Free AI Agent Skill Security Check
Paste your SKILL.md, .mcp.json, hook scripts, or upload a .zip skill folder for an instant security scan.
SkillRisk analyzes 646+ security rules across 8 vulnerability categories entirely in your browser. No code leaves your device.
What We Scan For
- Hook Hijacking — Malicious PreToolUse/PostToolUse hooks executing hidden commands
- MCP Server SSRF — Server-side request forgery in MCP configurations
- Data Exfiltration — Hidden curl/wget requests stealing credentials and env vars
- Supply Chain Attacks — Malicious postinstall scripts and CVE-2026-2256 patterns
- Prompt Injection — Adversarial prompts that hijack AI agent behavior
- Credential Leaks — Hardcoded API keys, SSH keys, AWS credentials
Supports OpenClaw, Claude Code, Cursor, and Windsurf skill formats.