@skillsafe-team/scan-before-install

Scan any GitHub-hosted AI skill for security issues with the SkillSafe API before installing it, and interpret the verdict.

View in AI SkillSafe app
Scanned · no findings
1 downloads
0 stars
0 demos
SKILL.md
namescan-before-install
descriptionScan any GitHub-hosted AI skill for security issues with the SkillSafe API before installing it. Use when the user asks to install a skill from GitHub, wants to check whether a skill is safe, or mentions vetting third-party agent skills.

Scan a skill before installing it

Before installing any third-party skill, scan it with SkillSafe's free public scanner and review the verdict. No account or API key is required.

Steps

  1. Submit the repository for scanning:

    curl -s -X POST https://api.skillsafe.ai/v1/scan/github \
      -H "content-type: application/json" \
      -d '{"github_url": "https://github.com/OWNER/REPO"}'
    

    The response includes a scan_id and, for small repos, immediate results.

  2. Poll for the result if the scan is queued:

    curl -s https://api.skillsafe.ai/v1/scan/github/SCAN_ID
    
  3. Interpret the report:

    • clean: true with grade A+/A — no threats found; safe to proceed.
    • Grade B/C — review each finding; medium findings are often capability flags (network access, subprocess use) that may be legitimate for the skill's purpose. Check the Bill of Materials to see whether the capabilities match what the skill claims to do.
    • Grade D/F or any critical finding — do not install. Common critical patterns: base64 decode-and-execute, writes to agent memory or instruction files, exfiltration to webhook services, credential harvesting.
  4. Cross-check the rule ids against the published ruleset at https://skillsafe.ai/security/ruleset_v2026.06.05/ if any finding is unclear, and show the user a short summary before they decide.

Notes

  • A clean scan is point-in-time: re-scan when the repository updates.
  • For skills installed from the SkillSafe registry, prefer the built-in dual-side verification (npx skills add https://api.skillsafe.ai/{ns}/{name}), which re-checks the content hash at install time.

Published by the SkillSafe team as a reference skill. Source: https://github.com/skillsafe/skillsafe.ai-website/tree/main/examples/skills/

Embed badges

Add these to your README to show the skill's verification status.

SkillSafe verified badge
Verified badge
[![SkillSafe verified badge](https://api.skillsafe.ai/v1/badge/@skillsafe-team/scan-before-install/verified)](https://skillsafe.ai/skill/@skillsafe-team/scan-before-install/)
Installs badge
Installs badge
[![Installs badge](https://api.skillsafe.ai/v1/badge/@skillsafe-team/scan-before-install/installs)](https://skillsafe.ai/skill/@skillsafe-team/scan-before-install/)
Scan badge
Scan badge
[![Scan badge](https://api.skillsafe.ai/v1/badge/@skillsafe-team/scan-before-install/scan)](https://skillsafe.ai/skill/@skillsafe-team/scan-before-install/)
Eval pass rate badge
Eval pass rate
[![Eval pass rate badge](https://api.skillsafe.ai/v1/badge/@skillsafe-team/scan-before-install/eval)](https://skillsafe.ai/skill/@skillsafe-team/scan-before-install/)