Seven dimensions
Prompt injection, sensitive access, compliance, scripts, dependencies, trigger scope, and frontmatter.
Read-only Hugging Face mirror
A deterministic, standard-library Python scanner for Skill files, directories, zip packages, inline text, and bounded public URLs, with seven risk dimensions and an A-F attestation.
680831411d73The scanner makes package risk inspectable without installing dependencies or executing the Skill.
Prompt injection, sensitive access, compliance, scripts, dependencies, trigger scope, and frontmatter.
Directory and zip scans apply path traversal, size, and file-count limits.
Reports bind scanner version, input SHA-256, ignores, completeness, findings, and grade.
The sequence is explanatory. Install and execute the actual project locally from its canonical repository.
Point the CLI at SKILL.md, a directory, zip, stdin, inline text, or a bounded URL.
Read text without executing package scripts or installing dependencies.
Apply conservative rules across all seven dimensions.
Inspect finding IDs, confidence, severity, remediation, and the exact input hash.
This page preserves the project's published limits instead of turning engineering checks into outcome claims.
This mirror does not accept or upload visitor Skill packages.
An A grade means no configured rule matched; it cannot prove a package is harmless.
The local Python scanner and tests remain the normative implementation.
Local files below are curated public mirrors. GitHub remains authoritative for development, releases, and issue history.