snyk-agent-scan-complianceCompliance expert for snyk-agent-scan — the agent skill file scanner — NOT for other Snyk CLI tools (snyk test, snyk code SAST, snyk iac, snyk container). Fixes alerts through content restructuring, never by suppressing or deleting information. Covers every file in a skill directory: SKILL.md, references/, assets/, and any secondary markdown. Apply when authoring a new skill, editing an existing one, triaging a failed snyk-agent-scan run locally or in CI, or unblocking a PR held by agent scanner failures. Not applicable to dependency vulnerabilities, code security findings, or infrastructure misconfigurations — those are out of scope.
Install via ClawdBot CLI:
clawdbot install samber/snyk-agent-scan-complianceGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
curl | sh`, `wget | bashCalls external URL not in known-safe list
https://github.com/samber/cc-skillsAI Analysis
This skill is a compliance scanner for AI skill definitions and does not process user data or send it to external servers. The only external reference is to a public GitHub repository for documentation, which is consistent with the skill's purpose. The potential risks are limited to the execution of shell commands during installation, but these are standard package management operations.
Audited Apr 18, 2026 · audit v1.0
Generated Oct 4, 2026
An AI agent developer writing a new Claude Code skill runs snyk-agent-scan locally before publishing to catch W001, W011, and W012 patterns early. They use this skill to restructure imperative external-content fetches into passive hints and offload install commands to frontmatter. This prevents downstream PR blocks when the skill hits a shared registry.
A platform team enforces agent-skill scanner compliance as a required CI check across a monorepo of internal skills. When a contributor's PR fails on W011 or W012 alerts, this skill guides the contributor through content restructuring rather than suppression. The goal is passing the gate without losing documentation value.
A maintainer's PR is blocked by agent scanner failures on a marketplace or skill library, and they need to remediate multiple high-severity alerts efficiently. This skill provides alert-by-alert remediation order (W001, then W011, then W012) with re-scans after each fix. The maintainer preserves all original information while satisfying scanner rules.
A security engineer auditing externally-sourced skill directories needs to distinguish real prompt-injection risks from false positives flagged as W001/W011/W012. This skill interprets the alert taxonomy against concrete file content across SKILL.md, references, and assets. Restructuring removes unsafe patterns while keeping the skill functional.
A team migrating a legacy skill library to a scanner-enforced standard batch-remediates dozens of files without breaking behavior. They use the pattern catalogs for MCP tool naming, URL imperatives, and version pinning. Version pinning and frontmatter install blocks eliminate recurring W012 alerts across the library.
A freely licensed MIT skill distributed via GitHub that helps developers author scanner-compliant agent skills. Adoption grows through community contribution and inclusion in curated skill libraries. It complements the scanner tool without replacing it.
A paid add-on sold to enterprises that bundles scanner remediation guidance with CI policy enforcement for internal skill repositories. It reduces PR friction and enforces organizational content standards. Pricing is per-seat or per-repository within platform subscriptions.
A consultancy or platform offering that audits, remediates, and maintains agent skill directories against scanner policies for clients. Experts use the skill to perform restructuring at scale and certify compliance. Ongoing retainers cover new skills and policy changes.
💬 Integration Tip
Pair this skill with a CI step that runs snyk-agent-scan and fails the build on new alerts, so contributors get immediate feedback. Store SNYK_TOKEN as a repository secret and fall back to `uvx snyk-agent-scan@latest` when the binary is not installed.
Scored Oct 4, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. Runs SAST/DAST sc...