devilking7x

Skillbadge — Security skill for Claude Code

Security community

In-browser trust scanner for AI agent skills (SKILL.md) — security heuristics + shareable badge.

How to install Skillbadge

This entry records only its repository, not the path inside it, so there is no exact command to give. Open devilking7x/skillbadge and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What Skillbadge does

In-browser trust scanner for AI agent skills (SKILL.md) — security heuristics + shareable badge.

Alternatives in Security

README

![SkillBadge — In-browser trust scanner for AI agent skills](og-image.webp)

SkillBadge 🛡️

[![MIT License](https://img.shields.io/badge/license-MIT-emerald)](LICENSE) [![Live demo](https://img.shields.io/badge/demo-live-emerald)](https://devilking7x.github.io/skillbadge/) [![100% client-side](https://img.shields.io/badge/client--side-100%25-blue)](#-privacy)

**Is that `SKILL.md` safe to install?** SkillBadge is an in-browser trust scanner for AI agent skills. Paste or drag & drop any `SKILL.md` file and get an instant heuristic security scan — prompt-injection phrases, exfiltration URLs, `curl | bash` pipes, credential harvesting, base64 blobs, obfuscated code, destructive shell commands, hardcoded secrets, and more.

🔗 **Live demo:** https://devilking7x.github.io/skillbadge/

✨ Features

  • 20 heuristic security checks — prompt-injection / instruction overrides, secrecy directives, credential harvesting language, known exfiltration & drop domains (Discord webhooks, webhook.site, ngrok…), raw IPs in URLs, curl|bash / wget|sh pipes, rm -rf (escalated to critical for /, ~, $HOME targets), dangerous chmod, sudo escalation, eval/exec, base64 blobs, obfuscated code (\x escapes, fromCharCode, atob, reversed strings), hardcoded secrets (Stripe/OpenAI/GitHub/AWS key patterns, private keys), env & shell-history snooping, reverse-shell primitives, persistence mechanisms (cron, systemd, rc files), sensitive local paths, URL-encoded links, plain-HTTP URLs, and missing frontmatter.
  • Trust score + verdict — 0–100 score with TRUSTED / CAUTION / SUSPICIOUS / DANGEROUS verdicts, each finding graded critical / warning / info with plain-English explanations and exact line-number matches.
  • Shareable SVG badge — generate a shields-style "scanned" badge with one click, plus copy-paste Markdown and HTML embed snippets for your README.
  • CI-friendly JSON report — downloadable report with an explicit ci.fail flag and threshold, ready to