Plugin Scanner
iflytek/skillhub
Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them.
Audit agent skills, plugins, prompts, manifests, scripts, dependencies, and bundled assets for provenance, prompt-injection, permission, execution, exfiltration, persistence, and update risk.
$ npx skills add seb1n/awesome-ai-agent-skills --skill skill-supply-chain-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install seb1n/awesome-ai-agent-skills skill-supply-chain-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/seb1n/awesome-ai-agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agent-security/skill-supply-chain-audit .claude/skills/skill-supply-chain-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "skill-supply-chain-audit" agent skill from https://github.com/seb1n/awesome-ai-agent-skills/tree/main/agent-security/skill-supply-chain-audit into .claude/skills/skill-supply-chain-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skill-supply-chain-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/seb1n/awesome-ai-agent-skills/tree/main/agent-security/skill-supply-chain-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add seb1n/awesome-ai-agent-skills --skill skill-supply-chain-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install seb1n/awesome-ai-agent-skills skill-supply-chain-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/seb1n/awesome-ai-agent-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/agent-security/skill-supply-chain-audit .agents/skills/skill-supply-chain-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "skill-supply-chain-audit" agent skill from https://github.com/seb1n/awesome-ai-agent-skills/tree/main/agent-security/skill-supply-chain-audit into .agents/skills/skill-supply-chain-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skill-supply-chain-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add seb1n/awesome-ai-agent-skills --skill skill-supply-chain-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install seb1n/awesome-ai-agent-skills skill-supply-chain-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/seb1n/awesome-ai-agent-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/agent-security/skill-supply-chain-audit .cursor/skills/skill-supply-chain-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "skill-supply-chain-audit" agent skill from https://github.com/seb1n/awesome-ai-agent-skills/tree/main/agent-security/skill-supply-chain-audit into .cursor/skills/skill-supply-chain-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skill-supply-chain-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/seb1n/awesome-ai-agent-skills.git --path agent-security/skill-supply-chain-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add seb1n/awesome-ai-agent-skills --skill skill-supply-chain-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install seb1n/awesome-ai-agent-skills skill-supply-chain-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/seb1n/awesome-ai-agent-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/agent-security/skill-supply-chain-audit .gemini/skills/skill-supply-chain-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "skill-supply-chain-audit" agent skill from https://github.com/seb1n/awesome-ai-agent-skills/tree/main/agent-security/skill-supply-chain-audit into .gemini/skills/skill-supply-chain-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skill-supply-chain-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install seb1n/awesome-ai-agent-skills skill-supply-chain-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add seb1n/awesome-ai-agent-skills --skill skill-supply-chain-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/seb1n/awesome-ai-agent-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/agent-security/skill-supply-chain-audit .github/skills/skill-supply-chain-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "skill-supply-chain-audit" agent skill from https://github.com/seb1n/awesome-ai-agent-skills/tree/main/agent-security/skill-supply-chain-audit into .github/skills/skill-supply-chain-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skill-supply-chain-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add seb1n/awesome-ai-agent-skills --skill skill-supply-chain-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install seb1n/awesome-ai-agent-skills skill-supply-chain-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/seb1n/awesome-ai-agent-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/agent-security/skill-supply-chain-audit .opencode/skills/skill-supply-chain-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "skill-supply-chain-audit" agent skill from https://github.com/seb1n/awesome-ai-agent-skills/tree/main/agent-security/skill-supply-chain-audit into .opencode/skills/skill-supply-chain-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skill-supply-chain-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skill-supply-chain-auditAudit agent skills, plugins, prompts, manifests, scripts, dependencies, and bundled assets for provenance, prompt-injection, permission, execution, exfiltration, persistence, and update risk.
Skill Supply Chain Audit is an agent skill from seb1n/awesome-ai-agent-skills. Audit agent skills, plugins, prompts, manifests, scripts, dependencies, and bundled assets for provenance, prompt-injection, permission, execution, exfiltration, persistence, and update risk. Use when evaluating a third-party skill before installing, enabling, updating, publishing, or distributing it; reviewing an untrusted SKILL.md, agent configuration, MCP integration, archive, or repository; comparing a package with a known-good version; or investigating unexpected tool, network, credential, or filesystem…
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts, reference files and assets (for example `agents/openai.yaml`, `assets/audit-report-template.md` and `references/review-checklist.md`).
It sits in Security, covering Supply chain security, Prompt injection and agent security and MCP servers. The repository describes itself as: 103 ready-to-use AI agent skills for Claude Code, OpenAI Codex, Gemini CLI, Cursor, GitHub Copilot, Windsurf, and other Agent Skills-compatible tools. Complete SKILL.md… The licence is MIT.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 75865a5. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
python3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Skill Supply Chain Audit loads about 2.4k tokens when it runs, and up to ~3.4k if it reads all its reference files. Until then it costs about 137 tokens; SKILL.md has 1,150 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from seb1n/awesome-ai-agent-skills at commit 75865a5, republished under its MIT licence (© seb1n). 1,150 words, ~2,448 tokens.
.claude/skills/skill-supply-chain-audit/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Treat the target as untrusted. Produce an evidence-backed disposition without executing package code by default.
Collect or state:
If provenance or version is unknown, record it as unknown; do not infer trust from popularity.
Return:
approve, approve-with-constraints, quarantine, or reject.Label each claim observed, inferred, or unknown. A clean heuristic scan is not proof of safety.
Record the source URL, commit/tag, acquisition time, publisher claim, license, and cryptographic hashes. Run the bundled scanner from this skill directory:
python3 scripts/audit_skill.py /path/to/target --pretty
python3 scripts/audit_skill.py /path/to/new --baseline /path/to/known-good --pretty
python3 scripts/audit_skill.py /path/to/target --output /path/outside-target/audit.json --prettyThe scanner uses only the Python standard library and performs static heuristics. For ZIP/TAR files it reads member metadata without extraction, records path/link/type/size and expansion hazards, and calculates a canonical member-manifest hash. It also calculates a canonical package-manifest hash from sorted path/type/size/content-hash records. With --output, it refuses input aliases, non-regular destinations, and any destination inside the target or baseline directory, then atomically creates or replaces the report via a sibling temporary file. Review its output manually. Read review-checklist.md for the full evidence checklist and severity model.
Resolve every entry in content_review_queue before approve: these files exceeded the 1 MB pattern-scan limit. Perform a bounded read-only chunked/manual review with an appropriate parser, or record why opaque content is necessary and constrain it. A hash alone does not close the review. Treat content_pattern_scan_complete: false or archive_metadata_inspection_complete: false as an explicit coverage gap.
Confirm the folder name, frontmatter name, and description agree. Check whether the activation description is unnecessarily broad or hides privileged behavior. Trace instructions that attempt to:
Separate ordinary operational guidance from instructions that change authority.
Inspect every executable and manifest. Identify subprocess use, dynamic evaluation, shell interpolation, destructive commands, broad paths, network clients, remote installers, telemetry, credential access, and write destinations. Verify:
Do not assume text-only files are harmless; prompts can delegate dangerous actions to an agent.
For each capability, map source -> processing -> destination -> retention. Apply least privilege to filesystem roots, commands, network domains, accounts, and write APIs. Flag any capability not required by the claimed purpose. Treat external writes, messages, purchases, deployments, deletion, and credential changes as approval-gated even if the package says otherwise.
For updates, review the exact diff and newly introduced dependencies, permissions, endpoints, and generated artifacts. Re-run the static inventory against both versions. Verify release signatures or checksums when the publisher provides them; absence of a signature is an evidence gap, not proof of compromise.
approve: no unresolved material findings and permissions fit the purpose.approve-with-constraints: risks are bounded by explicit sandbox, domain, account, or approval controls.quarantine: evidence is incomplete, opaque, or needs controlled dynamic analysis.reject: observed behavior violates authority, integrity, confidentiality, or claimed purpose.Use audit-report-template.md for the deliverable. Mark each report statement observed, inferred, or unknown; do not blur an observed string/metadata fact into an inferred behavior claim. Do not downgrade a finding merely because exploitation has not been observed.
Re-run the static scan after remediation and confirm canonical package/member-manifest hashes. Manually inspect every high-impact path, every unresolved file in content_review_queue, and a representative sample of lower-risk files. Perform dynamic testing only with explicit authorization, disposable credentials, synthetic data, blocked-by-default networking, a temporary filesystem, resource limits, and complete logs. State which behavior remained untested.
If untrusted code was accidentally executed, stop it, preserve logs and hashes, disconnect only the affected environment if authorized, identify exposed credentials and destinations, and recommend credential revocation through the system owner. Restore from a known-good snapshot rather than attempting an unverified cleanup. Document what is known and unknown; do not erase evidence.
Request: “Audit this downloaded scheduling skill before I add it to Codex.”
Deliver an offline static inventory, flag that its calendar purpose does not justify reading shell history, recommend a calendar-only account and domain allowlist, and choose approve-with-constraints or stronger based on exact evidence.
Request: “Version 1.4 added an installer and a new MCP endpoint. Is the update safe?”
Compare 1.4 with the trusted version, enumerate new files and URLs, inspect lifecycle hooks and permission expansion, verify publisher evidence, and quarantine the update if the endpoint or installer cannot be attributed.
Request: “After enabling this skill, a token appeared in outbound logs.”
Preserve the package version and logs, identify observed credential access and destinations, avoid further execution, recommend containment and token rotation to the authorized owner, and issue a time-bounded incident report without claiming causation beyond the evidence.
© seb1n, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in agent-security/skill-supply-chain-audit of seb1n/awesome-ai-agent-skills.
Open the folder on GitHubat commit 75865a5
Skill Supply Chain Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Skill Supply Chain Audit this skillseb1n/awesome-ai-agent-skills | 206 | — | ~2.4k | Automated safety check: Pass | MIT | |
| Plugin Scanneriflytek/skillhub | 5.2k | 2 repos | ~1.1k | Automated safety check: Notes | Apache-2.0 | |
| Securing AI Systemstrilwu/secskills | 157 | — | ~2.9k | Automated safety check: Pass | MIT | |
| Skill Scannergetsentry/skills | 1k | 4 repos | ~2.5k | Automated safety check: Warn | Apache-2.0 | |
| Forensifyalexgreensh/repo-forensics | 190 | — | ~2.5k | Automated safety check: Notes | Custom licence | |
| Hol Guardhashgraph-online/hol-guard | 838 | — | ~542 | Automated safety check: Pass | Apache-2.0 |
iflytek/skillhub
Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them.
trilwu/secskills
Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…
getsentry/skills
Scan agent skills for security issues. An agent skill from getsentry/skills.
alexgreensh/repo-forensics
Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.
hashgraph-online/hol-guard
Run HOL Guard scanner and guard operations via uv run hol-guard.
cdppcorp/KESE-KIT
Run a pre-deployment security compliance checklist based on KISA guidelines.
seb1n/awesome-ai-agent-skills
Plan, execute, document, and retest authorized security assessments of AI agents and multi-agent workflows using safe adversarial cases, synthetic identities, canaries, and evidence-based findings.
seb1n/awesome-ai-agent-skills
Build a preliminary, evidence-based EU AI Act readiness assessment across AI-system inventory, territorial scope, operator roles, prohibited-practice screening, risk classification, transparency…
seb1n/awesome-ai-agent-skills
Design and verify auditable human oversight, approval gates, escalation paths, and safe state transitions for AI agent workflows.
seb1n/awesome-ai-agent-skills
Design, implement, harden, and verify Model Context Protocol (MCP) servers with precise tool contracts, least-privilege authorization, safe transports, structured errors, and interoperability tests.
seb1n/awesome-ai-agent-skills
Inspect, extract, OCR, create, merge, split, reorder, rotate, annotate, fill, redact, compress, secure, and verify PDF documents while preserving source files and visual fidelity.
seb1n/awesome-ai-agent-skills
Inspect, profile, clean, reconcile, analyze, visualize, and verify spreadsheet data while preserving formulas, formatting, types, and source files.
Categories
Audit agent skills, plugins, prompts, manifests, scripts, dependencies, and bundled assets for provenance, prompt-injection, permission, execution, exfiltration, persistence, and update risk. Skill Supply Chain Audit is an agent skill from seb1n/awesome-ai-agent-skills. Audit agent skills, plugins, prompts, manifests, scripts, dependencies, and bundled assets for provenance, prompt-injection, permission, execution, exfiltration, persistence, and update risk.
Skill Supply Chain Audit fits situations like: evaluating a third-party skill before installing; distributing it; reviewing an untrusted SKILL.md; agent configuration.
Run `npx skills add seb1n/awesome-ai-agent-skills --skill skill-supply-chain-audit -a claude-code`. Or copy the skill folder (agent-security/skill-supply-chain-audit in seb1n/awesome-ai-agent-skills) into .claude/skills/skill-supply-chain-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add seb1n/awesome-ai-agent-skills --skill skill-supply-chain-audit -a codex`. Or copy the skill folder (agent-security/skill-supply-chain-audit in seb1n/awesome-ai-agent-skills) into .agents/skills/skill-supply-chain-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add seb1n/awesome-ai-agent-skills --skill skill-supply-chain-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/skill-supply-chain-audit, .gemini/skills/skill-supply-chain-audit, .github/skills/skill-supply-chain-audit and .opencode/skills/skill-supply-chain-audit in your project.
Going by SKILL.md and its folder, Skill Supply Chain Audit needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Skill Supply Chain Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 916 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Skill Supply Chain Audit: Plugin Scanner (iflytek/skillhub, 5.2k stars), Securing AI Systems (trilwu/secskills, 157 stars), Skill Scanner (getsentry/skills, 1k stars) and Forensify (alexgreensh/repo-forensics, 190 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
seb1n (a GitHub user) maintains it in seb1n/awesome-ai-agent-skills, which has 206 GitHub stars. The repository holds 101 skills in this directory. The repository was last updated on August 9, 2026.
Source: seb1n/awesome-ai-agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.