Skill Security Auditor
Security audit and vulnerability scanner for AI agent skills before installation. Use when: (1) evaluating a skill from an untrusted source, (2) auditing a skill directory or git repo URL for malicious code, (3) pre-install security gate for Claude Code plugins, OpenClaw skills, or Codex skills, (4) scanning Python scripts for dangerous patterns like os.system, eval, subprocess, network exfiltration, (5) detecting prompt injection in SKILL.md files, (6) checking dependency supply chain risks, (7) verifying file system access stays within skill boundaries. Triggers: "audit this skill", "is this skill safe", "scan skill for security", "check skill before install", "skill security check", "skill vulnerability scan".
Works with: Claude Code, Cursor, Codex CLI
Category: Security — see all ranked ›
Work: Security review · Agent configuration
Who it is for: Security engineer · Agent operator
- Adoption: 1 repos
- Health: active
- GitHub stars: 23,181
- Contributors: 30
- License: MIT
Security audit
Not scanned yet. We audit npm-published capabilities for known advisories, install-time scripts and permission surface; this one has no npm package we can resolve, or has not reached the queue.
source ↗ · skill:alirezarezvani/skill-security-auditor
Already running this? npx tashan-cli doctor checks your whole config against the Index — how it works ›