Pre-commit hook that blocks malicious AI agent skills before they're committed

Pre-commit hook that blocks malicious AI agent skills before they're committed

Snyk's ToxicSkills scan flagged 76 credential-stealing payloads across ~4,000 public agent skills. No marketplace currently code-signs or vets these before install.

Made a free scanner — no signup, no key:

curl -s --data-binary u/SKILL.md https://skillsguard.apiskillsguard.workers.dev/scan | jq .

151 rules (prompt injection, exfil, persistence, obfuscation incl. base64/Unicode-tag tricks). CLI + MCP server if you want Claude to auto-audit skills before trusting them: github.com/Teycir/SkillsGuard

submitted by /u/tcoder7
[link] [comments]


from hacking: security in practice https://ift.tt/J5gV1P0

Comments