🛡️ SkillAudit — AI Agent Security Scanner

Is that AI skill safe to install?

Scan any MCP skill or agent tool for security threats in 5 seconds. Free. No signup.

0 skills scanned

Paste a skill URLFREE

We'll scan for credential theft, data exfiltration, prompt injection & more

How the Skill Scanner Works

Paste a Skill URL

Any SKILL.md, MCP tool config, or agent definition

Instant Security Analysis

Pattern matching, intent detection, capability fingerprinting

Get a Safety Report

Risk score, findings, shareable link — in seconds

What We Detect — Agent Safety Threats

🔑Credential Theft Detection
API keys, tokens, .env access attempts
📡Data Exfiltration
Suspicious outbound data transfers
💉Prompt Injection
Behavior override & jailbreak attempts
🐚Reverse Shells
Code execution & backdoor detection
⛓️MCP Threat Chains
Dangerous capability combinations
🧠Agent Manipulation
Memory/soul file tampering attacks

Simple Pricing

Free basic scans. Pay per premium scan with USDC via x402 — no account needed.

Deep Scan

$0.05
per scan · USDC

+ Capability fingerprinting, threat chains, permission manifest

Batch Scan

$0.10
up to 20 URLs · USDC

Scan your whole skill library at once. Risk breakdown included.

Quick Start

# Free scan by URL
curl -X POST https://skillaudit.vercel.app/scan/url \
  -H "Content-Type: application/json" \
  -d '{"url": "https://example.com/SKILL.md"}'

# Free scan by content
curl -X POST https://skillaudit.vercel.app/scan/content \
  -H "Content-Type: application/json" \
  -d '{"content": "... skill text ..."}'

API Reference

EndpointCostDescription
POST /scan/urlFreeScan a skill by URL
POST /scan/contentFreeScan raw skill content
POST /scan/deep$0.05Full capability analysis + threat chains
POST /scan/batch$0.10Batch scan up to 20 URLs
POST /scan/compare$0.05Compare two skill versions
GET /scan/:idFreeGet scan result (JSON)
GET /report/:idFreeView scan report (HTML)
GET /statsFreeEcosystem scan statistics
GET /openapi.jsonFreeOpenAPI 3.0 spec