aig-skill-scannerScan any agent skill for security risks before you install or use it. Powered by Tencent Zhuque Lab A.I.G (AI-Infra-Guard). 100% local static analysis — no f...
Install via ClawdBot CLI:
clawdbot install aigsec/aig-skill-scannerGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Calls external URL not in known-safe list
https://github.com/Tencent/AI-Infra-Guard/Audited Apr 18, 2026 · audit v1.0
Generated May 7, 2026
Before deploying AI agents across the organization, security teams can use EdgeOne Skill Scanner to audit all installed skills for vulnerabilities. This ensures no malicious or risky skills are present, protecting sensitive corporate data and maintaining compliance.
Developers using platforms like Cursor or CodeBuddy can scan a new skill before installation to check for code injection, data exfiltration, or other security issues. This prevents potential supply chain attacks from compromised community skills.
In healthcare or finance, where data privacy is critical, administrators can periodically scan all agent skills to ensure no skill violates regulations by accessing or transmitting protected information. The local-only analysis ensures no data leaves the device.
MSPs managing multiple client agents can use the scanner to evaluate skills from third-party vendors before recommending them. This helps avoid liabilities from insecure skills and builds trust with clients.
Organizations with a large number of skills can integrate the scanner into their CI/CD pipeline to automatically audit any new or updated skills. This ensures ongoing security without manual intervention.
Offer the basic skill scanning for free (local-only, limited to single skills). A premium tier provides full-platform scans, detailed vulnerability reports, and integration with SIEM systems. Revenue comes from monthly subscriptions for the premium version.
License the scanner as an integrated security feature to agent platform vendors (e.g., Cursor, Windsurf). Platforms bundle it as a built-in safety check, paying a per-user or per-instance fee. This leverages the scanner's compatibility with multiple platforms.
Offer expert security consulting to customize the scanner for specific enterprise environments, including custom rule sets, integration with existing workflows, and dedicated support. Revenue from consulting fees and annual maintenance contracts.
💬 Integration Tip
Start by scanning a single skill file to verify the tool works, then run a full-platform scan to identify all risky skills. Integrate into CI/CD for automated checks on new skills.
Scored Jun 29, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...