Top AI Repos — open-source AI, indexed and scored
Top AI Repos tracks AI repositories on GitHub and answers two different questions about each one: is it moving right now, and would you bet a product on it.
Top AI Repos tracks AI repositories on GitHub and answers two different questions about each one: is it moving right now, and would you bet a product on it.
Security Scanner for Agent Skills
| Date | Stars |
|---|---|
| 2026-07-31 | 2384 |
| 2026-08-06 | 2405 |
Today
+21 stars today
This week
— stars this week
This month
— stars this month
Momentum
144.0
growth rate 0.00%/day
# Skill Scanner [](https://opensource.org/licenses/Apache-2.0) [](https://www.python.org/downloads/) [](https://pypi.org/project/cisco-ai-skill-scanner/) [](https://github.com/cisco-ai-defense/skill-scanner/actions/workflows/python-tests.yml) [](https://discord.com/invite/nKWtDcXxtx) [](https://www.cisco.com/site/us/en/products/security/ai-defense/index.html) [](https://learn-cloudsecurity.cisco.com/ai-security-framework) [](https://deepwiki.com/cisco-ai-defense/skill-scanner) A best-effort security scanner for AI Agent Skills that detects prompt injection, data exfiltration, and malicious code patterns. Combines **pattern-based detection** (YAML + YARA), **LLM-as-a-judge**, and **behavioral dataflow analysis** to maximize detection coverage of probable threats while minimizing false positives. > **Important:** This scanner provides best-effort detection, not comprehensive or complete coverage. A scan that returns no findings does not guarantee that a skill is free of all threats. See [Scope and Limitations](#scope-and-limitations) below. Supports [OpenAI Codex Skills](https://openai.github.io/codex/) and [Cursor Agent Skills](https://docs.cursor.com/context/rules) formats following the [Agent Skills specification](https://agentskills.io). With `--lenient`, also scans non-standard formats such as Claude Code `.claude/commands/*.md` and flat markdown skill repos. --- ## Highlights - **Multi-Engine Detection** - Static analysis, behavioral dataflow, LLM semantic analysis, and cloud-based scanning for layered, best-effort coverage - **False Positive Filtering** - Meta-analyzer significantly reduces noise while preserving detection capability - **CI/CD Ready** - SARIF output for GitHub Code Scanning, [reusable GitHub Actions workflow](docs/github-actions.md), exit codes for build failures - **Pre-commit Hook** - [Standard pre-commit framework](https://pre-commit.com/) integration to scan skills before every commit - **Extensible** - Plugin architecture for custom analyzers **[Join the Cisco AI Discord](https://discord.com/invite/nKWtDcXxtx)** to discuss, share feedback, or connect with the team. --- ## Scope and Limitations Skill Scanner is a detection tool. It identifies known and probable risk patterns, but it does not certify security. **Key limitations:** - **No findings ≠ no risk.** A scan that returns "No findings" indicates that no known threat patterns were detected. It does not guarantee that a skill is secure, benign, or free of vulnerabilities. - **Coverage is inherently incomplete.** The scanner combines signature-based detection, LLM-based semantic analysis, behavioral dataflow analysis, optional cloud services, and configurable rule packs. While this approach improve coverage, no automated tool can detect every technique, especially novel or zero-day attacks. - **False positives and false negatives can occur.** Consensus modes and meta-analysis reduce noise, but no configuration eliminates all incorrect classifications. Tune the [scan policy](docs/user-guide/custom-policy-configuration.md) to your risk tolerance. - **Human review remains essential.** Automated scanning is one component of a defense-in-depth strategy. High-risk or production deployments should pair scanner results with manual code review and/or threat modeling. --- ## Documentation | Guide | Description | |-
Excerpt of 16,845 characters
Read on GitHub35
4
4
Sense_wang
4
3
3
Adam Lin · @Agent-Threat-Rule · Taiwan
3
Richard Tweed · @tesslio · United Kingdom
2
2
2
2
2
1
1
1
1
1
1
1
OB · Coroboros
1
Would you bet a product on this? Bounded 0–100 and slow moving.
matched fp:f3415530c50df495, llm:Repository topics: agent, agent-skills, security; description: Security Scanner for Agent Skills
matched fp:f3415530c50df495, llm:Repository topics: agent, agent-skills, security; description: Security Scanner for Agent Skills
matched fp:f3415530c50df495, llm:Repository topics: agent, agent-skills, security; description: Security Scanner for Agent Skills