Free scanner for Claude, Codex & Cursor skills

Is this AI skill safe to install?

Agent skills can run code, read files and reach the internet. Paste a GitHub link and get a safety grade in seconds: prompt injection, hidden characters, credential access, risky commands and more.

Public repos only. Link to the repo or the folder that contains SKILL.md.

Checks the text only. Scripts it references are not fetched.
Prompt injection
Instructions that tell the AI to ignore its rules, hide actions from you or skip approval.
Hidden characters
Invisible Unicode that hides text from human reviewers while the model still reads it.
Credentials & exfiltration
Access to SSH keys, browser data or .env files, and uploads to webhook or paste sites.
Dangerous commands
Recursive deletes, disk formatting, sudo, and download-and-run patterns.
Persistence
Edits to shell profiles, cron jobs, launch agents or your AI agent's own settings.
Install-time code
npm lifecycle hooks, unpinned package sources and bundled binaries.

See exactly what we check and how the grade is calculated on the methodology page.

Popular vetted skills

35 skills scanned so far

Browse directory

Need more than an automated scan?

Our full review is a line-by-line human audit with a sandboxed test run. Skill authors get a "Reviewed" badge; teams get a clear yes or no before rolling a skill out.

Request a full review