Skillguard — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Skillguard (Agent Skill) and scored it 91/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 1 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} is the classic direct prompt-injection phrasing. Placed in a skill body that the agent reads as trusted instructions, it tries to make the agent abandon its prior rules and follow whatever comes next — a full system-prompt override.
ignore/disregard/forget … previous instructions sentence.Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
*Scan a Claude Code skill, plugin, or MCP server for malware before you install it.* One command, no install, no account.
npx github:epistemedeus/skillguard https://github.com/owner/repo
# or a local folder:
npx github:epistemedeus/skillguard ./my-skillSkillGuard report · 3 text files scanned
DANGER (4)
SKILL.md
■ Prompt-injection / data-exfil instruction in text [prompt-injection]
index.js
■ Possible env/secret exfiltration (sensitive env var near a network call) [env-exfil]
■ Hardcoded suspicious exfiltration endpoint (webhook/pastebin/raw-IP) [exfil-host]
■ Obfuscated/dynamic code execution (eval(atob), curl|bash) [obfuscation]
✗ DANGEROUS — do NOT install without reviewing the flagged files.The Claude Code / MCP ecosystem is exploding — and so is the attack surface. Researchers have found 71 malicious skills in the wild, ~26% of published skills carry vulnerabilities, and 30+ MCP CVEs landed in 60 days. The most common payloads:
ANTHROPIC_API_KEY, AWS_SECRET_ACCESS_KEY, ~/.env) shipped off to a webhook.postinstall) that run code the moment you npm install.SkillGuard catches these patterns in seconds, so you can vet a third-party skill or MCP server before trusting it with your machine and your keys.
SkillGuard does static analysis only. It clones with git clone (hooks disabled) and reads files — it never runs `npm install`, never executes build/postinstall scripts, and never runs the target code. Scanning a malicious package can't harm you. (A scanner that executed what it's inspecting would be the very risk it's meant to prevent.)
| Check | Catches | |
|---|---|---|
env-exfil | A sensitive env var read next to a network call | |
exfil-host | Hardcoded webhook / pastebin / raw-IP / Telegram exfil endpoints | |
obfuscation | eval(atob(...)), `curl \ | bash, subprocess` on encoded data |
prompt-injection | Data-exfil / "ignore instructions" / auto-approve text in SKILL.md, tool descriptions, prompts | |
secret-literal | API keys / private keys committed to the repo | |
committed-binary | Compiled ELF / Mach-O / PE executables in the tree | |
forced-artifact | The honeypot pattern: a build step that generates + commits an encrypted blob | |
dangerous-perms | Auto-approve-all, sandbox-disabling, --dangerously-skip-permissions | |
install-hook | pre/postinstall scripts that run on install |
Exit code: 0 clean · 2 suspicious · 3 dangerous — so you can gate CI on it.
Gate your CI on skill/MCP supply-chain safety:
- uses: epistemedeus/skillguard@v1
with:
path: . # path or git URL to scan
fail-on: dangerous # or "suspicious"Give your agent the ability to vet a skill/MCP server before installing it. Add to your Claude Code / MCP client config:
{
"mcpServers": {
"skillguard": {
"command": "npx",
"args": ["-y", "github:epistemedeus/skillguard", "mcp"]
}
}
}It exposes one tool, scan_skill(target), where target is a local path or a git/GitHub URL. Your agent can then check anything it's about to install. (Static-only — it never runs the scanned code.)
If your skill or MCP server comes back clean, earn a badge for your README:
npx github:epistemedeus/skillguard . --badgeIt prints a Markdown badge you can paste in — a signal to your users that you ran a malware scan:
The CLI is free and MIT-licensed — run it as often as you like. If you install third-party skills/MCPs regularly and want to stop worrying:
→ [samedaydesk.com/skillguard](https://samedaydesk.com/skillguard)
Heuristics catch known-bad patterns; a determined, novel attack can evade any static scanner. SkillGuard is a fast first line of defense, not a guarantee. Always review code from untrusted authors.
MIT · by SameDayDesk · issues + PRs welcome.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.