Elevate Skill security from 'malware detection' to 'capability auditing'
Not just whether it's malicious, but which approval-worthy capabilities it grants an Agent once enabled. Powered by the CleanSource skills v2 audit engine.
A fully transparent Skill that does exactly what it says can still send material outbound, use an enterprise key to reach third parties, or write to systems. It isn't malicious — yet it can cross the enterprise admission boundary
From 'is it malicious' to 'what will it gain, reach, and change once enabled'.
Not binary safe / malicious, but block / need_review / pass — separating legitimate-but-high-impact from confirmed-malicious.
Covers input visibility, instruction & runtime execution, Agent permission & identity, data & memory, asset cost & real-world actions, abuse evasion, and supply-chain ecosystem.
Doesn't block on keywords — grades by evidence strength, from mention-level, to commands and config, to executable chains, to runtime persistence.
Extracts dependency candidates from build files and even natural-language install intent, matched at version level against poisoning intelligence.
Every verdict carries evidence pinpointed to the SKILL.md line plus a disposition — auditable and reviewable, never keyword-hit-equals-verdict.
Three-tier verdicts embed into CI/CD and Skill-marketplace admission; export JSON to SCA/SBOM, IAM/DLP, SIEM/SOAR, and ticketing.
Parses a Skill's manifest and implementation to reconstruct its true capability boundary — files, network, shell exec, secret access — and flags high-risk capabilities.
Extracts real permissions from SKILL.md and code.
Detects hidden capabilities beyond what's declared.
Shell exec, secret reads and the like get priority alerts.
Compares dependency provenance and naming to catch typosquats, hijacked versions, and malicious injection — blocking and alerting on a hit.
Catches look-alike package names.
Verifies publisher and version integrity.
Alerts and blocks the moment it matches.
A Skills-for-Skills approach makes the audit flow itself dynamically loadable and extensible.
Baseline static scanning rules out obviously malicious samples — the part legacy SAST/SCA already covers.
Aligns the SKILL.md natural-language description with actual code behavior to catch says-one-thing-does-another.
Structured tags and evidence grading assess a single Skill, and detect attack chains emerging from multi-Skill collaboration.
AI-Agent Skill ecosystems carry prompt-injection, data-exfiltration and supply-chain-poisoning risks. SkillSec performs admission-grade security audits, answering which approval-worthy capabilities a Skill grants an Agent once enabled.
Malware detection only answers whether something is malicious. SkillSec elevates this to capability auditing — even a fully benign Skill can exfiltrate secrets or reach third parties with corporate credentials. Audits span 7 risk domains, 30+ structured tags and E1–E5 evidence grading.
Three-level verdicts — block / need_review / pass — with evidence chains precise to SKILL.md line numbers, serving directly as admission gates for enterprise Agent Skill listing and enablement.
Manifest auditing and behavior analysis for mainstream Agent extension ecosystems including Claude Skills and MCP.
No. Analysis is primarily static — reading both natural-language declarations such as SKILL.md and the script implementation, and checking their consistency — so verdicts are produced without executing anything in production.
As the admission gate before Skill listing or enablement: plug into your internal Skill marketplace or Agent platform approval flow, with block / need_review / pass verdicts driving the approval action directly.
Yes. Whether from a public marketplace or internal development, any Skill package can be audited — surfacing capability overreach and declaration-implementation mismatches before release.
Book a demo and see how SkillSec builds an admission-grade security intelligence line for your AI Agents.