SkillsGuard – static scanner for malicious AI agent skills
Catches malicious AI skill scripts when Semgrep and Snyk miss the format.

Gamified security training for AI agent skills, but it's pre-attack learning, not production defense.
Security engineers, AI product teams, DevSecOps practitioners, enterprises deploying agent frameworks
PicoCTF · PortSwigger Web Security Academy · OWASP Top 10
Catches malicious AI skill scripts when Semgrep and Snyk miss the format.
First open-source scanner for AI agent skill supply-chain attacks.
Hides AI secret, live multiplayer prompts race to uncover it through social competition.
Detects credential theft patterns in AI skill files after ClaudHub attack proved the risk.
Classic road trip game digitized, but manual tracking offers no advantage over paper.
This feels like the first serious attempt to treat agent-to-agent chatter as a network security problem: 16+ prompt-injection signatures (with recursive base64 decoding), AST static analysis of skills via acorn/estree, and sandboxed dynamic checks are concrete, non-trivial defenses. The repo shows real engineering (Docker, CI, security scans, 181 tests) — the missing piece is real-world performance and adoption, but if you run agent fleets this is worth poking at.