$npx skillfedfor your agent

cisco-ai-skill-scanner

Security scanner for Agent Skills packages - Detects prompt injection, data exfiltration, and malicious code

With conditionsPyPI TestingReleased Aug 2026295.3K downloads / moApache-2.0Pure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — cisco_ai_skill_scanner-2.0.13-py3-none-any.whl
v2.0.13 · released 2026-08-03 · Python >=3.10 · 20 runtime deps: anthropic, click, confusable-homoglyphs, fastapi, httpx, litellm, magika, oletools

Yes, with conditions. Install if you deploy AI agent skills and want a layered, best-effort threat detection baseline. The tool is actively maintained, has low install friction, and integrates cleanly into CI/CD. However, do not rely on it as your sole security control: the documentation explicitly warns that clean scans do not guarantee safety, and human code review remains essential for high-risk deployments. Suitable for teams building or consuming OpenAI Codex or Cursor Agent skills who need automated early warning.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10 or later.
  • LLM and cloud-based analyzers require API keys (SKILL_SCANNER_LLM_API_KEY, VIRUSTOTAL_API_KEY, AI_DEFENSE_API_KEY) set as environment variables; core static analysis runs without them.
  • Low friction: pure Python wheel with no compiled dependencies.

License · maintenance · safety

Apache-2.0 (permissive) — Apache-2.0 permissive license allows commercial and private use without restriction, modification, or redistribution obligations beyond license notice.

last release 2026-08-03 (11 days) · last repo commit 2026-08-04 · 2,431 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 295,264 downloads/mo, #7,926 on PyPI

Verify before relying

pip install cisco-ai-skill-scanner

skill-scanner scan /path/to/skill

# With LLM analysis and behavioral dataflow:
skill-scanner scan /path/to/skill --use-behavioral --use-llm
  • Actual false positive rate and detection precision across different threat categories in production use.
  • Performance characteristics (scan time, memory usage) on large skill repositories or complex dataflow graphs.
  • Whether the LLM consensus mode (multiple runs) materially improves detection accuracy over single-run LLM analysis.
Same gist for agents: .md · .json

What it is and what it does

Cisco AI Skill Scanner is a multi-engine security scanner designed to detect threats in AI Agent Skills—executable skill definitions for LLM agents following OpenAI Codex or Cursor Agent formats. It combines static pattern matching (YAML + YARA rules), behavioral dataflow analysis, and optional LLM-as-a-judge semantic analysis to identify prompt injection, data exfiltration, and malicious code patterns. The tool explicitly disclaims comprehensive coverage: a clean scan does not guarantee security, and novel attacks may evade detection.

The scanner integrates into CI/CD pipelines via SARIF output for GitHub Code Scanning, pre-commit hooks, and configurable exit codes. It supports custom YARA rules, threat taxonomies, and scan policies (strict/balanced/permissive), plus optional cloud integrations (VirusTotal, AWS Bedrock, Google Gemini, Azure OpenAI). A meta-analyzer reduces false positives, and an interactive wizard guides first-time users through CLI options.

Use it for

  • Scan AI agent skills in a GitHub Actions workflow before deployment to catch known threat patterns early.
  • Use as a pre-commit hook to prevent developers from committing skills with obvious prompt injection or exfiltration code.
  • Audit a repository of existing skills with behavioral and LLM analyzers enabled to identify latent threats across the codebase.
  • Generate SARIF reports for GitHub Code Scanning to surface skill security findings alongside other code quality checks.
  • Customize scan policies and YARA rules to match your organization's risk tolerance and threat model.
  • Integrate VirusTotal or Cisco AI Defense cloud scanning for binary and hash-based threat correlation.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, with conditions.

Install if you deploy AI agent skills and want a layered, best-effort threat detection baseline. The tool is actively maintained, has low install friction, and integrates cleanly into CI/CD. However, do not rely on it as your sole security control: the documentation explicitly warns that clean scans do not guarantee safety, and human code review remains essential for high-risk deployments. Suitable for teams building or consuming OpenAI Codex or Cursor Agent skills who need automated early warning.

Install

cisco-ai-skill-scanner on PyPI

Before you install

Low friction: pure Python wheel with no compiled dependencies. Active maintenance—released 11 days ago with 2431 GitHub stars. Requires Python 3.10+. Twenty runtime dependencies are substantial but all standard (anthropic, openai, fastapi, pydantic, yara-x, etc.), indicating a mature, feature-complete tool rather than a minimal proof-of-concept.

Requires Python 3.10 or later. LLM and cloud-based analyzers require API keys (SKILL_SCANNER_LLM_API_KEY, VIRUSTOTAL_API_KEY, AI_DEFENSE_API_KEY) set as environment variables; core static analysis runs without them.

License in practice

Apache-2.0 permissive license allows commercial and private use without restriction, modification, or redistribution obligations beyond license notice.

Quickstart

pip install cisco-ai-skill-scanner

skill-scanner scan /path/to/skill

# With LLM analysis and behavioral dataflow:
skill-scanner scan /path/to/skill --use-behavioral --use-llm

Verify before relying

  • Actual false positive rate and detection precision across different threat categories in production use.
  • Performance characteristics (scan time, memory usage) on large skill repositories or complex dataflow graphs.
  • Whether the LLM consensus mode (multiple runs) materially improves detection accuracy over single-run LLM analysis.

Package facts

LicenseApache-2.0 permissive
Python supportSupports the current Python release >=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
20 packages
anthropicclickconfusable-homoglyphsfastapihttpxlitellmmagikaoletoolsopenaipdfidpydanticpython-dotenvpython-frontmatterpython-multipartpyyamlrichtabulatetextualuvicornyara-x
MaintenanceActively maintained 11 days since the last release
Last repo commit
First released
Downloads295,264 / month, #7,926 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 4 - BetaEnvironment :: ConsoleIntended Audience :: DevelopersIntended Audience :: Information TechnologyLicense :: OSI Approved :: Apache Software LicenseOperating System :: OS IndependentProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Topic :: SecurityTopic :: Software Development :: Quality AssuranceTopic :: Software Development :: TestingTyping :: Typed

Evidence: cisco_ai_skill_scanner-2.0.13-py3-none-any.whl

Tags

Capabilities
ai agent skill security scannerprompt injection detectionllm security analysisagent skills threat detectionmalicious code pattern detectiondata exfiltration scanningopenai codex skill scannercursor agent skill security
Topics
ai-securitythreat-detectionci-cd-ready
PyPI keywords
ai-securityanthropicclaudecodexllm-securitymcpopenaiprompt-injectionscannersecurityskillsstatic-analysisthreat-detection

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “ai agent skill security scanner”

  • cisco-ai-skill-scannerScans AI Agent Skills for prompt injection, data exfiltration, and…
  • skillsawA linter for AI agent instruction files that detects structural…
  • plugin-scannerLints, verifies, and gates plugins, skills, MCP servers, and packages…

Give your agent the search over MCP, or paste the wish link into any chat.

More Testing packages

pluggy Worth it
PyPI · Libraries · released May 2025

Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.

Install it if you're building an extensible application or framework.

MITpure Python · 3.9+aging
1.3Bdownloads / mo
pytest Worth it
PyPI · Libraries · released Jun 2026

pytest is a testing framework that lets you write test functions using plain assert statements and automatically discovers and runs them, with detailed failure reporting.

MITpure Python · 3.10+
1.1Bdownloads / mo
virtualenv Worth it
PyPI · Libraries · released Aug 2026

virtualenv creates isolated Python environments where packages can be installed independently without affecting the system Python or other projects.

MITpure Python · 3.9+
532.9Mdownloads / mo
coverage Worth it
PyPI · Testing · released Aug 2026

Coverage.py measures which lines of Python code are executed during test runs, reporting coverage percentages and identifying untested code paths.

Install it if you want to measure test completeness or enforce coverage thresholds in your project.

permissive licensepure Python · 3.10+
335.8Mdownloads / mo
pytest-asyncio Worth it
PyPI · Testing · released May 2026

pytest-asyncio is a pytest plugin that enables writing and running async test functions using the asyncio library, allowing developers to await code directly within test cases.

Install it if you write tests for any asyncio-based code.

Apache-2.0pure Python · 3.10+
275.9Mdownloads / mo
pytest-json-ctrf Worth it
PyPI · Testing · released Jul 2026

A pytest plugin that generates test reports in Common Test Report Format (CTRF) as JSON, compatible with pytest-xdist and pytest-playwright for distributed and browser-based testing.

Install it if you need CTRF-formatted test output for CI/CD integration or cross-tool reporting.

MITpure Python · 3.8+
273.0Mdownloads / mo

See also bbot · cisco-ai-mcp-scanner · skillsaw · threatwire · skills-ref · sealights-python-agent · flawfinder · picklescan · boost-skill-cli · garak

Further reading