Scan agent skill folders for risky patterns and missing safeguards before sharing or deployment with Cisco Skill Scanner
Run a pre-trust security pass over skill packs and prompt bundles before they get shared, merged, or deployed.
Prerequisites
Python 3.10+, skill-scanner package, optional LLM provider credentials for semantic analyzers, and access to the target skill repository or archive
Installation
Use the upstream install or setup path that matches your environment:
- uv pip install cisco-ai-skill-scanner
- pip install cisco-ai-skill-scanner
- pip install cisco-ai-skill-scanner[bedrock]
- pip install cisco-ai-skill-scanner[google]
Requirements and caveats from upstream:
- Prerequisites: Python 3.10+ and uv (recommended) or pip
Basic usage or getting-started notes:
bash
Using uv (recommended)
Using pip
Extracted from upstream docs: https://raw.githubusercontent.com/cisco-ai-defense/skill-scanner/HEAD/README.md