Skillbadge — Security skill for Claude Code
In-browser trust scanner for AI agent skills (SKILL.md) — security heuristics + shareable badge.
How to install Skillbadge
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open devilking7x/skillbadge and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Skillbadge does
In-browser trust scanner for AI agent skills (SKILL.md) — security heuristics + shareable badge.
Alternatives in Security
- Security Threat Model — Generate repo-specific threat models identifying trust boundaries 14.6k ★
- Skill Scanner — Security Scanner for Agent Skills 2.5k ★
- Mcp-scan (Invariant Labs) — MCP security scanner with proxy mode for real-time scanning without infrastructure changes 1.9k ★
README

SkillBadge 🛡️
[](LICENSE) [](https://devilking7x.github.io/skillbadge/) [](#-privacy)
**Is that `SKILL.md` safe to install?** SkillBadge is an in-browser trust scanner for AI agent skills. Paste or drag & drop any `SKILL.md` file and get an instant heuristic security scan — prompt-injection phrases, exfiltration URLs, `curl | bash` pipes, credential harvesting, base64 blobs, obfuscated code, destructive shell commands, hardcoded secrets, and more.
🔗 **Live demo:** https://devilking7x.github.io/skillbadge/
✨ Features
- 20 heuristic security checks — prompt-injection / instruction overrides, secrecy directives, credential harvesting language, known exfiltration & drop domains (Discord webhooks, webhook.site, ngrok…), raw IPs in URLs,
curl|bash/wget|shpipes,rm -rf(escalated to critical for/,~,$HOMEtargets), dangerouschmod,sudoescalation,eval/exec, base64 blobs, obfuscated code (\xescapes,fromCharCode,atob, reversed strings), hardcoded secrets (Stripe/OpenAI/GitHub/AWS key patterns, private keys), env & shell-history snooping, reverse-shell primitives, persistence mechanisms (cron, systemd, rc files), sensitive local paths, URL-encoded links, plain-HTTP URLs, and missing frontmatter. - Trust score + verdict — 0–100 score with TRUSTED / CAUTION / SUSPICIOUS / DANGEROUS verdicts, each finding graded critical / warning / info with plain-English explanations and exact line-number matches.
- Shareable SVG badge — generate a shields-style "scanned" badge with one click, plus copy-paste Markdown and HTML embed snippets for your README.
- CI-friendly JSON report — downloadable report with an explicit
ci.failflag and threshold, ready to
Related Skills
Synk Skill Security Scanner
Agent Trust Hub
Security Audit Database
Use when auditing a database-backed app for the most common database security mistakes — multi-tenant data lea
Security Audit Web App
Use when auditing a web app frontend/edge layer for common security mistakes — server vs client boundary leaks
Webmcp Development Guide
Browser-side WebMCP development guide skill: existing-site integration, Declarative and Imperative APIs, secur
Stark Audit
Audit existing UI/UX code, flows, or screenshots against UX heuristics plus the matching platform's anti-slop
Jared Audit
Skeptical kanban-manager audit — walk the backlog oldest-first, verdict per item (close / reshape / leave-alon
Related Agents
Gitnexus Security Boundary Reviewer
GitNexus security and trust-boundary reviewer. Use for auth, permissions, secrets, injection, unsafe parsing,
Security Architecture
Boucle implements a defense-in-depth security model to protect against prompt injection attacks and maintain t
Security Reviewer Heavy
Security review for changes that touch security-sensitive areas — authentication, authorisation, session or to