Sigil Scan

Automated security auditing for AI agent code. Scans repos, packages, MCP servers, and installed skills for malicious patterns using eight-phase analysis: install hooks, dangerous code patterns, network exfiltration, credential access, obfuscation, provenance, prompt injection, and skill security. Use when: cloning repos, installing packages, reviewing MCP servers, auditing skills, scanning code before execution, or when asked to check if something is safe, audit code, scan for malware, review dependencies.

nomarj 471fc88 10 files · 75.2 KB Updated

File contents

nomarj/sigil-skill/tree/main/sigil-scan commit 471fc88dbc

Frequently asked questions

npx skillmds@latest add nomarj/sigil-scan