安全

skill-injection-scanner

试用

Scan agent skill files for hidden instructions and prompt-injection patterns (EN/RU) before a poisoned skill rewrites your agent. 19 rules, zero dependencies. Use ONLY with the user's explicit consent: tell the user which skills folder will be scanned — findings are printed to stdout locally.

它能做什么

Scan agent skill files for hidden instructions and prompt-injection patterns (EN/RU) before a poisoned skill rewrites your agent. 19 rules, zero dependencies. Use ONLY with the user's explicit consent: tell the user which skills folder will be scanned — findings are printed to stdout locally.

技能文档

Skill Injection Scanner

Local-first. No telemetry, no cloud sync — the files you scan never leave your machine.

When to use

  • You just installed a skill from a marketplace (ClawHub, n8n, OpenClaw, npm…) and want to check it before first use.
  • You maintain a skills library and want a periodic security sweep.
  • You write agent skills and want to make sure none of your docs accidentally look like hidden commands. Don't use for: general code SAST, binary malware analysis, full-repo vulnerability scanning.

Quick start

# from this package (or the git repo: github.com/vnbochkarev-netizen/skill-injection-scanner)
python3 scanner.py --skills ~/.openclaw/skills
python3 scanner.py --skills ~/.claude/skills --format json
python3 scanner.py --skills /path/to/skills --exclude .bak --include-code-spans

What it detects (19 rules)

  • Role/personality hijack («you are now…», «ты теперь…») and system-message impersonation
  • «Ignore previous instructions» / «follow only this text» (EN+RU)
  • Secrecy orders («never tell the owner…», «не говори владельцу»)
  • Obfuscated instructions (base64/rot13/encoded), embedded <|system|> / ```system markers
  • Remote fetch-and-run (curl | bash, git clone … && run), instruction extraction from attachments/images
  • Manipulation tricks («this is critical: ignore…», emoji-boosted commands)

Context-aware scoring: security docs that describe injections, «show, don't tell» writing advice, code-span examples and trusted hosts (github.com, docs.python.org, …) are not flagged; unknown hosts stay HIGH with a «verify the source» note. --self-test exits 1 if fixtures/ are missing — it can never report a fake green. Note: the packaged copy has no fixtures/ (marketplace policy); run --self-test from the git repo, which ships them.

WhatWhereHow to delete
Read file contents of the folder you point atin memory onlynothing is written; findings go to stdout
Findings (file:line, rule, snippet)stdout / --format jsonclose the terminal / redirect to a file and delete it

Get explicit consent before scanning a folder: tell the user what will be read. The tool writes nothing, phones nothing and keeps no logs.

Permissions

  • Files: read-only access to the skills directory the user explicitly points at.
  • Process: none — no subprocesses, no installs, no shell execution.
  • Network: NONE.
  • Secrets: never reads secret/config files by design; a credential-looking pattern inside a scanned file is reported as a finding with a short snippet for local review.

License

MIT © 2026 Viacheslav Bochkarev. Free to use, modify and redistribute.

相关技能

Security scanner for AI agent skills. Detects hardcoded secrets, unsafe code execution, prompt injection, and malware patterns in under 50ms. Scan before you...

Automated security audit for AI agent skills. Use BEFORE installing any skill from ClawHub, GitHub, or other sources. Scans SKILL.md + all files for 30+ red...

作者 Zoran2 次安装

Scan skills in a project directory for security issues and generate a markdown table report, then install skills from a local registry. Combines static analysis of code and markdown files with supply chain checks. Use when auditing a skills directory, generating a security summary table, or installi

按 OWASP Agentic Skills Top 10 审计已安装的 AI Agent 技能,输出文本、JSON、SARIF 或 HTML 报告。

29 次安装1 星标

Check agent config for things that break silently on someone else's machine. Use before publishing or committing a SKILL.md, AGENTS.md, CLAUDE.md or llms.txt, before publishing a skill to ClawHub, when a skill "works on my machine" but not for a teammate, when a skill fails to trigger, or when asked to review agent config. Catches references to files that do not exist, absolute paths under the author's home directory, undeclared CLI dependencies, a frontmatter name that does not match the skill's directory, and two skills whose descriptions are so similar the agent fires the wrong one.