32% of ClawHub skills contain malicious code — 33,746 extensions scanned

Mandatory Security Scanning

The Only Skill Directory
With Security First

Every SKILL.md pre-scanned for malicious code, prompt injection attacks, and security vulnerabilities before listing.

AI Extensions Scanned: 0
1,541 Skills • 32,205 MCP Servers
6 Sources • ClawHub, SkillsMP, Skills.lc, MCP Registry, MCPMarket, Awesome MCP
K
Browse Verified Skills
0
AI Extensions Scanned
0
Malicious Blocked
99.8%
Detection Rate
Just now
Last Scan
Prompt Injection Tested
Sandbox Verified
No Exfiltration Code
Use SkillShield

One product, three ways to check AI skills

Browse the public directory first, run the local scanner before you install anything sensitive, and use hosted registry checks when you want a quick answer without a local scan setup.

1. Browse the scored directory

Start with the public dataset if you want a fast trust check, issue summary, and source context.

Best for

Checking a skill before you download it or comparing multiple options side by side.

Browse verified results

2. Scan locally with the canonical CLI

Use the local scanner when you want the main skillshield command on your machine.

Local scanner

npm install -g skillshield
skillshield scan ./SKILL.md

Use this when you want the local scanner and the canonical skillshield binary.

3. Run hosted registry checks

Use the hosted/API CLI when you want quick registry lookups through skillshield-registry.

Hosted checks

npm install -g skillshield-cli
skillshield-registry check github

The VS Code extension also depends on skillshield-registry being available on your PATH.

Command boundary

Do not mix the two CLI lanes

skillshield is the local scanner. skillshield-registry is the hosted registry/API CLI shipped through the skillshield-cli package. That split keeps the local security workflow and the hosted lookup workflow clean.

VS Code setup

  • Install the SkillShield Security extension.
  • Keep skillshield-registry on your PATH.
  • Use the directory first, then scan locally before you install high-trust skills.
NEW — First MCP Security Scanner

Secure Your MCP Servers

MCP servers are the browser extensions of AI agents — but with direct system access. We built the first security scanner to detect tool poisoning, over-permissioned access, and prompt injection vulnerabilities.

Tool Poisoning
Malicious instructions hidden in descriptions
Over-Permissioned
Unrestricted filesystem & network access
Prompt Injection
Attack vectors via crafted inputs
Supply Chain
Dependency & typosquatting risks
1,000+ servers analyzed
Free security scans
server-filesystem
modelcontextprotocol
45
Security Score
HIGH RISK
HIGH
Unrestricted filesystem access detected
MEDIUM
Path traversal vulnerability in tool schema
2 findings • Scan completed
View full report
Live Scanner

Risk Breakdown by Marketplace

Real scan data from 33,746 extensions across 6 sources

clawhub.ai

1,416 skills

⚠️ HIGH RISK
CRITICAL
461
HIGH
71
MEDIUM
154
LOW
730

⚡ 32.6% CRITICAL — nearly 1 in 3 skills are dangerous

skillsmp.com

160 skills

✅ CLEAN
CRITICAL
0
HIGH
0
MEDIUM
4
LOW
156

✅ 97.5% clean — well-curated marketplace

skills.lc

100 skills

✅ CLEAN
CRITICAL
0
HIGH
1
MEDIUM
5
LOW
94

✅ 94% clean — trusted open source skills

Browse Skills

Discover verified, secure SKILL.md files for your AI workflows

Showing 0 of 0

How We Protect You

Every skill undergoes a rigorous 3-step security analysis before being listed in our directory.

1

Upload

Developers submit their SKILL.md files through our secure portal or API.

2

Scan

Our automated systems perform static analysis, prompt injection detection, and sandbox testing.

3

Verify

Clean skills receive a security score and are listed. Suspicious files are quarantined.

Static Analysis

Deep code inspection for malicious patterns, hidden commands, and suspicious API calls.

Learn more

Prompt Injection Detection

Specialized testing for jailbreak attempts, instruction overrides, and manipulation techniques.

Learn more

Behavior Sandbox

Isolated execution environment to observe actual runtime behavior and network activity.

Learn more
Live Activity Feed

Frequently Asked Questions

Everything you need to know about SkillShield

A SKILL.md file is a standardized documentation format that describes how an AI model should perform a specific task or use a particular tool. It contains instructions, examples, constraints, and safety guidelines that help AI systems understand and execute the skill correctly.

Our scanning process uses a combination of static analysis, pattern matching, and dynamic sandboxing. We check for malicious code patterns, prompt injection vulnerabilities, data exfiltration attempts, and unexpected behavior in isolated environments. Each scan generates a detailed security report.

Absolutely! Anyone can submit a SKILL.md file for review. Simply create an account, upload your skill file, and our automated systems will begin the security scan. Once verified, your skill will be listed in the directory with full attribution.

Skills that fail our security checks are not listed in the public directory. The submitter receives a detailed report explaining what issues were found. Minor issues can often be fixed and resubmitted. Skills with serious security concerns are quarantined and flagged for manual review.

Yes! Browsing and using verified skills is completely free. We also offer free submissions for open-source skills. For commercial or high-volume submissions, we offer premium plans with priority scanning and additional features.

Ready to Secure Your AI Skills?

Join thousands of developers who trust SkillShield for verified, secure SKILL.md files.

Start Browsing

Popular Safe Skills

Explore our collection of verified, secure skills with 100/100 security scores — ready to install and use safely.