@skillsafe-team/scan-before-install
Scan any GitHub-hosted AI skill for security issues with the SkillSafe API before installing it, and interpret the verdict.
| name | scan-before-install |
| description | Scan any GitHub-hosted AI skill for security issues with the SkillSafe API before installing it. Use when the user asks to install a skill from GitHub, wants to check whether a skill is safe, or mentions vetting third-party agent skills. |
Scan a skill before installing it
Before installing any third-party skill, scan it with SkillSafe's free public scanner and review the verdict. No account or API key is required.
Steps
Submit the repository for scanning:
curl -s -X POST https://api.skillsafe.ai/v1/scan/github \ -H "content-type: application/json" \ -d '{"github_url": "https://github.com/OWNER/REPO"}'The response includes a
scan_idand, for small repos, immediate results.Poll for the result if the scan is queued:
curl -s https://api.skillsafe.ai/v1/scan/github/SCAN_IDInterpret the report:
clean: truewith gradeA+/A— no threats found; safe to proceed.- Grade
B/C— review each finding; medium findings are often capability flags (network access, subprocess use) that may be legitimate for the skill's purpose. Check the Bill of Materials to see whether the capabilities match what the skill claims to do. - Grade
D/For anycriticalfinding — do not install. Common critical patterns: base64 decode-and-execute, writes to agent memory or instruction files, exfiltration to webhook services, credential harvesting.
Cross-check the rule ids against the published ruleset at
https://skillsafe.ai/security/ruleset_v2026.06.05/if any finding is unclear, and show the user a short summary before they decide.
Notes
- A clean scan is point-in-time: re-scan when the repository updates.
- For skills installed from the SkillSafe registry, prefer the built-in
dual-side verification (
npx skills add https://api.skillsafe.ai/{ns}/{name}), which re-checks the content hash at install time.
Published by the SkillSafe team as a reference skill. Source: https://github.com/skillsafe/skillsafe.ai-website/tree/main/examples/skills/
Loading...
Select a file to preview
Analyzing security...
Checking scan reports and verification data.
Bill of Materials
Everything this skill can do — files, network, commands, and more.