Scan any AI skill for threats — before you install it
Paste a GitHub URL. You get a severity verdict plus the matched ATR rules in seconds.
ONLINE SKILL SCANNER
Scan any skill. No install needed.
Paste a GitHub URL to instantly check if an AI skill or MCP server is safe. Results are cached -- same content is never re-scanned.
Scans run server-side. No code is stored. Only content hash is cached for deduplication.
WHAT WE CHECK
Prompt Injection
Hidden instructions that hijack the agent's behaviour.
Tool Poisoning
Malicious MCP tool output that triggers code execution.
Secret Exfiltration
Attempts to leak API keys, tokens, or credentials.
Obfuscation
Encoded or disguised payloads that dodge inspection.
NEXT STEP
Run this on every agent, automatically
The online scanner is a one-shot audit. Install Panguard to guard your agents in real time — the same ATR rules, always on.