Skill Sentry

Local, static, explainable pre-install security audit for Agent Skills. Scans a third-party Skill's SKILL.md, scripts, config, and manifest to produce a risk report (destructive commands, hidden network calls, secret reads, obfuscation, prompt injection, persistence) so you can decide whether to install it. Use when the user says "audit this Skill before installing", "check this plugin for risks", "scan an Agent Skill for prompt injection", or "is this Skill safe to add". Never executes the scanned code and never uploads it.

whaojie797-design Updated

File contents

whaojie797-design/skill-sentry/tree/main/ commit 266b35d688

Frequently asked questions

npx skillmds@latest add whaojie797-design/skill-sentry