snyk-skill-scannerScan installed agent components (MCP servers, skills, agent tools) for security vulnerabilities using snyk-agent-scan. Use only when running uvx snyk-agent-s...
Install via ClawdBot CLI:
clawdbot install SwiftKing100/snyk-skill-scannerGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Sends data to undocumented external endpoint (potential exfiltration)
report → https://github.com/snyk/agent-scan/blob/main/docs/issue-codes.mdCalls external URL not in known-safe list
https://astral.sh/uv/install.shAI Analysis
The skill's primary function is to execute a local security scanner (snyk-agent-scan) via uvx, which aligns with its stated auditing purpose. The external URLs referenced are for downloading the scanner tool (uv installer, documentation) and do not indicate active data exfiltration or credential harvesting. The risk is low as the user explicitly invokes the scan and controls the target paths.
Audited Apr 16, 2026 · audit v1.0
Generated Mar 21, 2026
Development teams building AI agents can use this skill to scan newly developed or third-party skills and MCP servers before deployment. It helps identify high-risk vulnerabilities like prompt injection or malware, ensuring only secure components are integrated into production agents.
Large organizations implementing AI agents for internal or customer-facing use can integrate this skill into their CI/CD pipelines. It automates security checks to comply with regulatory standards by detecting credential leaks and untrusted content, reducing legal and operational risks.
Maintainers of open-source AI projects can use this skill to regularly audit contributed skills and dependencies for security issues. This prevents the introduction of malicious code like tool poisoning, safeguarding the project's integrity and user trust.
Freelancers or consultants customizing AI agents for clients can run scans before delivering solutions. This ensures the final product is free from high-severity vulnerabilities like toxic flows, providing added value and reducing post-deployment support issues.
Offer a subscription-based service where clients pay a monthly fee for automated, ongoing security scans of their AI agent components. This model generates recurring revenue by providing continuous vulnerability monitoring and compliance reports.
Sell enterprise licenses that include custom integrations, priority support, and advanced features like detailed analytics. This targets large organizations needing tailored security solutions for their AI infrastructure, with high upfront or annual licensing fees.
Provide a free basic version for individual developers or small teams, with limited scans. Monetize through premium tiers offering faster scans, more detailed reports, and API access for automation, appealing to growing businesses.
💬 Integration Tip
Integrate this skill into your CI/CD pipeline by running uvx snyk-agent-scan commands automatically during build processes to catch vulnerabilities early.
Scored Apr 19, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...