Know what you're installing.

Static security checks for agent skills, MCP servers, npm packages, VS Code extensions, and GitHub Actions. Every finding points to the file and line that triggered it.

Try

Run it locally or in CI

The same engine ships as an npm CLI that scans files on your machine without uploading them, and as a GitHub Action with JSON and SARIF reports for code scanning.

$ npx @maxwellyoung/skillscan ./my-skill