Observed arrival · 2026-09-27
SkillCanary checks AI skills before they reach your agent
A scanner for reviewing AI-agent skill files for prompt injection, credential access, exfiltration, and other attack signals before installation.
- For
- People reviewing third-party AI-agent skills before installation
- Worth noticing
- In its 100-skill sample, all 15 unsafe scores came from documentation-URL volume; none of eight named attack categories produced findings.
Field notes
The browser demo runs only a subset of the checks and presents a verdict band alongside the pasted skill; the site says the text stays in the browser. The reported field test covered 20 official Anthropic skills, 15 from obra/superpowers, and 65 from wshobson/agents. SkillCanary attributes its 15 unsafe scores to documentation-link volume, not live threats, and cautions that the sample is not evidence that the broader supply chain is safe.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue