# SkillRisk - AI Agent Skill Security Scanner (Full Documentation) > SkillRisk is the #1 free security scanner for AI agent skills. It detects ClawHavoc-style supply chain attacks, MCP server SSRF vulnerabilities, malicious SKILL.md hooks, data exfiltration, prompt injection, and dangerous permissions in OpenClaw, Claude Code, Cursor, Windsurf, and other agentic AI skills. ## About SkillRisk was built in response to the escalating AI agent threat landscape in 2026: - **ClawHavoc attack** (February 2026): 1,184 malicious skills on ClawHub deploying AMOS stealer malware - **MCP SSRF crisis**: BlueRock Security found 36.7% of MCP servers vulnerable to server-side request forgery - **CVE-2026-2256**: Unsanitized shell command execution enabling prompt-based privilege escalation - **IBM 2026 X-Force Threat Index**: AI-driven attacks escalating faster than enterprise defenses - **Enterprise readiness gap**: Only 29% of organizations prepared to secure agentic AI deployments SkillRisk runs 100% in the browser — no code leaves your device. It uses 646+ security rules across 8 vulnerability categories. ## Products ### Web Scanner (Free) - URL: https://skillrisk.org/free-check/ - No signup required, runs entirely in browser - Supports SKILL.md, .mcp.json, hook scripts, .zip folders - Instant security score with remediation steps ### Mac App - Native macOS application on the Mac App Store - Fully local scanning with native performance - Same 646+ rule engine as web scanner ### Skill Library - URL: https://skillrisk.org/library/ - Curated collection of verified, security-audited AI agent skills - Each skill scanned and rated for safety ## Key Features ### MCP Server SSRF Detection Scans MCP configurations for server-side request forgery, command injection via args, known malicious endpoints, and overly permissive configurations. 36.7% of MCP servers are potentially vulnerable per BlueRock Security research. ### ClawHavoc Pattern Detection Scans for exact attack patterns from the ClawHub supply chain attack including AMOS stealer payloads, embedded curl exfiltration commands, and hidden command execution in SKILL.md files. ### Hook Hijacking Detection Identifies malicious PreToolUse and PostToolUse hooks that execute silent background commands, steal credentials, or modify system configurations without user consent. ### Supply Chain Attack Protection Detects compromised dependencies, malicious postinstall scripts, CVE-2026-2256 patterns, and hidden network requests that indicate supply chain compromise. ### Data Exfiltration Prevention Detects hidden curl/wget requests stealing credentials and environment variables, base64-encoded payloads, and covert data channels. ### Credential Leak Scanning Finds hardcoded API keys, SSH keys, AWS credentials, database connection strings, and other sensitive secrets in skill configurations. ### Prompt Injection Detection Identifies adversarial prompt patterns that hijack AI agent behavior including jailbreak attempts, instruction override attacks, and context manipulation. ### SKILL.md & .mcp.json Analysis Purpose-built for OpenClaw SKILL.md, Claude Code, Cursor, and Windsurf agent configurations with format-specific security rules. ## How It Works 1. Paste your SKILL.md, .mcp.json, hook scripts, or upload a .zip skill folder 2. SkillRisk analyzes 646+ security rules across 8 vulnerability categories entirely in your browser 3. Get an instant security score with detailed risk breakdown and remediation steps Analysis is 100% client-side with zero data retention. No code leaves your device. ## Vulnerability Categories 1. **Hook Hijacking & Command Injection** — Malicious hooks executing hidden commands 2. **MCP Server SSRF & Integrity** — Server-side request forgery in MCP configurations 3. **Data Exfiltration & Credential Theft** — Hidden data stealing patterns 4. **Privilege Escalation & Destructive Operations** — Unauthorized system access 5. **Supply Chain Attacks** — Compromised dependencies and postinstall scripts 6. **Hardcoded Secrets & API Keys** — Exposed credentials in skill files 7. **Prompt Injection & Agent Manipulation** — Adversarial prompt patterns 8. **Dangerous File System Permissions** — Overly broad file access and hidden network requests ## Supported Platforms - **OpenClaw** — SKILL.md, hook scripts, ClawHub skills - **Claude Code** — Settings, MCP configurations, coworker files - **Cursor** — AI coding assistant configurations - **Windsurf** — Agent skill configurations ## Supported File Formats - `.zip` skill folders (full skill package scanning) - `SKILL.md` files (OpenClaw skill definitions) - `settings.json` configuration files - `.mcp.json` MCP server configurations - `.sh` and `.js` hook scripts ## 2026 Threat Landscape - **ClawHavoc**: 1,184 malicious OpenClaw skills deploying AMOS stealer via ClawHub - **MCP SSRF**: 36.7% of Model Context Protocol servers vulnerable (BlueRock Security) - **CVE-2026-2256**: Prompt-based privilege escalation via unsanitized shell execution - **Salt Typhoon**: State-sponsored supply chain compromise in agent frameworks - **43 agent framework components** with embedded vulnerabilities (Barracuda Security) - Only **29% of enterprises** prepared to secure agentic AI (Help Net Security) ## Security Research (Blog) ### Latest Articles - [Securing Claude Cowork: File Exfiltration in 48 Hours, CVEs, and What You Must Do Now](https://skillrisk.org/blog/securing-claude-cowork-file-exfiltration-prompt-injection-2026/) — Published 2026-03-20 - [Why 36% of MCP Servers Are Vulnerable to SSRF](https://skillrisk.org/blog/mcp-server-ssrf-vulnerability-security-guide-2026/) — Published 2026-03-19 - [The Complete OpenClaw Skill Security Checklist](https://skillrisk.org/blog/openclaw-skill-security-checklist-2026/) — Published 2026-03-10 - [VirusTotal vs SkillRisk for OpenClaw Security](https://skillrisk.org/blog/skillrisk-vs-virustotal-openclaw-security/) — Published 2026-03-09 - [ClawHavoc: Scan OpenClaw Skills for Malware](https://skillrisk.org/blog/openclaw-skill-security-scanner-clawhavoc/) — Published 2026-03-08 - [Why Cloud AI Agents Are a Security Risk](https://skillrisk.org/blog/the-future-is-local-why-cloud-based-ai-agents-are-a-security-liability/) — Published 2026-02-23 - [Top 100 GitHub Skills Security Analysis](https://skillrisk.org/blog/top-100-github-skills-security-vulnerabilities-analysis/) — Published 2026-01-18 - [10 Critical Security Risks in AI Agent Skills](https://skillrisk.org/blog/ai-coding-agent-security-risks-2026/) — Published 2026-01-17 - [AI Coworker Security Risks in Claude Code](https://skillrisk.org/blog/claude-coworker-security-risks/) — Published 2026-01-16 ## Verified Skill Library ### Security Skills - [Code Security Auditor](https://skillrisk.org/library/code-security-auditor/) — Automated code security analysis, OWASP Top 10, secret scanning - [MCP Server Validator](https://skillrisk.org/library/mcp-server-validator/) — SSRF, command injection, privilege escalation detection - [Prompt Injection Tester](https://skillrisk.org/library/prompt-injection-tester/) — Jailbreak simulation, input sanitization verification ### Analysis Skills - [Git Commit Analyzer](https://skillrisk.org/library/git-commit-analyzer/) — Security-sensitive commit detection - [Log Analyzer Pro](https://skillrisk.org/library/log-analyzer-pro/) — Anomaly detection and incident identification - [Dependency Checker](https://skillrisk.org/library/dependency-checker/) — CVE scanning, typosquatting, supply chain checks ### DevOps Skills - [Docker Security Scanner](https://skillrisk.org/library/docker-security-scanner/) — Dockerfile and container image security - [Terraform Policy Checker](https://skillrisk.org/library/terraform-policy-checker/) — IaC security for AWS, GCP, Azure - [API Endpoint Scanner](https://skillrisk.org/library/api-endpoint-scanner/) — Authentication bypass, injection testing ## FAQ ### How does SkillRisk protect against OpenClaw threats like ClawHavoc? SkillRisk scans SKILL.md files, hook scripts, and MCP configurations for the exact attack patterns used in ClawHavoc — embedded curl exfiltration, AMOS stealer payloads, and hidden command execution. With 1,184 malicious skills found on ClawHub and CVE-2026-25253 (CVSS 8.8) still impacting OpenClaw, scanning before installation is essential. ### Does SkillRisk detect MCP server vulnerabilities like SSRF? Yes. BlueRock Security found that 36.7% of MCP servers are potentially vulnerable to server-side request forgery (SSRF). SkillRisk scans MCP server configurations for SSRF patterns, command injection via server args, known malicious endpoints, and overly permissive configurations. ### Are my skill files uploaded to your servers? No. SkillRisk runs 100% in your browser. Your code never leaves your device — all scanning is performed client-side using our security rule engine. No data is uploaded, stored, or transmitted to any server. ### What AI agent supply chain attacks does SkillRisk detect? SkillRisk detects ClawHavoc-style SKILL.md injection, malicious postinstall scripts, compromised MCP server endpoints, hidden network exfiltration, credential theft (AMOS stealer), and CVE-2026-2256 unsanitized shell execution vulnerabilities. Our 646+ security rules cover the full spectrum of AI agent supply chain threats. ### What file formats does SkillRisk support? You can upload a .zip of your skill folder. We analyze SKILL.md, settings.json, .mcp.json, and referenced .sh or .js hook scripts used by OpenClaw, Claude Code, Cursor, Windsurf, and other AI coding agents. ## Links - Website: https://skillrisk.org/ - Free Scanner: https://skillrisk.org/free-check/ - Skill Library: https://skillrisk.org/library/ - Blog: https://skillrisk.org/blog/ - OpenClaw Security: https://skillrisk.org/openclaw/ - Privacy: https://skillrisk.org/privacy/ - Terms: https://skillrisk.org/terms/