Local-first skill supply-chain linter — scan AI-agent skills for prompt-injection text, exfiltration lines, approval-disabling instructions, and embedded secrets. A CWI trust-layer product.
v1.0.0rules v1.0.0 · 25 rulesstdlib only$0LIVE demo — runs the real engine in your browser
Try it now — scan skill text in your browser
The live demo below runs the real 25-rule engine — paste a SKILL.md and get a severity-triaged verdict, parity-verified finding-for-finding against the Python CLI. No install, no accounts, no network — nothing you paste leaves your machine.
Store card #6 PENDING — price on request, never published without approval.
Scan skill text
Paste a SKILL.md (or any skill file) below, or pick files from disk. Every line is matched against the 25-rule versioned catalog — the same engine as the CLI, verified finding-for-finding.
Dogfood — the CLI's own test fixtures
These are the real fixture skills from the CLI test suite: planted prompt-injections, exfiltration lines, approval-disabling text, embedded-secret patterns, and clean-skill negative controls. Scanned live by this page's engine.
Rule catalog v1.0.0 · 25 rules · pinned per release
Published rules can be studied by attackers — the honest signature-game tradeoff. Rules are pinned per release and every report carries the rules version, so a clean verdict is auditable. Full patterns in rules.json.
Honest limits. Signature-based triage, never a certificate of safety. A PASS means no known signatures matched — it is not proof the skill is safe. Novel attacks, obfuscation, and non-text payloads are out of scope by design. No network, no telemetry, stdlib only.
Get Skill Doctor Lite for your pipeline
Skill Doctor Lite v1.0.0 — 25-rule versioned skill supply-chain linter with CI-ready exit codes and machine-readable reports. For licensing, volume, or integration inquiries:
A Cumulative Web Inc trust-layer product. Pricing on request — no prices are published without approval.