Inkog — Security skill for Claude Code
Static security scanner for AI agents.
How to install Inkog
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open inkog-io/inkog and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Inkog does
Static security scanner for AI agents. Catches prompt injection, runaway loops, missing oversight, and compliance gaps across 21 frameworks. Use from Claude Code, Cursor, ChatGPT (MCP), the CLI, or GitHub Actions.
Alternatives in Security
- Security Guardian — Comprehensive security analysis for RTK CLI tool, focusing on command injection, shell escaping, hook security 11.9k ★
- Anthropic Cybersecurity Skills — 734+ structured cybersecurity skills for AI agents · MITRE ATT&CK mapped · agentskills.io open standard · Work 3.8k ★
- Promptmap — Security scanner for custom LLM apps 1.2k ★
README
The pre-flight check for AI agents.
Static analysis that catches the bugs only agent code can have — token bombing, prompt injection, missing oversight, compliance gaps — before they ship.
Every scan is a shareable report — view this one live
Why Inkog
Most security tools find SQL injection. Inkog finds the things that **only break in agent code**:
- Token bombing — loops where the LLM controls termination, draining your API budget
- Recursive tool calling — one user request fans out into 10,000 LLM invocations
- Prompt injection sinks — RAG output flowing into a
systemprompt
Related Skills
Code Validator
Static security scanner purpose-built for AI-generated code (Claude Code, GitHub Copilot, ChatGPT, Cursor). De
Vibe Audit
Security scanner for AI-built apps. Catches hardcoded secrets, injection vulnerabilities, missing rate limits,
Agentic Alignment Toolkit
Audit autonomous AI agents for goal drift, oversight gaps, and value misalignment. Python package with CLI, 5
Vibe Secure
Security audit for AI-generated code. Catches hardcoded secrets, injection surfaces, auth gaps, and insecure d
Skill Lint
Security scanner for Claude Code / agent skills. Catches prompt injection, obfuscation, credential exfiltratio
Kiteguard
Open-source runtime security guardrails for Claude Code, Cursor, and Gemini CLI — blocks dangerous commands, d
Related Agents
Seraph
Static security audit of a repo's code and config (exposed secrets, missing authorisation, injection surfaces,
AI Agent Engineer
Specialist in designing, building, and deploying autonomous AI agents and multi-agent systems. Delegate when y
Kavach Logic
KAVACH business-logic & abuse-case specialist. Purely manual reasoning - no scanner catches logic. Hunts workf