Know what you're installing.
Static security checks for agent skills, MCP servers, npm packages, VS Code extensions, and GitHub Actions. Every finding points to the file and line that triggered it.
Try
⌘ + Enter
Run it locally or in CI
The same engine ships as an npm CLI that scans files on your machine without uploading them, and as a GitHub Action with JSON and SARIF reports for code scanning.
$ npx @maxwellyoung/skillscan ./my-skill