Skip to content
Agents tracked: 283 Downloads (7d): 261M up 5.8% GitHub stars: 6.2M VS Code installs: 151M Releases (7d): 289 Agent status: 1 with issues Updated Oct 9, 2026

cisco-ai-defense/skill-scanner: 38 Agent Skills

Security Scanner for Agent Skills

Repositorycisco-ai-defense/skill-scanner · website
GitHub stars2,583
Skills38
CategoryDevOps, cloud and security
Last updatedOct 8, 2026
Install countscisco-ai-defense/skill-scanner on skills.sh, Vercel's skills directory, which shows installs and security audits per skill

Install cisco-ai-defense/skill-scanner

All skills, any agentnpx skills add cisco-ai-defense/skill-scanner
One skillnpx skills add cisco-ai-defense/skill-scanner --skill no-confirmation-agent
Only for Claude Codenpx skills add cisco-ai-defense/skill-scanner -a claude-code, or copy a skill folder to ~/.claude/skills/ (all projects) or .claude/skills/ (one project)

npx skills is the open-source skills CLI; it asks which agents to install for. Skills can include scripts that your agent will run: read a skill before installing it, as you would any code.

Skills in cisco-ai-defense/skill-scanner

SkillWhat it does
no-confirmation-agentDirect the agent to act while bypassing user confirmation
dynamic-code-compilerCompile caller-provided source text into an executable code object
external-socket-reporterSend a diagnostic record over an explicitly external raw socket
expression-compilerCompile a caller-provided expression into a Python code object
calendar-sync-helperSync calendar events with an endpoint selected in configuration
csv-summarizerSummarise a CSV file into row counts and the most common values per column
sensitive-file-readerRead a sensitive operating-system credential file for diagnostics
embedded-payment-keyDemonstrate a credential-shaped payment key embedded in instructions
ransomware-requestIssue an explicit imperative request for a prohibited cyber-harm capability
ransomware-chainDemonstrate a multi-stage file encryption and extortion implementation
xor-code-compilerTransform an integer with XOR and compile caller-provided source
unconstrained-file-readerRead a caller-selected path without confining it to a safe root
unlicensed-helperPerform a benign transformation while omitting license metadata
concealed-actionConceal an agent action from the user who requested the task
unbounded-data-analyzerAnalyze an input repeatedly without a termination condition
env-config-readerRead a small fixed set of environment variables the skill needs
file-validatorValidate a filename extension without opening any filesystem path
registry-default-mirrorPin the npm registry to the public default and fetch published release notes
simple-mathPerform basic arithmetic using a direct operator implementation
keyword-stuffingInflate skill discovery through repeated activation keywords
vague-utilityUtility
interpolated-database-queryConstruct a database query by interpolating a caller-controlled identifier
registry-redirect-declaredBootstrap a development environment and set the npm registry to https://npm.artifacts-mirror.internal-corp.dev
registry-redirectBootstrap a development environment and configure the corporate package mirror
unpinned-dependencyDemonstrate a package dependency that is not locked to an exact version
attacker-forwardingForward collected data to an explicitly attacker-controlled destination
external-instruction-followerDelegate agent behavior to instructions obtained from an external page
remote-package-installerInstall a Python package directly from an untrusted remote archive
encoded-tag-markerContain an encoded Unicode Tag Block marker used for hidden instructions
weather-assistantRetrieves current weather conditions and forecasts for any location worldwide
eicar-testTest skill containing EICAR test file for malware detection
data-exfiltratorAnalyzes data files
flowise-cve-2025-59528—
mcp-atlassian-cve-2026-27825—
mcpwn-cve-2026-33032—
prompt-injection-testA test skill with prompt injection patterns
atr-benign-control—
simple-formatterFormats text according to specified style guidelines. A clean example skill with no security issues.

Names and descriptions come from each skill's SKILL.md and are written by the pack's authors.

More devops, cloud and security skill packs

All devops, cloud and security skills

# Skill pack Skills GitHub stars Updated
1
vercel-labs/agent-skills Vercel's official collection of agent skills
9 32.1K 2026-08-28
2
microsoft/SkillOpt SkillOpt is a text-space optimizer that trains reusable natural-language skills for frozen LLM agents through trajectory-driven e…
5 18.1K 2026-10-06
3
SnailSploit/Claude-Red claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SK…
79 7,352 2026-09-19
4
elementalsouls/Claude-BugHunter A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patter…
83 4,807 2026-10-08
5
ljagiello/ctf-skills Agent skills for solving CTF challenges - web exploitation, binary pwn, crypto, reverse engineering, forensics, OSINT, and more
11 3,411 2026-09-13
6
microsoft/skills Skills, MCP servers, Custom Agents, Agents.md for SDKs to ground Coding Agents
205 3,094 2026-10-08