skillvet is a one-command supply-chain scanner for AI agent skills and MCP servers. It reads the tree without executing it and prints a RED / YELLOW / GREEN verdict in about five seconds. Node 20+, zero runtime dependencies. Flags undeclared outbound hosts, ~/.ssh and token reads, npm postinstall hooks, base64/eval-style obfuscation, and unexpected binaries. MIT license.
Maker here. I kept dropping random SKILL.md folders into a local agent with full machine access. This month researchers flagged ~7,600 malicious GitHub repos, 800+ posing as AI skills/MCP. I wanted a five-second check before install, not another dashboard. It is not a sandbox and a GREEN is not a proof of safety, but it catches the sloppy stuff already in the wild: install hooks, stolen-token reads, mystery binaries, and a fetch to a domain the skill never declared. Feedback on false positives welcome, especially on phone-home patterns.