← Skill Risk CheckCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
changed
Update to Skill Risk Check
Snapshot Oct 9, 2026 · 00:00 UTC · version 0.1.5
Package or technical metadata updated
Discoverability changed from “UNLISTED” to “LISTED”.
Observed in package metadata. These changes alone do not establish a new customer-facing feature.
Discoverability
Before
UNLISTED
After
LISTED
Compare saved observations
Download comparison JSONFull technical diff · 1 changed fields
changed /discoverability
BEFORE
"UNLISTED"
AFTER
"LISTED"
Full snapshot data
{
"canonical_app_id": null,
"connector_id": null,
"created_at": "2026-08-25T03:55:49.169893Z",
"discoverability": "LISTED",
"id": "plugins_6a8d0cf2365881919812f4c32c7648e6",
"is_template": false,
"name": "agent-skillguard",
"release": {
"app_ids": [],
"app_manifest": null,
"app_templates": [],
"description": "Scan agent skills and plugins locally for reviewable risk patterns before installation.",
"display_name": "Skill Risk Check",
"id": "pluginrel_18406829f2b081918a09a6c0535e6fd4",
"interface": {
"brand_color": "#0183E0",
"capabilities": [
"Scan local skills and plugins before install",
"Find risky instructions, permissions, and downloads",
"Show file-and-line evidence and remediation",
"Export JSON, Markdown, and SARIF",
"Never run or upload the target"
],
"category": "Security",
"composer_icon_dark_url": null,
"composer_icon_url": "https://files.openai.com/content?id=file_000000007f3c81f5a117583353b12d2f",
"default_prompt": "I found a viral skill repo on Twitter. Before I install it, audit the public repo and flag anything unsafe.",
"default_prompts": [
"I found a viral skill repo on Twitter. Before I install it, audit the public repo and flag anything unsafe.",
"Audit this plugin's scripts, permissions, and external calls. Rank risks with file-and-line evidence.",
"Give me a go-or-no-go. List what blocks installation, what must be fixed, and what I still need to review."
],
"developer_name": "Orbral",
"logo_url": "https://files.openai.com/content?id=file_00000000a6f881fd97b3ad90ed6bc318",
"logo_url_dark": "https://files.openai.com/content?id=file_000000003ad481f59e22464ae71246d3",
"long_description": "Use this before installing an agent skill or plugin. Skill Risk Check scans local files for hidden instructions, broad permissions, suspicious downloads, prompt-injection patterns, and possible secret exposure, then returns ranked findings with file-and-line evidence and remediation. Do not use it as a safety certification; it never runs, installs, enables, or uploads the target.",
"plugin_category_id": "security",
"privacy_policy_url": "https://github.com/SpannDaMan/agent-skillguard/blob/main/PRIVACY.md",
"screenshot_urls": [],
"short_description": "Scan before you install.",
"terms_of_service_url": "https://github.com/SpannDaMan/agent-skillguard/blob/main/TERMS.md",
"website_url": "https://github.com/SpannDaMan/agent-skillguard"
},
"keywords": [
"plugin-security",
"agent-skills",
"pre-install-scan",
"prompt-injection",
"supply-chain",
"sarif",
"codex",
"claude-code"
],
"onboarding_skill_name": null,
"requires_local_executor": false,
"skills": [
{
"description": "Use before installing an agent skill or plugin. Scan local files for risky instructions, broad permissions, suspicious downloads, prompt-injection patterns, and possible secret exposure; return file-and-line findings and remediation without running, uploading, or certifying the target.",
"interface": {
"brand_color": null,
"default_prompt": null,
"display_name": "agent-skillguard",
"icon_large_url": null,
"icon_small_url": null,
"iconography": "radar",
"short_description": "Use before installing an agent skill or plugin. Scan local files for risky instructions, broad permissions, suspicious downloads, prompt-injection patterns, and possible secret exposure; return file-and-line findings and remediation without running, uploading, or certifying the target."
},
"name": "agent-skillguard",
"plugin_release_skill_id": "pluginrsk_6a8d0cf46e74819183dc3317b152a807"
}
],
"version": "0.1.5"
},
"scope": "GLOBAL",
"status": "ENABLED"
}SHA-256 of public snapshot: 42ecbb26566cbbfe456de1335ed261cb6be3da2c4006e86ec7055d1eb9d89579