Flagged: sudo usage. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by huifer · Claude Skill · ★ 164
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is skill-security-scan safe to install? View the security audit →
Skill-Security-Scanner 🔍 Claude Skills 安全扫描工具 - 保护你的开发环境 English Documentation | 中文文档 📖 简介 skill-security-scan 是一个命令行工具,用于扫描和检测 Claude Skills 的安全风险。在安装第三方 Skills 前,使用此工具进行安全审查,有效防止恶意代码窃取数据或破坏系统。 本项目由 WellAlly Technology 开发者发起并维护,致力于为开发者社区提供安全可靠的工具。 ⚠️ 为什么需要 skill-security-scan? 在本地 Claude Code 中使用 Skills 存在以下安全风险: 完整文件系统访问 - Skills 可以读取任意文件,包括 SSH 密钥、API 密钥等 网络访问能力 - Skills 可以向外部服务器发送数据 脚本执行权限 - Skills 可以执行任意系统命令 依赖破坏 - Skills 可能修改全局依赖,破坏其他项目 ✨ 特性 🔍 全面安全检测 - 网络、文件、命令、代码注入等多维度检测 🎯 智能风险评分 - 自动计算风险分数和等级 🎨 多种输出格式 - HTML 报告(默认)、彩色终端、JSON 报告 🌍 国际化支持 - 支持中文和英文界面 📁 智能路径扫描 - 自动扫描 目录和当前目录 ⚙️ 灵活配置 - 自定义规则、白名单管理 🚀 高性能 - 快速扫描大型项目 🚀 快速开始 安装 基本使用 bash 扫描当前目录和 .claude/skills/(默认行为) skill-security-scan scan 扫描指定路径(仍会自动包含 .claude/skills/) skill-security-scan scan /path/to/skill 扫描并生成指定名称的 HTML 报告 skill-security-scan scan --output myreport.html
| Stars | 164 |
| Forks | 12 |
| Language | Python |
| Category | Claude Skill |
| License | MIT |
| Quality Score | 69.1003528534119/100 |
| Last Updated | 2025-12-29 |
| Created | 2025-12-29 |
| Platforms | claude-code, python |
| Est. Tokens | ~7k |
Looking for a skill-security-scan alternative? If you're comparing skill-security-scan with other claude skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Vendor-neutral MCP configuration manager — one CLI to add, toggle, and audit MCP servers and skills across eve
Feishu / Lark 飞书文档与任务管理工具,支持 MCP 服务器和 CLI + Skill 两种使用方式,可无缝集成 Cursor、Claude Code、Cline 等 AI 编码工具
Claude Code LSP: enhance your Claude Code experience with non-IDE dependent LSP integration.
A Model Context Protocol (MCP) that allows Claude Desktop and other AI tools (Claude Code, Cursor, Antigravity
The memory + security kernel for AI agents. Strata: a signed append-only log, receipts on every write, exact-h
Overture is an open-source, locally running web interface delivered as an MCP (Model Context Protocol) server
Explore other popular claude skill tools:
skill-security-scan is skill-security-scan is a command-line tool designed to scan and detect security risks in Claude Skills. Before installing third-party Skills, use this tool for security review to effectively prevent m. It is categorized as a Claude Skill with 164 GitHub stars.
skill-security-scan is primarily written in Python. It covers topics such as claude-code, skills.
You can find installation instructions and usage details in the skill-security-scan GitHub repository at github.com/huifer/skill-security-scan. The project has 164 stars and 12 forks, indicating an active community.
skill-security-scan is released under the MIT license, making it free to use and modify according to the license terms.
The top alternatives to skill-security-scan on Agent Skills Hub include mcpick, Feishu-MCP, cclsp. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: