Relative paths may escape the intended KB root without normalization.
SKILL.md, MCP JSON, OpenAPI, or bundled folder/zip.
Supply-chain security for Agent Skills and MCP tools
Reads local knowledge-base files under user-controlled paths
Accepts arbitrary query strings from the agent runtime
No shell execution or credential exfiltration patterns detected
This sample skill implements a knowledge-base retriever with filesystem read scope. Static analysis found no critical exfiltration patterns. Dependency scan returned no known CVEs for pinned packages. Dynamic probing was run in monitor mode. Review path traversal guards before production use.
Relative paths may escape the intended KB root without normalization.
Dynamic probe did not detect outbound connections in monitor mode.
requests@2.31.0 No known CVEs Video walkthrough
Product demo — not a live environment.
SKILL.md, MCP JSON, OpenAPI, or bundled folder/zip.
Normalize structure, dependencies, and scan surface.
Trifecta, CVE scan, static rules, optional dynamic probe, intent check.
Score, findings, remediation priorities — ready for audit.
skillguard_parse_skillskillguard_trifecta_scoreskillguard_generate_reportReady to see ClawDesk in action?