.md plus any scripts — and get a stamped, scored dossier.

2
scan_skill_from_github

Point it at a GitHub repo or owner/repo (optionally a subdir); it fetches and inspects everything.

3
scan_skill_from_url

Fetch a single raw file by URL and inspect it on the spot.

4
list_patterns

Pull the full rulebook — every detection pattern with its category and explanation.

03

The rulebook

17 categories of agent risk · live OSV CVE lookup

04

Deputize your agent

streamable http + sse · both live

POST /mcp
GET /sse

Use the full origin above with any MCP-capable client — Claude, IDE agents, or custom SDK clients.

Claude Desktop / stdio (via mcp-remote):