SkillScan files a security dossier on any AI agent skill — flagging prompt injection, data exfiltration, supply-chain tampering and 60+ other patterns — and serves it as Model Context Protocol tools.
real engine · runs on the edge · nothing stored
4 MCP tools · one endpoint
Inspect skill files you pass inline — SKILL.md plus any scripts — and get a stamped, scored dossier.
Point it at a GitHub repo or owner/repo (optionally a subdir); it fetches and inspects everything.
Fetch a single raw file by URL and inspect it on the spot.
Pull the full rulebook — every detection pattern with its category and explanation.
17 categories of agent risk · live OSV CVE lookup
streamable http + sse · both live
Use the full origin above with any MCP-capable client — Claude, IDE agents, or custom SDK clients.
Claude Desktop / stdio (via mcp-remote):