Launching today

AgentGuard
Scan AI agent Skills for risks before you install them
22 followers
Scan AI agent Skills for risks before you install them
22 followers
AgentGuard scans AI agent SKILL.md files for security risks, hidden capabilities, and quality issues before you install them. Paste a Skill, get a Trust Report with scores, findings, and a clear verdict. Free to use — no account required.





Free
Launch Team

Dropbox SignSimple, secure eSignatures for the way your team works.
Promoted
The scary one isn't the malicious skill, it's a well meaning one carrying shell access it never needed for the job it does. That's the thing I can't eyeball at volume.
@justin_rockmore That is the case this scan is for. A well-meaning skill that grants a shell shows up as a shell capability and a security signal, so you can spot that grant across a pile of skills without reading each file straight through.
What the score does not do is decide that the shell was unnecessary. It treats shell access as a risk whenever the text grants it. Whether this job actually needed a shell is still a review call, made from the capability list next to what the skill says it does.
since a SKILL.md is just instructions, not code, the risky part is usually what it tells the agent to do once it already has tool access, not anything visible in a static read of the markdown. a skill can look completely clean and still cause damage if it's combined with a shell or file-write tool that only shows up at runtime. does the trust report account for what other tools/permissions the agent already has, or is the score based purely on the skill text in isolation
@galdayan You're right, and that's a real limit of this scan.
The Trust Report scores the skill text in isolation. You paste a SKILL.md, and the score comes from that string only: deterministic pattern checks (shell, filesystem, credentials, network, obfuscation, prompt injection) plus structure signals like scope, steps, and examples. The model writes the narrative, but it does not change the numbers, and it is also grounded only in that same text. Nothing in the pipeline receives the agent's tool list, MCP servers, shell access, or host permissions.
So a skill can look completely clean and still be dangerous if it is loaded into an agent that already has a shell or file-write tool. Those tools only exist at runtime, and this scan never sees them. A high score means "this document does not itself instruct risky behavior," not "this skill is safe in your agent's current permission set."
Accounting for the host would need a second input: the agent's available tools and permissions, scored together with the skill. That is not part of this report today.
@rahul_das42 that's a clean way to put it, "safe document" versus "safe in this agent" are genuinely two different claims and conflating them is where I'd worry someone gets burned. a lighter middle ground might be a manifest the skill author fills in themselves, stating what tool categories it expects to run with, shell, network, filesystem, whatever. doesn't need runtime integration, just makes the expected blast radius something the user compares against their own setup instead of inferring it from a prose description