Local-first capability discovery for AI agent workspaces. Scans your skills, MCP servers, and scripts to find risky combinations (e.g. read .env + post to webhook = data exfiltration) — no LLM calls, no uploads. CLI + HTML report + chat summary for personal agents like Hermes and OpenClaw.