Scan AI agent skills before they touch your machine.
Drop it in front of the skill installer you already use. GuardSkills scans the skill first, scores the risk, and runs the install only when your policy says yes.
$ npx skills add vercel-labs/skills --skill find-skills$ npx guardskills@latest skills add vercel-labs/skills --skill find-skillsv1.5.0 · universal prepend · scanner ruleset 2026.2
See the same install workflow, now scanned before execution.
Skills are just code. Anyone can publish one.
A skill can ship prompts that read your environment, spawn processes, or wipe files. When an agent installs and runs it, it runs with your permissions. A typo in a repo name is all it takes to hand a stranger your tokens.
- Reads of
.env, tokens, SSH keys, and browser storage - Shell escapes,
eval, and remote fetch-and-run - Recursive deletes and writes outside the project
Just add guardskills to the command you already run.
Put guardskills immediately after npx in the provider command you already know. GuardSkills uses a pinned GitHub checkout or a provider-specific immutable artifact when available.
Drop-in shortcuts
skills.sh
npx guardskills skills add vercel-labs/skills --skill find-skillsOpenSkills
npx guardskills openskills install anthropics/skills frontend-designSkillKit
npx guardskills skillkit install rohitg00/skillkit dev-toolsPlaybooks
npx guardskills playbooks add skill anthropics/skills --skill frontend-designOpenClaw
npx guardskills openclaw skills install git:owner/repolocalskills
npx guardskills localskills install my-skill@1.2.3npx guardskills@latest when you want npm to resolve the newest published CLI explicitly.Provider coverage
Three layers cover dedicated integrations, immutable registry adapters, and other npm-based installers.
npx guardskills providersBuilt-in
skills.sh, Playbooks, OpenSkills, SkillKit
Dedicated commands with pinned GitHub checkout
Adapters
OpenClaw, SkillKit skills.sh, localskills
Exact commits, versions, or verified artifacts
Universal prepend
Any other npm-based provider
Infers one GitHub source and skill; ambiguity fails closed
Using a different npm installer?
Universal prepend mode scans a safely identified GitHub source before the provider runs. Use the wrapper when the installer needs the verified checkout path itself.
Universal prepend
npx guardskills my-provider install owner/repo --skill my-skill$ guardskills wrap --source vercel-labs/skills --skill find-skills --require-pinned-handoff -- npx skills add {checkout} --skill find-skillsScan and inspect
Preview the verdict without installing
guardskills add owner/repo --skill my-skill --dry-runEnforce policy in CI (machine-readable)
guardskills add owner/repo --skill my-skill --ci --jsonScan a local checkout
guardskills scan-local ./my-skillScan a ClawHub skill
guardskills scan-clawhub owner/skill-slugWhat GuardSkills looks for.
Ruleset 2026.2 runs deterministic checks across fenced code, command-like snippets, and supported script files. Markdown prose is never treated as executable. A weighted risk score reflects how exploitable each finding is.
Credential exfiltration
Reads of tokens, API keys, .env, SSH keys, and browser or agent secret stores, plus any outbound send of them.
Remote code execution
eval, child_process, exec and spawn, dynamic import of remote code, and shell escapes inside prompts or scripts.
Destructive file ops
Recursive deletes, rm -rf patterns, and writes that escape the project directory or overwrite system files.
Privilege escalation
Attempts to raise permissions, mutate system config, install persistence, or disable security tooling.
Obfuscated payloads
Encoded PowerShell, process-substitution execution, split-token commands, and bundles shaped to hide what they do.
Unsafe network calls
Exfiltration endpoints, hidden telemetry, webhooks, and outbound calls to untrusted or private hosts.
The installer receives the source GuardSkills actually scanned.
GitHub flows use a clean checkout at the precise 40-character commit. Registry adapters resolve exact versions and verify content-addressed artifacts before handoff.
- {checkout} is replaced with the verified local directory the installer should use.
- HEAD must equal the scanned 40-character SHA, with no tracked or untracked changes.
- Checkouts persist under the GuardSkills cache so symlinked skills keep working.
Verified checkout cache
~/.guardskills/cache/checkouts/<owner>/<repo>/<commit-sha>Verified artifact cache
~/.guardskills/cache/artifacts/<provider>/<sha256>Auditable scan receipts
Write a versioned JSON record with the source, commit, ruleset, preset, decision, and a SHA-256 hash for every scanned file. Its checksum detects changes but is not a digital signature.
guardskills add owner/repo --skill my-skill --receipt .guardskills/s.receipt.json --dry-runguardskills verify-receipt .guardskills/s.receipt.jsonSafe execution contract
- Installer must be a bare command resolved from PATH, never a direct file path.
- Default allowlist: npx, npm, pnpm, yarn, bunx, bun.
- Executable and args are passed directly with shell disabled, no string interpolation.
- Token, password, secret, and API-key values are redacted in the displayed command.
- CRITICAL outcomes can never be overridden.
Cache lifecycle
List verified checkouts and artifacts, then preview age-based cleanup before explicitly confirming it.
guardskills cache listguardskills cache prune --older-than-days 30 --dry-runEvery skill gets a verdict. Your policy decides what happens next.
Pick a preset on the CLI or in guardskills.config.json. Use policy.minimumPreset so users and CI cannot downgrade an organization-required posture.
0 allow10 needs confirm20 blocked30 runtime errorPulls from where your skills already live.
Built-in GitHub providers use verified commit checkouts. OpenClaw, SkillKit skills.sh, and localskills add dedicated exact-version or immutable-artifact resolver paths.
Sources
Skill formats
Stop pasting npm links. Share one page.
Send teammates here for the install command, the verdict model, and the source.
$ npx skills add vercel-labs/skills --skill find-skills$ npx guardskills@latest skills add vercel-labs/skills --skill find-skills