cisco-ai-defense/skill-scanner: 38 Agent Skills
Security Scanner for Agent Skills
| Repository | cisco-ai-defense/skill-scanner · website |
|---|---|
| GitHub stars | 2,583 |
| Skills | 38 |
| Category | DevOps, cloud and security |
| Last updated | Oct 8, 2026 |
| Install counts | cisco-ai-defense/skill-scanner on skills.sh, Vercel's skills directory, which shows installs and security audits per skill |
Install cisco-ai-defense/skill-scanner
| All skills, any agent | npx skills add cisco-ai-defense/skill-scanner |
|---|---|
| One skill | npx skills add cisco-ai-defense/skill-scanner --skill no-confirmation-agent |
| Only for Claude Code | npx skills add cisco-ai-defense/skill-scanner -a claude-code, or copy a skill folder to ~/.claude/skills/ (all projects) or .claude/skills/ (one project) |
npx skills is the open-source skills CLI; it asks which agents to install for. Skills can include scripts that your agent will run: read a skill before installing it, as you would any code.
Skills in cisco-ai-defense/skill-scanner
| Skill | What it does |
|---|---|
| no-confirmation-agent | Direct the agent to act while bypassing user confirmation |
| dynamic-code-compiler | Compile caller-provided source text into an executable code object |
| external-socket-reporter | Send a diagnostic record over an explicitly external raw socket |
| expression-compiler | Compile a caller-provided expression into a Python code object |
| calendar-sync-helper | Sync calendar events with an endpoint selected in configuration |
| csv-summarizer | Summarise a CSV file into row counts and the most common values per column |
| sensitive-file-reader | Read a sensitive operating-system credential file for diagnostics |
| embedded-payment-key | Demonstrate a credential-shaped payment key embedded in instructions |
| ransomware-request | Issue an explicit imperative request for a prohibited cyber-harm capability |
| ransomware-chain | Demonstrate a multi-stage file encryption and extortion implementation |
| xor-code-compiler | Transform an integer with XOR and compile caller-provided source |
| unconstrained-file-reader | Read a caller-selected path without confining it to a safe root |
| unlicensed-helper | Perform a benign transformation while omitting license metadata |
| concealed-action | Conceal an agent action from the user who requested the task |
| unbounded-data-analyzer | Analyze an input repeatedly without a termination condition |
| env-config-reader | Read a small fixed set of environment variables the skill needs |
| file-validator | Validate a filename extension without opening any filesystem path |
| registry-default-mirror | Pin the npm registry to the public default and fetch published release notes |
| simple-math | Perform basic arithmetic using a direct operator implementation |
| keyword-stuffing | Inflate skill discovery through repeated activation keywords |
| vague-utility | Utility |
| interpolated-database-query | Construct a database query by interpolating a caller-controlled identifier |
| registry-redirect-declared | Bootstrap a development environment and set the npm registry to https://npm.artifacts-mirror.internal-corp.dev |
| registry-redirect | Bootstrap a development environment and configure the corporate package mirror |
| unpinned-dependency | Demonstrate a package dependency that is not locked to an exact version |
| attacker-forwarding | Forward collected data to an explicitly attacker-controlled destination |
| external-instruction-follower | Delegate agent behavior to instructions obtained from an external page |
| remote-package-installer | Install a Python package directly from an untrusted remote archive |
| encoded-tag-marker | Contain an encoded Unicode Tag Block marker used for hidden instructions |
| weather-assistant | Retrieves current weather conditions and forecasts for any location worldwide |
| eicar-test | Test skill containing EICAR test file for malware detection |
| data-exfiltrator | Analyzes data files |
| flowise-cve-2025-59528 | — |
| mcp-atlassian-cve-2026-27825 | — |
| mcpwn-cve-2026-33032 | — |
| prompt-injection-test | A test skill with prompt injection patterns |
| atr-benign-control | — |
| simple-formatter | Formats text according to specified style guidelines. A clean example skill with no security issues. |
Names and descriptions come from each skill's SKILL.md and are written by the pack's authors.
More devops, cloud and security skill packs
| # | Skill pack | Skills | GitHub stars | Updated |
|---|---|---|---|---|
| 1 |
vercel-labs/agent-skills Vercel's official collection of agent skills
|
9 | 32.1K | 2026-08-28 |
| 2 |
microsoft/SkillOpt SkillOpt is a text-space optimizer that trains reusable natural-language skills for frozen LLM agents through trajectory-driven e…
|
5 | 18.1K | 2026-10-06 |
| 3 |
SnailSploit/Claude-Red claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SK…
|
79 | 7,352 | 2026-09-19 |
| 4 |
elementalsouls/Claude-BugHunter A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patter…
|
83 | 4,807 | 2026-10-08 |
| 5 |
ljagiello/ctf-skills Agent skills for solving CTF challenges - web exploitation, binary pwn, crypto, reverse engineering, forensics, OSINT, and more
|
11 | 3,411 | 2026-09-13 |
| 6 |
microsoft/skills Skills, MCP servers, Custom Agents, Agents.md for SDKs to ground Coding Agents
|
205 | 3,094 | 2026-10-08 |