Vetix — Automated scanning, identification, and assessment of SKILL security risks, based on Golang.
-
Updated
Sep 19, 2026 - Go
Vetix — Automated scanning, identification, and assessment of SKILL security risks, based on Golang.
Enhanced malicious Skill detection tool. Analyzes whether a target skill poses security threats to users who install it.
AVE - Agentic Vulnerability Enumeration. The open behavioral classification standard for agentic AI components.
Three portable Agent Skills for research, repository deployment, and pre-install safety review.
Open-source CLI scanner for agentic AI components such as skills, MCP servers, system prompts
One-command pre-install scorecard for AI agent skills: security, permissions, token cost, footprint, and maintainability.
Audit AI skill safety before you ship. Static + semantic + adversarial audit pipeline for SKILL.md, Codex skill.yaml, Claude Code commands, and OpenCode. Free hosted tier on tarai.dev.
Find, vet, and install the right AI agent skill from a natural-language need.
AI security toolkit for prompt injection detection, sensitive data protection, runtime monitoring, and threat intelligence for LLM and agent workflows.
Quality, security, compatibility and publishing toolkit for AI Agent Skills - lint and validate SKILL.md, scan for secrets and prompt injection, check portability across Claude Code, Codex, Cursor and Gemini CLI
Static security scanner for agent skills: A-F risk rating, safe zip scanning, CI-tested rules
detect structural trust boundary vulnerabilities that enable cascading supply chain compromise
Decide once. Re-decide never. A Claude Code skill that evaluates skills before installing and persists every decision.
Static security scanner for AI skills, agents, prompts, and MCP instruction files
A curated list of amazingly awesome Cybersecurity datasets
Installable guard skill for agent skills.
See what your AI-agent skills can actually do. Vouch audits every SKILL.md on your machine, explains each skill's capabilities in plain English, and flags the risky ones (destructive commands, secret exfiltration, prompt injection). Local, deterministic — like npm audit, but for agent skills.
Security auditor for AI agent skills — catches hidden-Unicode prompt injection, reviewer-subversion, data exfiltration & post-install drift that markdown-only vetters miss.
DeepSeek Harness plugin for safely discovering, auditing, and adopting external Agent Skills — prompt-injection and AgentBaiting defense.
To associate your repository with the skill-security topic, visit your repo's landing page and select "manage topics."