aig-skill-scannerScan any agent skill for security risks before you install or use it. Powered by Tencent Zhuque Lab A.I.G (AI-Infra-Guard). 100% local static analysis — no f...
Install via ClawdBot CLI:
clawdbot install aigsec/aig-skill-scannerGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Calls external URL not in known-safe list
https://github.com/Tencent/AI-Infra-Guard/Audited Apr 18, 2026 · audit v1.0
Generated May 7, 2026
Before deploying AI agents across the organization, security teams can use EdgeOne Skill Scanner to audit all installed skills for vulnerabilities. This ensures no malicious or risky skills are present, protecting sensitive corporate data and maintaining compliance.
Developers using platforms like Cursor or CodeBuddy can scan a new skill before installation to check for code injection, data exfiltration, or other security issues. This prevents potential supply chain attacks from compromised community skills.
In healthcare or finance, where data privacy is critical, administrators can periodically scan all agent skills to ensure no skill violates regulations by accessing or transmitting protected information. The local-only analysis ensures no data leaves the device.
MSPs managing multiple client agents can use the scanner to evaluate skills from third-party vendors before recommending them. This helps avoid liabilities from insecure skills and builds trust with clients.
Organizations with a large number of skills can integrate the scanner into their CI/CD pipeline to automatically audit any new or updated skills. This ensures ongoing security without manual intervention.
Offer the basic skill scanning for free (local-only, limited to single skills). A premium tier provides full-platform scans, detailed vulnerability reports, and integration with SIEM systems. Revenue comes from monthly subscriptions for the premium version.
License the scanner as an integrated security feature to agent platform vendors (e.g., Cursor, Windsurf). Platforms bundle it as a built-in safety check, paying a per-user or per-instance fee. This leverages the scanner's compatibility with multiple platforms.
Offer expert security consulting to customize the scanner for specific enterprise environments, including custom rule sets, integration with existing workflows, and dedicated support. Revenue from consulting fees and annual maintenance contracts.
💬 Integration Tip
Start by scanning a single skill file to verify the tool works, then run a full-platform scan to identify all risky skills. Integrate into CI/CD for automated checks on new skills.
Scored May 7, 2026
Security vetting protocol before installing any AI agent skill. Red flag detection for credential theft, obfuscated code, exfiltration. Risk classification L...
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Comprehensive security auditing for Clawdbot deployments. Scans for exposed credentials, open ports, weak configs, and vulnerabilities. Auto-fix mode included.
Audit codebases and infrastructure for security issues. Use when scanning dependencies for vulnerabilities, detecting hardcoded secrets, checking OWASP top 10 issues, verifying SSL/TLS, auditing file permissions, or reviewing code for injection and auth flaws.
Audit a user's current AI tool stack. Score each tool by ROI, identify redundancies, gaps, and upgrade opportunities. Produces a structured report with score...
Detect anomalies and outliers in construction data: unusual costs, schedule variances, productivity spikes. Statistical and ML-based detection methods.