Security scanner for AI agent skills and prompts. Detects credential theft, prompt injection, zero-width character attacks, and ClawHavoc malware indicators.
SkillsSafe defines 2 tools with clear, domain-specific purposes. Both tools have well-written descriptions (200+ chars) that explain WHAT they do, WHEN to use them, and what they return. Input schemas are present and properly typed with JSON Schema. The scan_skill tool uses oneOf to enforce mutually exclusive parameters (url vs content), which is sophisticated. However, output schemas are not documented, the response structure is not formally specified, forcing LLMs to infer what fields to expect. Error handling is mentioned in descriptions but not formalized with recovery guidance. Tool names follow verb_noun convention (scan_skill, get_report) and are unambiguous. Parameters are well-described with enums (lang) and clear constraints. No security issues detected, no credentials exposed as parameters.
Retrieve a previously generated scan report by scan_id. Returns a link to the full report page at skillssafe.com.
Scan an AI agent skill file (SKILL.md, MCP tool config, or system_prompt) for security threats before installation. Detects credential theft, data exfiltration, prompt injection, hidden zero-width characters, shell injection, reverse shells, memory poisoning, scope creep, and ClawHavoc malware indicators. Returns INSTALL/REVIEW/BLOCK decision with risk score 0–100. Free, no API key required. Supports OpenClaw, Claude Code, Cursor, and Codex skills.
Output schemas not documented. scan_skill and get_report descriptions mention return values (INSTALL/REVIEW/BLOCK decision, risk score, threats found, report link) but no formal schema is provided. LLMs cannot plan downstream operations or extract structured data without knowing the response shape.
Error handling lacks recovery guidance. Descriptions do not specify what errors can occur (e.g., invalid URL, timeout, malformed content) or how the LLM should respond. A tool that scans external URLs should document timeout behavior and retry strategy.
scan_skill accepts 'url' parameter but does not document URL format constraints or supported schemes. Description says 'ClawHub URLs, GitHub raw URLs, or any HTTP-accessible' but no regex pattern or length limit is specified. LLMs may pass invalid URLs.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | A | 82 | 2026-07-28+ | v2 |
scan_skill 'content' parameter lacks size constraints. No maximum length specified for the raw text input. Large payloads could cause timeouts or memory issues. Should document max content size (e.g., 1MB).
get_report 'scan_id' parameter description is minimal ('The scan ID (e.g. ss_a3f8c901_...)') and relies on example format. Should document the scan_id format explicitly (e.g., 'Format: ss_[hex]_[hex], generated by scan_skill') to prevent LLM hallucination of invalid IDs.