Scan before you install

Scan AI agent skills before they touch your machine.

Drop it in front of the skill installer you already use. GuardSkills scans the skill first, scores the risk, and runs the install only when your policy says yes.

just add guardskills to the command you already run
before
$ npx skills add vercel-labs/skills --skill find-skills
with GuardSkills
$ npx guardskills@latest skills add vercel-labs/skills --skill find-skills

v1.5.0 · universal prepend · scanner ruleset 2026.2

See the same install workflow, now scanned before execution.

The risk

Skills are just code. Anyone can publish one.

A skill can ship prompts that read your environment, spawn processes, or wipe files. When an agent installs and runs it, it runs with your permissions. A typo in a repo name is all it takes to hand a stranger your tokens.

  • Reads of .env, tokens, SSH keys, and browser storage
  • Shell escapes, eval, and remote fetch-and-run
  • Recursive deletes and writes outside the project
what a malicious skill can hide
$ install free-tool
! reads ~/.ssh/id_rsa and ~/.env
! child_process.exec("bash ./setup.sh")
! rm -rf ~/projects
! POST keys -> sk-live-***.example
agent runs all of this with your permissions
verdict: CRITICAL blocked
Quickstart

Just add guardskills to the command you already run.

Put guardskills immediately after npx in the provider command you already know. GuardSkills uses a pinned GitHub checkout or a provider-specific immutable artifact when available.

Drop-in shortcuts

skills.sh

npx guardskills skills add vercel-labs/skills --skill find-skills

OpenSkills

npx guardskills openskills install anthropics/skills frontend-design

SkillKit

npx guardskills skillkit install rohitg00/skillkit dev-tools

Playbooks

npx guardskills playbooks add skill anthropics/skills --skill frontend-design

OpenClaw

npx guardskills openclaw skills install git:owner/repo

localskills

npx guardskills localskills install my-skill@1.2.3
Use npx guardskills@latest when you want npm to resolve the newest published CLI explicitly.

Provider coverage

Three layers cover dedicated integrations, immutable registry adapters, and other npm-based installers.

npx guardskills providers

Built-in

skills.sh, Playbooks, OpenSkills, SkillKit

Dedicated commands with pinned GitHub checkout

Adapters

OpenClaw, SkillKit skills.sh, localskills

Exact commits, versions, or verified artifacts

Universal prepend

Any other npm-based provider

Infers one GitHub source and skill; ambiguity fails closed

Using a different npm installer?

Universal prepend mode scans a safely identified GitHub source before the provider runs. Use the wrapper when the installer needs the verified checkout path itself.

Universal prepend

npx guardskills my-provider install owner/repo --skill my-skill
Verified-commit handoff
works with any installer
$ guardskills wrap --source vercel-labs/skills --skill find-skills --require-pinned-handoff -- npx skills add {checkout} --skill find-skills

Scan and inspect

Preview the verdict without installing

guardskills add owner/repo --skill my-skill --dry-run

Enforce policy in CI (machine-readable)

guardskills add owner/repo --skill my-skill --ci --json

Scan a local checkout

guardskills scan-local ./my-skill

Scan a ClawHub skill

guardskills scan-clawhub owner/skill-slug
Detection

What GuardSkills looks for.

Ruleset 2026.2 runs deterministic checks across fenced code, command-like snippets, and supported script files. Markdown prose is never treated as executable. A weighted risk score reflects how exploitable each finding is.

Credential exfiltration

Reads of tokens, API keys, .env, SSH keys, and browser or agent secret stores, plus any outbound send of them.

Remote code execution

eval, child_process, exec and spawn, dynamic import of remote code, and shell escapes inside prompts or scripts.

Destructive file ops

Recursive deletes, rm -rf patterns, and writes that escape the project directory or overwrite system files.

Privilege escalation

Attempts to raise permissions, mutate system config, install persistence, or disable security tooling.

Obfuscated payloads

Encoded PowerShell, process-substitution execution, split-token commands, and bundles shaped to hide what they do.

Unsafe network calls

Exfiltration endpoints, hidden telemetry, webhooks, and outbound calls to untrusted or private hosts.

Provenance

The installer receives the source GuardSkills actually scanned.

GitHub flows use a clean checkout at the precise 40-character commit. Registry adapters resolve exact versions and verify content-addressed artifacts before handoff.

  • {checkout} is replaced with the verified local directory the installer should use.
  • HEAD must equal the scanned 40-character SHA, with no tracked or untracked changes.
  • Checkouts persist under the GuardSkills cache so symlinked skills keep working.

Verified checkout cache

~/.guardskills/cache/checkouts/<owner>/<repo>/<commit-sha>

Verified artifact cache

~/.guardskills/cache/artifacts/<provider>/<sha256>
pinned handoff
$ guardskills wrap --source acme/skill --skill s --require-pinned-handoff -- npx skills add {checkout} --skill s
resolved acme/skill @ a1b2c3d...e4f5
+ HEAD matches scanned commit, working tree clean
{checkout} -> cache checkouts/acme/skill/a1b2c3d
receipt written: .guardskills/s.receipt.json
verdict: SAFE risk 4/100
-> handed verified checkout to skills add

Auditable scan receipts

Write a versioned JSON record with the source, commit, ruleset, preset, decision, and a SHA-256 hash for every scanned file. Its checksum detects changes but is not a digital signature.

guardskills add owner/repo --skill my-skill --receipt .guardskills/s.receipt.json --dry-runguardskills verify-receipt .guardskills/s.receipt.json

Safe execution contract

  • Installer must be a bare command resolved from PATH, never a direct file path.
  • Default allowlist: npx, npm, pnpm, yarn, bunx, bun.
  • Executable and args are passed directly with shell disabled, no string interpolation.
  • Token, password, secret, and API-key values are redacted in the displayed command.
  • CRITICAL outcomes can never be overridden.

Cache lifecycle

List verified checkouts and artifacts, then preview age-based cleanup before explicitly confirming it.

guardskills cache list
guardskills cache prune --older-than-days 30 --dry-run
Policy

Every skill gets a verdict. Your policy decides what happens next.

Pick a preset on the CLI or in guardskills.config.json. Use policy.minimumPreset so users and CI cannot downgrade an organization-required posture.

Preset
Thresholds
Gate behavior
balanced
Standard
Warnings and overrides work normally
strict
Lower
Warnings and overrides work normally
paranoid
Strict
Only SAFE may proceed
acme/cool-skill
$ guardskills add acme/cool-skill
scanning 48 files ...
+ credential exfiltration: none
+ remote code execution: none
+ destructive writes: none
risk: 4/100 SAFE
-> installing cool-skill
anon/free-tool
$ guardskills add anon/free-tool
scanning 31 files ...
x credential exfiltration: ~/.ssh/id_rsa
x remote code execution: eval(payload)
x unsafe network: POST -> sk-live-***
risk: 92/100 CRITICAL
x blocked by policy - not installed
Verdict
Risk
Default action
SAFE
low
install
WARNING
medium
ask before install
UNSAFE
high
block
CRITICAL
severe
block
UNVERIFIABLE
unknown
block, needs review
Exit codes0 allow10 needs confirm20 blocked30 runtime error
Sources and formats

Pulls from where your skills already live.

Built-in GitHub providers use verified commit checkouts. OpenClaw, SkillKit skills.sh, and localskills add dedicated exact-version or immutable-artifact resolver paths.

Sources

GitHubClawHubOpenClawlocal pathskills.shlocalskills

Skill formats

Codex skillsClaude CodeplaybooksOpenSkillsSkillKitOpenClaw

Stop pasting npm links. Share one page.

Send teammates here for the install command, the verdict model, and the source.

$ npx skills add vercel-labs/skills --skill find-skills
$ npx guardskills@latest skills add vercel-labs/skills --skill find-skills