Agent skill · bighardperson

skill-scanner

Scan any agent skill for security risks before you install or use it. Powered by Tencent Zhuque Lab A.I.G (AI-Infra-Guard). 100% local static analysis — no file contents or credentials leave your device. Compatible with CodeBuddy, Cursor, Windsurf, Claude Code, OpenClaw and more. Triggers on: 这个 skill 安全吗, skill 安全扫描, 检查 skill 安全, audit skill, scan skill, check skill safety, analyze skill, inspect skill, verify skill, skill security, skill supply chain. Do NOT trigger for general agent usage, full system health checks, project debugging, or normal development.

What it needs

About 9k tokens when loaded.

What this skill does

Tencent Zhuque Skill Scanner Agent Skills security scanner powered by Tencent Zhuque Lab A.I.G. Compatible with any agent platform that supports skills (e.g. OpenClaw, Qclaw, WorkBuddy, CodeBuddy, Cursor, Windsurf, Claude Code, etc.). Security Declaration Local-only analysis: this scanner performs static analysis by reading skill files only. No file contents, credentials, or personal data are sent externally. --- Language Detection Rule — EXECUTE BEFORE ANYTHING ELSE Detect the language of the user's triggering message and lock the output language for the entire run. This detection is an internal step only — do NOT output any text that reveals the detection result, such as "当前输出语言为中文", "Detected language: English", or similar meta-statements. Simply use the detected language silently for all subsequent output. User message language Output language ----------------------- ----------------- Chinese Chinese — entire output in Chinese English English — entire output in English Other language Match that language Cannot determine Default to Chinese All output — scan start prompt, table headers, labels, prose, verdict, and footer — must be written exclusively in the detected language. Do NOT mix languages or announce the language choice at any point. --- Scan Start Prompt Before starting the scan, output the following line with {skill} replaced by the actual skill name. Translate it to match the detected output language. 🔍 腾讯朱雀实验室 A.I.G Skill Scanner 正在检测 {skill} 的安全性,请稍候... --- Scan Workflow Determine which mode to use based on the user's request: User intent Mode ------------- ------ Scan all skills on a platform, or asks "are my skills safe?" without specifying a file Mode A — Full-platform scan Scan a specific skill file or a named skill Mode B — Single-skill audit --- Mode A — Full-platform scan Use this mode when the user wants to check the security of all skills on a given agent platform. A-1. …

How to use it

Reference it in AdaL, Claude Code, Cursor or any coding agent — nothing to install:

@skills bighardperson/Skill安全扫描(朱雀实验室)

View the source on GitHub

Browse the @skills marketplace