SkillGuard Agent Security Scanner
Paste the following prompt into your AI chat to install this skill:
Please follow https://skillhub.cn/install/skillhub.md to install @user_fee73aa5/skillguard.
About this skill
Problem
Agent skills may bundle prompts, code snippets, declared permissions, and network dependencies. Installing them without review can let risks surface only at runtime: prompt injection, credential leakage, dangerous execution, sensitive file access, unexpected outbound requests, or memory pollution. SkillGuard performs a pre-install security check that can be reviewed before adoption.
How It Works
It maps eight detectors to OWASP ASI Top 10:
- Prompt injection: flags jailbreak patterns, manipulative phrasing, and Chinese bypass attempts.
- Secrets and execution: checks for API keys, tokens, passwords, and dangerous calls such as eval, exec, and subprocess.
- Dependencies and permissions: audits dependency packages and cross-checks declared permissions against actual behavior.
- Data and network: detects sensitive file access, data exfiltration paths, and URL-based network requests against a whitelist.
- Memory risk: identifies memory poisoning and cognitive attack indicators.
After the scan, it outputs a TRACE score across Trust, Reliability, Authenticity, Compliance, and Exposure, making it easier to decide whether to publish, review, or block a skill.
Boundaries
SkillGuard is best used as a static pre-install review and gating check. It should not replace sandboxed execution, human code review, or runtime network isolation. Scores and detector findings are risk signals; final decisions should consider business sensitivity and the Agent's permission boundary.
Use Cases
- Run a static pre-install scan of a third-party Agent skill and record TRACE scores before adding it to a workspace.
- Check candidate skills for prompt injection, jailbreak phrasing, and Chinese inducement patterns during intake review.
- Inspect skill packages for exposed API keys, tokens, passwords, and dangerous calls such as eval, exec, and subprocess.
- Cross-check declared permissions against actual behavior, sensitive file access, and URL whitelist network requests before publishing.
Best For
- Engineers responsible for Agent workspace intake: need to block high-risk third-party skills before release.
- Platform security reviewers: need reviewable scan results organized by OWASP ASI risk items.
- Maintainers of private skill repositories: need to compare candidate skills using TRACE scores before publishing.
- Team leads integrating external Agent capabilities: need prompt injection and credential leakage as launch gates.
Related Skills
A lightweight wrapper and automation tool for Jaeger-related GitHub scenarios.
Vault Wrap is a wrapping skill for Vault and GitHub automation.
Port management, threat-intel audits, drift checks, and multi-node monitoring for self-hosted infrastructure.
Provides health checks for HTTP, TCP, Ping, and log sources with dynamic-threshold alerts, anomaly detection, and scheduled inspection reports.