We built a zero-config npm/pip scanner that audits AI agent skills before installation. We expose security gaps by diffing declared permissions against real-world behavior across 10 rule categories. Unlike single-file scanners, we catch combined multi-file risks: privilege chaining, prompt injections, undeclared network calls, and credential harvesting.
SkillGuard is open-source, self-hosted, and licensed with Apache 2.0.