Security scanner for third-party AI agent-skill files (SKILL.md manifests, hooks, bundled scripts). CLI, library, MCP server, and GitHub Action, all reading the same 10 rule packs, including cross-skill privilege chaining and prompt-injection detection. Zero-auth, zero-config npx or pip scan.
<!-- mcp-name: io.github.RudrenduPaul/skillguard --> <!-- Ownership-proof string for registry.modelcontextprotocol.io publishing. Do not remove. --> <div align="center"> Scans third-party AI agent-skill files (`SKILL.md` manifests, hooks, and bundled scripts) for known attack patterns before they run, and is the only scanner in its category you can also call as an MCP tool from inside another agent.