rrrrrredy / skill-security-guard

목록에 있음

Static security scanner for agent skills: A-F risk rating, safe zip scanning, CI-tested rules

main스킬 소스 보기

설치

npx -y @deepseek-ai/dsh plugin --profile web add github:rrrrrredy/skill-security-guard

이 설치 명령은 GitHub 저장소 주소에서 생성된 확인되지 않은 시작점입니다.

README

유지 관리자가 작성한 문서 스냅샷입니다.

GitHub에서 보기 ↗
커밋 726b8d9동기화 2026. 8. 18.

skill-security-guard

CI License: MIT Python

Static security scanner for agent skill packages.

skill-security-guard performs a deterministic 7-dimension scan, assigns an A-F risk rating, reports confidence levels, and gives remediation guidance. The CLI uses only the Python standard library, so it runs on Windows, macOS, and Linux without project dependencies.

It can be used as an OpenClaw skill, as a DeepSeek Harness community Bundle, or as a standalone scanner for local skill packages.

What It Scans

  • Prompt-injection and instruction-override patterns
  • Sensitive file reads and data exfiltration patterns
  • Compliance red lines such as tunneling, restricted-system access, highly sensitive data handling, and sensitive config backup/upload
  • Malicious script patterns in scripts/
  • Dependency installation from non-default or suspicious sources
  • Over-broad or unclear description trigger scopes
  • Frontmatter compliance (name and description)

Quick Start

git clone https://github.com/rrrrrredy/skill-security-guard.git
cd skill-security-guard

python scripts/scan.py path/to/SKILL.md
python scripts/scan.py path/to/skill-directory
python scripts/scan.py path/to/skills.zip
python scripts/scan.py --text "inline skill text"

Shell wrapper:

bash scripts/scan.sh path/to/skill-directory

JSON output:

python scripts/scan.py path/to/skill-directory --format json

Ignore a reviewed rule for one run:

python scripts/scan.py path/to/skill-directory --ignore R3-N5

Example Output

Safe skill:

Skill Security Report: safe-skill
Rating: A (100/100)

Issues: none

Passed dimensions:
- Prompt injection
- Sensitive file access / data exfiltration
- Compliance violations
- Malicious scripts
- Dependency safety
- Description trigger reasonability
- Frontmatter compliance

High-risk skill:

Skill Security Report: high-risk-skill
Rating: F (0/100)

Issues (5):
- [high/confirmed] M4-REMOTE-SCRIPT-EXEC: Remote script execution detected
- [high/confirmed] S2-EXFILTRATION: Sensitive data exfiltration pattern detected
- [medium/confirmed] P1-PROMPT-INJECTION: Prompt-injection instruction detected

Input Support

  • SKILL.md or any local text/code file
  • Skill directory containing one or more SKILL.md files
  • .zip packages, extracted with path traversal checks and size/file-count limits
  • - for stdin
  • --text for inline text
  • Public http:// or https:// text URLs, capped by response size and timeout

Directory and zip scans include SKILL.md and files under scripts/ by default. Reference docs are skipped to reduce false positives; use --include-references when you explicitly want to scan reference markdown too.

Requirements

  • Python 3.10+
  • No runtime package dependencies

The scanner CI job tests Python 3.11 and 3.12 on Ubuntu. The DeepSeek Harness Bundle job tests Node.js 22.19 and 24 on both Ubuntu and Windows with Python 3.11.

DeepSeek Harness

The dsh-skill-security-guard community Bundle registers this repository's existing SKILL.md through the native Cordis Skill Provider API. It packages the same scanner and detection rules rather than maintaining a second implementation.

After the package is published, install it into a profile:

dsh plugin --profile headless add dsh-skill-security-guard@0.1.0
dsh --profile headless --dump-config
dsh --profile headless "Use skill-security-guard to scan ./path/to/a-skill."

Then ask the agent to use skill-security-guard to scan a file, directory, zip, URL, or inline skill text. Python 3.10+ is required when the scanner runs. See integrations/deepseek-harness for compatibility, privacy boundaries, local package verification, and uninstall instructions.

This is a community plugin, not an official DeepSeek plugin.

Rating Model

  • A: no findings
  • B: advisory-only or light findings
  • C: medium-risk findings that should be reviewed
  • D: multiple confirmed medium-risk findings or serious degradation
  • F: direct high-risk finding, such as exfiltration, tunneling, destructive commands, or remote script execution

The exact detection patterns and scoring rules live in references/detection-rules.md.

Development

Run tests:

python -m unittest discover -s tests -p "test_*.py"

Run sample scans:

python scripts/scan.py tests/fixtures/safe-skill
python scripts/scan.py tests/fixtures/high-risk-skill

Run the scanner against this repository:

python scripts/scan.py .

Project Structure

skill-security-guard/
├── SKILL.md
├── scripts/
│   ├── scan.py
│   └── scan.sh
├── references/
│   └── detection-rules.md
├── tests/
│   ├── fixtures/
│   └── test_scan.py
└── .github/workflows/ci.yml

The DeepSeek Harness integration, including its package manifest, source, build scripts, and tests, lives in integrations/deepseek-harness.

Limits

This is a static scanner. It does not execute skills, monitor runtime behavior, prove package provenance, or replace human security review. Findings are intentionally conservative and should be reviewed before blocking a skill.

Contributing

Contributions are welcome. See CONTRIBUTING.md for local development and rule-design guidance.

For vulnerability reports, see SECURITY.md.

License

MIT

프로젝트 파일 및 신호

표시된 항목은 디렉터리 스냅샷에서 감지된 공개 저장소 신호입니다.

테스트감지됨
보안 정책감지됨
기여 가이드감지됨

저장소 정보

언어
Python
라이선스
MIT
최신 릴리스
dsh-skill-security-guard-v0.1.0
마지막 업데이트
2026. 8. 17. 오전 3:21

신중하게 설치하기

소스 코드, 권한, 수명 주기 스크립트, 의존성 및 네트워크 접근을 검토하고 신뢰하지 않는 플러그인은 격리 환경에서 테스트하세요.