Quick Start Guide
Installation
Using UV (Recommended)
# Install uv if you haven't already
curl -LsSf https://astral.sh/uv/install.sh | sh
# Clone and setup
git clone https://github.com/cisco-ai-defense/skill-scanner
cd skill-scanner
# Install all dependencies
uv sync --all-extras
Using pip
# Install the package
pip install cisco-ai-skill-scanner[all]
Basic Usage
Scan a Single Skill
# From source (with uv)
uv run skill-scanner scan evals/skills/safe-skills/simple-math
# Installed package
skill-scanner scan evals/skills/safe-skills/simple-math
Scan Multiple Skills
# Scan all skills in a directory
skill-scanner scan-all evals/skills --format table
# Recursive scan with detailed markdown report
skill-scanner scan-all evals/skills --format markdown --detailed --output report.md
Demo Results
The project includes test skills in evals/skills/ for evaluation and testing:
[OK] simple-math (SAFE)
$ skill-scanner scan evals/skills/safe-skills/simple-math
============================================================
Skill: safe-calculator
============================================================
Status: [OK] SAFE
Max Severity: SAFE
Total Findings: 0
Scan Duration: 0.00s
[FAIL] multi-file-exfiltration (CRITICAL)
$ skill-scanner scan evals/skills/behavioral-analysis/multi-file-exfiltration
============================================================
Skill: data-analyzer
============================================================
Status: [FAIL] ISSUES FOUND
Max Severity: CRITICAL
Total Findings: 12
Scan Duration: 0.00s
Findings Summary:
Critical: 5
High: 3
Medium: 3
Low: 1
Detected Threats:
- ✅ Data exfiltration (HTTP POST to external server)
- ✅ Reading sensitive files (~/.aws/credentials)
- ✅ Environment variable theft (API_KEY, SECRET_TOKEN)
- ✅ Command injection (eval on user input)
- ✅ Base64 encoding + network (exfiltration pattern)
Useful Commands
# List available analyzers
skill-scanner list-analyzers
# Validate rule signatures
skill-scanner validate-rules
# Get help
skill-scanner --help
skill-scanner scan --help
Output Formats
JSON (for CI/CD)
skill-scanner scan /path/to/skill --format json --output results.json
SARIF (for GitHub Code Scanning)
skill-scanner scan /path/to/skill --format sarif --output results.sarif
Markdown (human-readable report)
skill-scanner scan /path/to/skill --format markdown --detailed --output report.md
Table (terminal-friendly)
skill-scanner scan-all evals/skills --format table
Advanced Features
Enable All Analyzers
skill-scanner scan /path/to/skill \
--use-behavioral \
--use-llm \
--use-trigger \
--use-aidefense \
--use-virustotal
Cross-Skill Analysis
skill-scanner scan-all /path/to/skills --check-overlap
Pre-commit Hook
cp scripts/pre-commit-hook.sh .git/hooks/pre-commit
chmod +x .git/hooks/pre-commit
Next Steps
Review the documentation:
- README.md - Project overview
- docs/architecture.md - System design
- docs/threat-taxonomy.md - All threat categories
Try scanning your own skills:
skill-scanner scan /path/to/your/skillIntegrate with CI/CD:
skill-scanner scan-all ./skills --fail-on-findings # Exit code 1 if critical/high issues found
Troubleshooting
UV not found
Install UV:
curl -LsSf https://astral.sh/uv/install.sh | sh
Module not found errors
Sync dependencies:
uv sync --all-extras
Permission errors
UV manages its own virtual environment - no need for manual venv activation.