Skillxray

Scan an AI agent skill, plugin, or MCP bundle for security and hygiene problems before installing or trusting it - prompt injection in the instructions, hidden/invisible Unicode, dangerous commands (curl-pipe-sh, reverse shells), data exfiltration, hardcoded secrets, and auto-running hooks. Use before adding a third-party skill or plugin, before wiring up an MCP server someone else wrote, or whenever you're about to trust a SKILL.md you didn't write. Returns an A-F grade and a per-finding report.

munzzyy 6db07e8 2.9 KB Updated

File contents

munzzyy/skillxray/tree/main/skills/skillxray commit 6db07e8323

Frequently asked questions

npx skillmds@latest add munzzyy/skillxray