skill-shield

Static-analysis security scoreboard for public AI agent skills.

Skills scanned
Avg risk
Critical
High
Last crawl
Every score is computed at runtime from a real public SKILL.md on GitHub. No mocks, no seeds, no Math.random(). Re-scan cadence: 6 hours.

Risk leaderboard

Skill Repository Risk Findings Last scanned
Loading…

Biggest movers this week

Skills whose risk score changed the most over the last 7 daily snapshots.

Loading…

Submit a skill

Paste a public github.com/.../SKILL.md URL. The scanner pulls the raw file and reports a risk score within a few minutes.

Methodology

Every skill is scored as the sum of pattern weights, capped at 100. Each pattern can contribute at most three times per skill to keep large files from dominating. Categories: safe 0–20 low 21–40 moderate 41–60 high 61–80 critical 81–100.

Patterns and weights are published below; you can audit the regexes in scanners/patterns.js.

PatternCategoryWeightWhat it catches

Known sources

Public repositories the crawler walks every 6 hours.

RepositoryBranchLast fetchedStatusSkills found
Loading…