← Plugin catalog
Security

Skill Risk Check

Orbral v0.1.5

Publisher description

From the marketplace listing

Use this before installing an agent skill or plugin. Skill Risk Check scans local files for hidden instructions, broad permissions, suspicious downloads, prompt-injection patterns, and possible secret exposure, then returns ranked findings with file-and-line evidence and remediation. Do not use it as a safety certification; it never runs, installs, enables, or uploads the target.

Language: English · Automatically detected from descriptions.

Publisher keywords

Search terms declared by the publisher.

Matches for “plugins”

Exact text from the indicated source. A mention alone does not establish support for your task.

Publisher capabilities · listing

Scan local skills and plugins before install Find risky instructions, permissions, and downloads Show file-and-line evidence and remediation Export JSON, Markdown, and SARIF Never run or upload the target

Publisher description

Scan agent skills and plugins locally for reviewable risk patterns before installation.

Files & skills

File archives

Plugin package37 files · 9.07 MBBrowse files →
Skill instructions
agent-skillguard1.68 KB

View saved version →

---
name: agent-skillguard
description: Use before installing an agent skill or plugin. Scan local files for risky instructions, broad permissions, suspicious downloads, prompt-injection patterns, and possible secret exposure; return file-and-line findings and remediation without running, uploading, or certifying the target.
---

# Skill Risk Check

Use this skill when the user asks whether an agent skill or plugin should be trusted, installed, reviewed, or admitted.

## Non-negotiable boundary

Scanning is read-only. Never execute, source, import, install, or enable the target artifact during review. A clean report is not proof that an artifact is safe, and a finding is not proof of malicious intent.

## Workflow

1. Identify the exact local target and its provenance.
2. Run `skillguard scan <path> --format markdown` before any installation step.
3. Review every active finding at its exact file and line.
4. Separate confirmed behavior, ambiguous behavior, and false positives.
5. If a false positive is accepted, suppress only its exact fingerprint, rule ID, and rule version with a concrete reason.
6. Re-run the scan and report both active and suppressed counts.
7. Stop before installation or permission grants unless the user separately authorized them.
8. When evaluating the scanner itself, require the public positive/negative fixture corpus and non-coverage registry to pass `tools/verify_rule_corpus.py`.

## Exit codes

- `0`: no active findings at or above the selected severity.
- `1`: at least one active finding requires review.
- `2`: the scan could not be completed reliably.

Exit `0` means only that the configured deterministic rules found no active match. It is not a safety certification.
Package details

Publisher declarations from the archived package. These are separate from our research and the live service's terms.

Package license
MIT
Package author
Orbral
Keywords
See publisher keywords

Declared capabilities

  • Scan local skills and plugins before install
  • Find risky instructions, permissions, and downloads
  • Show file-and-line evidence and remediation
  • Export JSON, Markdown, and SARIF
  • Never run or upload the target

Some manifest fields differ or could not be read. The structured report retains the source references.

Package observed Oct 3, 2026.

Technical details
First seen
Sep 30, 2026 · 22:02 UTC
Last seen
Oct 4, 2026 · 12:00 UTC
Collection status
Collected

plugins_6a8d0cf2365881919812f4c32c7648e6

Download plugin data (JSON)

Before you connect Skill Risk Check

How do I connect it?

Open the publisher's marketplace listing to check current availability and follow its connection instructions. This directory does not install plugins. Check the requested access and any account requirements before connecting.

Check marketplace availability ↗

Does it require paid access?

We have not established the pricing or subscription requirements for this plugin. An absent price does not mean free access.

Compare researched pricing and access models →

How can I evaluate it?

Check the declared skills and available files, then try a small task whose result you can verify. Our archived descriptions and instructions establish publisher claims, not tested runtime quality. Review sources and coverage limits.