Securing AI Systems
trilwu/secskills
Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…
Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them.
$ npx skills add iflytek/skillhub --skill plugin-scanner -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install iflytek/skillhub plugin-scanner --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/iflytek/skillhub.git skills-src && mkdir -p .claude/skills && cp -r skills-src/builtin-skills/skills/plugin-scanner .claude/skills/plugin-scanner && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "plugin-scanner" agent skill from https://github.com/iflytek/skillhub/tree/main/builtin-skills/skills/plugin-scanner into .claude/skills/plugin-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "plugin-scanner", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/iflytek/skillhub/tree/main/builtin-skills/skills/plugin-scannerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add iflytek/skillhub --skill plugin-scanner -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install iflytek/skillhub plugin-scanner --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/iflytek/skillhub.git skills-src && mkdir -p .agents/skills && cp -r skills-src/builtin-skills/skills/plugin-scanner .agents/skills/plugin-scanner && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "plugin-scanner" agent skill from https://github.com/iflytek/skillhub/tree/main/builtin-skills/skills/plugin-scanner into .agents/skills/plugin-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "plugin-scanner", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add iflytek/skillhub --skill plugin-scanner -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install iflytek/skillhub plugin-scanner --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/iflytek/skillhub.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/builtin-skills/skills/plugin-scanner .cursor/skills/plugin-scanner && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "plugin-scanner" agent skill from https://github.com/iflytek/skillhub/tree/main/builtin-skills/skills/plugin-scanner into .cursor/skills/plugin-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "plugin-scanner", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/iflytek/skillhub.git --path builtin-skills/skills/plugin-scanner--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add iflytek/skillhub --skill plugin-scanner -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install iflytek/skillhub plugin-scanner --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/iflytek/skillhub.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/builtin-skills/skills/plugin-scanner .gemini/skills/plugin-scanner && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "plugin-scanner" agent skill from https://github.com/iflytek/skillhub/tree/main/builtin-skills/skills/plugin-scanner into .gemini/skills/plugin-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "plugin-scanner", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install iflytek/skillhub plugin-scannerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add iflytek/skillhub --skill plugin-scanner -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/iflytek/skillhub.git skills-src && mkdir -p .github/skills && cp -r skills-src/builtin-skills/skills/plugin-scanner .github/skills/plugin-scanner && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "plugin-scanner" agent skill from https://github.com/iflytek/skillhub/tree/main/builtin-skills/skills/plugin-scanner into .github/skills/plugin-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "plugin-scanner", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add iflytek/skillhub --skill plugin-scanner -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install iflytek/skillhub plugin-scanner --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/iflytek/skillhub.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/builtin-skills/skills/plugin-scanner .opencode/skills/plugin-scanner && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "plugin-scanner" agent skill from https://github.com/iflytek/skillhub/tree/main/builtin-skills/skills/plugin-scanner into .opencode/skills/plugin-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "plugin-scanner", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
plugin-scannerScan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them.
Plugin Scanner is an agent skill from iflytek/skillhub. Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them.
Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `NOTICE.md`).
It sits in Security, covering Prompt injection and agent security, Supply chain security and MCP servers. It works with Model Context Protocol. The repository describes itself as: Self-hosted, open-source agent skill registry for enterprises. Publish & version skill packages, govern with RBAC and audit logs, deploy on-premise with Docker or Kubernetes. The licence is Apache-2.0.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 7352597. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pipxFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.compypi.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Plugin Scanner loads about 1.1k tokens when it runs, and up to ~1.1k if it reads all its reference files. Until then it costs about 48 tokens; SKILL.md has 506 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
- Never read `.env` files, credential stores, private keys, or unrelated user secrets.Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from iflytek/skillhub at commit 7352597, republished under its Apache-2.0 licence (© iflytek). 506 words, ~1,105 tokens.
.claude/skills/plugin-scanner/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Use HOL's local plugin-scanner when a user asks to inspect an AI agent skill, plugin, MCP server, agent package, or repository before installation or use.
The scanner is shipped by the open-source plugin-scanner Python distribution. It is built from the same HOL Guard source repository, but it is intentionally packaged separately from the hol-guard runtime CLI. Scanning runs locally and does not require Guard Cloud.
Use this skill when the user asks to:
SKILL.md before installing it;.env files, credential stores, private keys, or unrelated user secrets.references/trusted-scanner.toml by absolute path and do not use a target-owned baseline.plugin-scanner if the command is not already available.command -v plugin-scannerIf it is not installed, explain that plugin-scanner is a separate open-source CLI distribution from the HOL Guard repository and, with user approval, install it in an isolated CLI environment:
pipx install plugin-scannerDo not assume an existing hol-guard installation also provides the plugin-scanner command. If pipx is unavailable, point the user to the plugin-scanner installation instructions rather than silently changing their Python environment.
Resolve references/trusted-scanner.toml relative to this SKILL.md and use its absolute path as TRUSTED_SCANNER_CONFIG. This prevents a target-owned .plugin-scanner.toml, .codex-plugin-scanner.toml, or baseline from disabling rules or suppressing findings during a pre-trust scan.
For a repository or directory:
plugin-scanner scan PATH --config "$TRUSTED_SCANNER_CONFIG" --profile strict-security --format markdownFor machine-readable results:
plugin-scanner scan PATH --config "$TRUSTED_SCANNER_CONFIG" --profile strict-security --format jsonFor Agent Skill / plugin structure validation:
plugin-scanner lint PATH --config "$TRUSTED_SCANNER_CONFIG" --profile strict-security
plugin-scanner verify PATHUse the narrowest target path that contains the material the user asked to inspect.
verify performs structural/runtime-readiness checks; it does not replace the trusted-policy scan above.
Summarize:
Do not claim "safe" solely because no finding was returned. Say that no covered issue was detected by the current scan.
© iflytek, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in builtin-skills/skills/plugin-scanner of iflytek/skillhub.
Open the folder on GitHubat commit 7352597
We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in iflytek/skillhub, which our catalogue first saw on October 7, 2026.
Plugin Scanner next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Plugin Scanner this skilliflytek/skillhub | 5.2k | 2 repos | ~1.1k | Automated safety check: Notes | Apache-2.0 | |
| Securing AI Systemstrilwu/secskills | 156 | — | ~2.9k | Automated safety check: Pass | MIT | |
| Forensifyalexgreensh/repo-forensics | 187 | — | ~2.5k | Automated safety check: Notes | Custom licence | |
| Skill InspectorNVIDIA/SkillSpector | 20k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | |
| MCP Server Security Auditawarexone/Agentic-Bug-Hunter | 5.3k | — | ~1.9k | Automated safety check: Warn | MIT | |
| Auditing MCP Servers For Tool Poisoningmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.7k | Automated safety check: Warn | Apache-2.0 |
trilwu/secskills
Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…
alexgreensh/repo-forensics
Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.
NVIDIA/SkillSpector
Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT.
awarexone/Agentic-Bug-Hunter
Audits MCP servers and their client configs for tool poisoning, prompt injection, over-privileged tools, injection bugs, secret leaks and missing approval gates.
mukul975/Anthropic-Cybersecurity-Skills
Audit MCP servers for tool poisoning, tool shadowing, rug pulls, SSRF, and unauthenticated exposure using Invariant Labs' mcp-scan for static/runtime scanning plus manual SSRF/auth checks and…
hashgraph-online/hol-guard
Run HOL Guard scanner and guard operations via uv run hol-guard.
iflytek/skillhub
Answers questions about a past agent run from its recording, using causal graphs and replay, instead of reconstructing events from memory.
iflytek/skillhub
Audits and rewrites formulaic, AI-sounding prose while keeping facts, voice and format, using a local Python scorer and inspect-only, rewrite or embedded-gate modes.
iflytek/skillhub
Access 2,000+ AI models and API tools through one MCP interface for inference, media generation, search, scraping, embeddings, social data, and structured retrieval.
iflytek/skillhub
Drafts a copy-paste-ready LinkedIn post from your facts and ideas, choosing the smallest structure that fits and keeping an accessible plain-text fallback for any styled text.
iflytek/skillhub
Connects an agent to a SkillHub registry and uses the official SkillHub CLI to search, install, list and explicitly upgrade skills from that registry.
iflytek/skillhub
Breaks AI-generated text into checkable claims, verifies them against independent sources and labels each one, with an optional exercise for learners.
Works with
Categories
Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them. Plugin Scanner is an agent skill from iflytek/skillhub. Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them.
Plugin Scanner fits situations like: tasks that involve Prompt injection and agent security; tasks that involve Supply chain security; tasks that involve MCP servers.
Run `npx skills add iflytek/skillhub --skill plugin-scanner -a claude-code`. Or copy the skill folder (builtin-skills/skills/plugin-scanner in iflytek/skillhub) into .claude/skills/plugin-scanner in your project. Claude Code loads it when a task matches its description.
Run `npx skills add iflytek/skillhub --skill plugin-scanner -a codex`. Or copy the skill folder (builtin-skills/skills/plugin-scanner in iflytek/skillhub) into .agents/skills/plugin-scanner in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add iflytek/skillhub --skill plugin-scanner -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/plugin-scanner, .gemini/skills/plugin-scanner, .github/skills/plugin-scanner and .opencode/skills/plugin-scanner in your project.
Going by SKILL.md and its folder, Plugin Scanner needs the command-line tools its instructions call (pipx). Our summary lists: Python 3.
SKILL.md names 2 domains. As links in the text: github.com and pypi.org. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Plugin Scanner is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.1k tokens (SKILL.md is roughly 4.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 16 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Plugin Scanner: Securing AI Systems (trilwu/secskills, 156 stars), Forensify (alexgreensh/repo-forensics, 187 stars), Skill Inspector (NVIDIA/SkillSpector, 20k stars) and MCP Server Security Audit (awarexone/Agentic-Bug-Hunter, 5.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
iflytek (a GitHub organization) maintains it in iflytek/skillhub, which has 5,152 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 1, 2026.
Source: iflytek/skillhub on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.