ant-skill-reviewSecurity scanner for Claude Code Skill packages. Use when the user wants to audit, review, or check the safety of a Skill before installing — e.g. "is this s...
Install via ClawdBot CLI:
clawdbot install antaisecuritylab/ant-skill-reviewGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Calls external URL not in known-safe list
https://registry.npmjs.org`Audited Apr 16, 2026 · audit v1.0
Generated May 11, 2026
A community manager for an open-source AI project wants to vet skill contributions before merging them. This scanner automates detection of prompt injection, credential theft, and malicious dependencies in contributed skill packages, ensuring only safe code is merged.
A security team at a large enterprise evaluates third-party skills for internal AI assistants used by employees. The scanner provides a risk score and recommendation, enabling the team to block high-risk skills that could exfiltrate sensitive corporate data.
A DevOps engineer integrates this scanner into a CI/CD pipeline to automatically scan skill packages before deployment. If a package scores 'high' or 'critical', the pipeline fails, preventing risky skills from reaching production.
A skill marketplace operator uses the scanner to pre-screen all submitted skills for security issues before listing them. This ensures a baseline of trust and safety for marketplace users, reducing the risk of malicious listings.
An individual developer considering installing a community-shared skill runs the scanner to quickly assess its safety. The clear risk level and recommendation help the developer make an informed decision without manual code review.
Offer the scanner as a hosted API or web service where users submit skill packages for analysis. Monetize via subscription tiers: free (basic pre-scan), pro (full analysis), and enterprise (CI/CD integration, custom rules).
Release the scanner as open-source (MIT/Apache) to build community adoption and trust. Generate revenue by selling commercial licenses for advanced features (deep analysis, custom reporting) and consulting/services for integration.
Partner with AI skill marketplaces to embed the scanner as a mandatory pre-listing check. Charge the marketplace a per-scan fee or a commission on each skill listed, providing a steady revenue stream from high-volume scanning.
💬 Integration Tip
To integrate, clone the repo and run `npm install`, then configure your LLM API key and base URL in a `.env` file or pass via `--config`; for CI/CD, use the `--json` flag to parse results programmatically.
Scored Jul 9, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...