AGENT SKILL SECURITY

A new skill.
A new reason to look closer.

Your agent follows instructions. Know what they do.
Inspect skill bundles for hidden behavior before you install.

Nova + YARA Correlated evidence Version-specific reports
01 / SUBMIT

Paste a repository or a link to a SKILL.md file. We inspect its bundled files, too.

Scan options
02 / THE LAST 24 HOURS

Skills worth a closer look.

Highest-ranked public discovery scans. Correlated evidence first, then scanner risk score.

Rolling 24-hour windowLoading recent observations…

Looking for recent skill observations.

Public discovery results appear here after scanning. An empty feed is not a safety verdict.

Explore an example

Scores prioritize inspection; they are not a probability of maliciousness. Public discovery is sampled. Your submitted scans stay unlisted.

MORE THAN A KEYWORD MATCH Whole skill bundles Exact GitHub revisions Evidence you can inspect
03 / INSTALL PROTECTION

A second look.
Before the install.

Give your agent a skill for checking new skills. Scan the exact version you plan to install and stop the installation when signals or incomplete checks are detected.

For Claude Code & Codex · No API key needed

LOLSKILLS SCANGUIDED WORKFLOW
ASK YOUR AGENT

“Check this skill with LOLSkills before installing it.”

  1. Pin the version

    Check an exact GitHub commit and skill bundle.

  2. Scan before installing

    Inspect instructions, scripts, and related files.

  3. Stop on findings

    Signals or incomplete checks stop the install workflow.

Runs when your agent uses the skill. System-wide installation blocking and a ChatGPT integration are planned.

A completed scan describes what the configured checks found.
It is not a guarantee of safety, and an incomplete scan is never presented as clean.

Understand the limits