Agent skill

Skill Scanner

by zrt-ai-lab in zrt-ai-lab/opencode-skills

A skill your agent uses when reviewing an agent Skill before sharing, installing, or executing it and when checking a Skill bundle for credentials, dangerous commands, suspicious network behavior…

No licenceAuto-check passedSecurity

Install Skill Scanner

skills CLI
$ npx skills add zrt-ai-lab/opencode-skills --skill skill-scanner -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install zrt-ai-lab/opencode-skills skill-scanner --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/zrt-ai-lab/opencode-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skill-scanner .claude/skills/skill-scanner && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
skill-scanner
GitHub stars
287
Token cost
~317 tokens
SKILL.md length
70 words
Files
4 (incl. scripts)
Skills in repo
26
Repo updated
First seen
Licence
None found

At a glance

A skill your agent uses when reviewing an agent Skill before sharing, installing, or executing it and when checking a Skill bundle for credentials, dangerous commands, suspicious network behavior…

  • Works in 5 steps: 读取目标 Skill 的文件清单,确认扫描范围。 → 执行 Markdown 报告和 JSON 报告两种模式。 → 优先处理 critical、high,再判断 medium 是否为明确业务需要。 → …
  • Reviewing an agent Skill before sharing
  • SKILL.md covers 触发场景, 安全边界, 使用方式 and 标准流程, plus 2 more sections
  • Runs Python scripts from its folder; calls python3

What it does

Skill Scanner is an agent skill from zrt-ai-lab/opencode-skills. Use when reviewing an agent Skill before sharing, installing, or executing it and when checking a Skill bundle for credentials, dangerous commands, suspicious network behavior, or obfuscated code.

Its SKILL.md is about 320 tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts (for example `README.md`, `scripts/scan_skill.py` and `tests/test_scan_skill.py`).

It sits in Security, covering Prompt injection and agent security. The repository describes itself as: OpenCode/Claude Code 技能库 。特色技能:视频生成、图片生成、AI Agent 互联、智能问数等等各场景,持续开发更新中.

When your agent uses it

  • Reviewing an agent Skill before sharing
  • Executing it and when checking a Skill bundle for credentials
  • Dangerous commands
  • Suspicious network behavior

Example prompts

  • “/skill-scanner”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. 读取目标 Skill 的文件清单,确认扫描范围。
  2. 执行 Markdown 报告和 JSON 报告两种模式。
  3. 优先处理 critical、high,再判断 medium 是否为明确业务需要。
  4. 核对报告中的相对路径和行号;不要要求工具回显敏感内容。
  5. 清理或隔离问题后重新扫描,并保存不含敏感值的报告。

What it can do on your machine

Read from SKILL.md and the folder at commit d38536f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Skill Scanner loads about 317 tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 70 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~317

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 70 words (~317 tokens).

name
skill-scanner

Read the full SKILL.md on GitHub

Files

SKILL.md and 3 other files (scripts) in skill-scanner of zrt-ai-lab/opencode-skills.

  • SKILL.md
  • README.md
  • scripts/scan_skill.py
  • tests/test_scan_skill.py

Open the folder on GitHubat commit d38536f

Compare with similar skills

Skill Scanner next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Skill Scanner compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Skill Scanner this skillzrt-ai-lab/opencode-skills287—~317Automated safety check: PassNone
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Forensifyalexgreensh/repo-forensics188—~2.5kAutomated safety check: NotesCustom licence
Hol Guardhashgraph-online/hol-guard827—~542Automated safety check: PassApache-2.0
Kesekit Checkcdppcorp/KESE-KIT361—~1.3kAutomated safety check: PassMIT
Setuphashgraph-online/hol-guard827—~443Automated safety check: PassApache-2.0

Similar skills

  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    188 GitHub stars~2.5k tokensUpdated 12 days ago
    SecurityAuto-check: notes
  • Hol Guard

    hashgraph-online/hol-guard

    Run HOL Guard scanner and guard operations via uv run hol-guard.

    827 GitHub stars~542 tokensUpdated today
    SecurityAuto-check passed
  • Kesekit Check

    cdppcorp/KESE-KIT

    Run a pre-deployment security compliance checklist based on KISA guidelines.

    361 GitHub stars~1.3k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Setup

    hashgraph-online/hol-guard

    Install or initialize HOL Guard local runtime protection for Claude Code.

    827 GitHub stars~443 tokensUpdated today
    SecurityAuto-check passed
  • Clawscan CLI

    openclaw/clawscan

    A skill your agent uses when running or explaining the ClawScan CLI, including one-off agent-skill scans, benchmark runs, scanner fixtures, judge harness commands, env var validation, and…

    143 GitHub stars~3k tokensUpdated yesterday
    SecurityAuto-check passed

More from zrt-ai-lab/opencode-skills

All 26 skills in this repo
  • Wechat Publisher

    zrt-ai-lab/opencode-skills

    This skill should be used when preparing Markdown articles for a WeChat Official Account draft box, selecting wenyan-cli themes, processing article images, or troubleshooting authentication and…

    287 GitHub stars~465 tokensUpdated 2 mo ago
    Auto-check passed
  • Codex Image Service

    zrt-ai-lab/opencode-skills

    A skill your agent uses when Codex needs native image generation, editing, or engineered multi-image composition, especially sets, material kits, grids, storyboards, carousels, presentations…

    287 GitHub stars~2k tokensUpdated 2 mo ago
    Auto-check passed
  • Smart Query

    zrt-ai-lab/opencode-skills

    智能数据库查询技能。通过SSH隧道连接线上数据库,支持自然语言转SQL、执行查询、表结构探索。当用户需要查询数据库、问数据、看表结构时使用此技能。

    287 GitHub stars~484 tokensUpdated 2 mo ago
    Auto-check passed
  • Video Creator

    zrt-ai-lab/opencode-skills

    视频创作技能。图片+音频合成视频,支持TTS配音、淡入淡出转场、字幕、片尾、BGM。当用户提到「生成视频」「做视频」「教学视频」「图文转视频」「做视频号」「配音视频」「图文结合视频」「古诗视频」「故事视频」时触发。内含生图→配音→合成全流程,无需单独调用image-service。

    287 GitHub stars~3.3k tokensUpdated 2 mo ago
    Auto-check passed
  • Searchnews

    zrt-ai-lab/opencode-skills

    当用户要求"搜索新闻"、"查询AI新闻"、"整理新闻"、"获取某天的新闻",或提到需要搜索、整理、汇总指定日期的AI行业新闻时,应使用此技能。

    287 GitHub stars~1.8k tokensUpdated 2 mo ago
    Auto-check passed
  • Xhs Note Creator

    zrt-ai-lab/opencode-skills

    小红书笔记素材创作技能。当用户需要创建小红书笔记素材时使用这个技能。技能包含:根据用户的需求和提供的资料,撰写小红书笔记内容(标题+正文),生成图片卡片(封面+正文卡片),以及发布小红书笔记。

    287 GitHub stars~956 tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Skill Scanner

What does Skill Scanner do?

A skill your agent uses when reviewing an agent Skill before sharing, installing, or executing it and when checking a Skill bundle for credentials, dangerous commands, suspicious network behavior…. Skill Scanner is an agent skill from zrt-ai-lab/opencode-skills. Use when reviewing an agent Skill before sharing, installing, or executing it and when checking a Skill bundle for credentials, dangerous commands, suspicious network behavior, or obfuscated code.

When should I use Skill Scanner?

Skill Scanner fits situations like: reviewing an agent Skill before sharing; executing it and when checking a Skill bundle for credentials; dangerous commands; suspicious network behavior.

How do I install Skill Scanner in Claude Code?

Run `npx skills add zrt-ai-lab/opencode-skills --skill skill-scanner -a claude-code`. Or copy the skill folder (skill-scanner in zrt-ai-lab/opencode-skills) into .claude/skills/skill-scanner in your project. Claude Code loads it when a task matches its description.

How do I install Skill Scanner in Codex?

Run `npx skills add zrt-ai-lab/opencode-skills --skill skill-scanner -a codex`. Or copy the skill folder (skill-scanner in zrt-ai-lab/opencode-skills) into .agents/skills/skill-scanner in your project. Codex loads it when a task matches its description.

Can I use Skill Scanner in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add zrt-ai-lab/opencode-skills --skill skill-scanner -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/skill-scanner, .gemini/skills/skill-scanner, .github/skills/skill-scanner and .opencode/skills/skill-scanner in your project.

What does Skill Scanner need to run?

Going by SKILL.md and its folder, Skill Scanner needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Skill Scanner access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Skill Scanner safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Skill Scanner use?

No licence was found for Skill Scanner or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Skill Scanner use?

About 317 tokens (SKILL.md is roughly 1.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Skill Scanner?

Skills that share tags, products or a category with Skill Scanner: Skill Scanner (getsentry/skills, 1k stars), Forensify (alexgreensh/repo-forensics, 188 stars), Hol Guard (hashgraph-online/hol-guard, 827 stars) and Kesekit Check (cdppcorp/KESE-KIT, 361 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Skill Scanner?

zrt-ai-lab (a GitHub user) maintains it in zrt-ai-lab/opencode-skills, which has 287 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on July 22, 2026.

Source: zrt-ai-lab/opencode-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.