skillsmith / scan verdict
Loading…
Heuristic static scan — not a security guarantee. Scan your own skill at skillsmith.ch.
Loading…
Heuristic static scan — not a security guarantee. Scan your own skill at skillsmith.ch.
Every Claude Agent Skill you publish, install, or point an AI agent at should be audited for security risks. skillsmith performs a multi-layered static analysis on each SKILL.md you submit, looking for known attack patterns documented in the AI-security research community. The scanner combines three detection engines:
eval, exec, pickle.loads, subprocess, yaml.load without SafeLoader, os.system, dynamic __import__, and dozens more. These are weighted by how directly they can be weaponized in a SKILL.md context.Each scan produces a risk verdict from clean to critical. A clean verdict means the scanner found no high-confidence indicators of malicious intent. A critical verdict means at least one pattern matched with enough weight to suggest the skill is actively trying to abuse an AI agent. Mid-tier verdicts (low, medium, high) reflect increasing density of suspicious signals.
Important: a clean verdict is a static-analysis signal, not a guarantee. It means the skill didn't trip any of the 1,900+ patterns we currently track. New attack techniques appear regularly, and heuristics can miss novel evasion. Use skillsmith as one input among many — code review, sandbox testing, and source provenance still matter.
Some examples of patterns that will fire a finding:
curl, wget, or fetch() to non-allowlisted domains, or to spawn child processes via os.system / subprocess.Popen.Security scanners are noisy. A skill that legitimately teaches the agent to call eval() on trusted input — for example, a sandboxed calculator skill — will trigger the code-pattern engine. That's by design: the scanner errs on the side of asking you to look. The risk verdict reflects aggregate signal, so a single low-weight match does not push a clean skill into "high" territory. You can always click the snippet link to see the exact line that matched and decide whether it's actually dangerous in context.
If you believe a scan result is wrong, you can file a community report from the API or via the MCP tool. Crowd reports help calibrate the rule weights over time.
skillsmith is built and maintained as an independent research tool. The pattern lists, weight calibrations, and explainer heuristics are all versioned in the public repository at github.com/Larslllllll/skillsmith-web. The scanner is open source, the API is free for low-volume use, and the underlying threat-intelligence work is funded by Pro subscriptions and a small grant from the Solana Foundation. If you find a pattern that should be added (or one that fires too aggressively), please open an issue.