
Skill ScannerAçık kaynaklı güvenlik tarama aracı, AI ajan yeteneklerini prompt injection ve kötü niyetli patternler için denetler.
Genel Bakış
Temel özellikler
- Prompt injection pattern algılama
- Veri kaçakları heuristikleri
- Kötü niyetli kod desenleri taraması
- SARIF rapor çıktı
- CI/CD pipeline entegrasyonu
- Erişilebilir kural seti
Fiyatlar
- Model
- Freemium
- Kategori
- Software Testing (QA) Agents
- Puan
- 4.7 / 5 (6)
Kullanım senaryoları
Depolama öncesi üçüncü taraf ajan yeteneklerini doğrulayın
Ajanın dış yeteneklerini ve eklentilerini taramanın, prompt injection patternleri ve şüphe uyandıran kodları azaltarak kompromite edilen entegrasyon riskini azaltmak için dışa aktarın.
CI/CD güvenlik kapılarını uygulayın
SARIF çıktı kullanarak Skill Tarama'yı build akımları ile entegre edin, böylece tehlikeli yetenek manifesto ve talimatlarını içeren çekme isteklerini otomatik olarak engellen.
GitHub kod taramasında bulguları yüzeyin
SARIF raporlarını GitHub kod taramasına veya güvenlik panolarına akıtın, böylece geliştiriciler ve güvenlik ekibi, diğer kod sorunlarıyla birlikte ajan yeteneklerinin güvenlik açıklarını triaj yapabilsin.
Özel kurallarla içsel yetenekler-harden
Kurallarının genişletme rule setı kurumsal tehdit modellerini eşleşecek şekilde, içsel olarak yapılan ajan yeteneklerinin, veri kaçakları ve kötü niyetli desenler için temel kontrol noktalarını karşıladığını güvence altına alın.
Artılar ve eksiler
Artılar
- Ücretsiz ve açık kaynaklı
- Ajan spesifik tehditleri olan prompt injection gibi hedefler
- SARIF çıktı mevcutta güvenlik araçları ile entegre
- CI/CD güvenlik kapıları için faydalı
- Algılama kurallarını özelleştirilebilir
Eksiler
- Teknik kurulum ve komut Satırı familiarity gerektirir
- Statik analiz tüm çalışma zamanlı saldırıları yakalayamaz
- Kapsamı topluluk tarafından yönetilen kurallara bağlıdır
İncelemeler
6 puandan ortalama.
İnceleme bırakmak için giriş yap.
Does the job
Pretty happy overall. Extensible rule set just works and sARIF output integrates with existing security tools. Static analysis cannot catch all runtime attacks can be annoying, but no dealbreakers — I'd recommend it to a friend without hesitating.
Use it every day
Honestly didn't expect to like it this much. SARIF report output is exactly what I needed, and free and open source. I do wish static analysis cannot catch all runtime attacks, but I reach for it almost every day now and it just clicks.
Use it every day
Honestly didn't expect to like it this much. SARIF report output is exactly what I needed, and useful for CI/CD security gates. but I reach for it almost every day now and it just clicks.
Years in this space
I've evaluated a lot of these over the years. What stands out here is sARIF report output — handled better than most — and free and open source. Worth the time if this is your use case.
Use it every day
Honestly didn't expect to like it this much. SARIF report output is exactly what I needed, and targets agent-specific threats like prompt injection. I do wish coverage depends on community-maintained rules, but I reach for it almost every day now and it just clicks.
Solid for our team
We rolled this out across the team last quarter and useful for CI/CD security gates. Data exfiltration heuristics fits neatly into how we already work, and sARIF report output removed a step we used to do by hand. Requires technical setup and CLI familiarity, which is the main caveat, but it has held up under daily use.
Sorular
How much does Skill Scanner cost and what's the licensing model?
Skill Scanner is free and open source, so there are no licensing fees. You can self-host and run it as part of your own workflows, with the trade-off that you handle setup, maintenance, and any rule customization yourself.
What threats can it detect, and what are its limitations?
It performs static analysis on skill manifests, instructions, and bundled code to flag prompt injection patterns, data exfiltration heuristics, and suspicious code. As a static tool, it can't catch all runtime attacks, and detection quality depends on the community-maintained or custom rule set.
How does Skill Scanner integrate with CI/CD and existing security tooling?
It outputs findings in SARIF, the standard format consumed by tools like GitHub code scanning, security dashboards, and code review workflows. This makes it straightforward to wire into CI/CD pipelines as a security gate alongside other static analysis tools.
Soru sor
Software Testing (QA) Agents alternatifleri
CarbonCopies AI
Software Testing (QA) Agents
Kullanıcı etkileşimlerini taklit eden AI ikizleri, otomatik UX/fonksiyonel test geçirmek ve uygulamalar/website'lerde hataları tespit etmek için kullanılır.
Diffblue Cover
Software Testing (QA) Agents
Otonom bir AI ajanı, doğrulanmış kesinlikle doğrulukta Java birim testleri ve ölçeklenebilirlikle oluşturur ve sürdürür.
PentAGI
Software Testing (QA) Agents
Acılabilir, özerk penetrasyon testi aracıları, 20'dan fazla güvenlik aracıyı izole bir Docker kümesinde bellek ve web zekası ile çalıştırmak.
Flowtest AI
Software Testing (QA) Agents
İnsansı bir AI agenti siteslerinizi simüle ettiğiniz gerçek kullanıcılardan alınmasını sağlamak ve sorunları teşhis etmek için kullanabilirsiniz.
Keploy
Software Testing (QA) Agents
Ön-mühendislikli bir AI ajansta, otomatik olarak mock oluşturur ve birimi, entegrasyon ve API testlerini günceller.
Trending now
Reducto AI
AI Agent Development Platforms
Belge zeka API, karmaşık PDF'ler, sunumlar ve tabloları okur ve yapılandırılmış verileri ayırarak, ayrıştırır, ayırır, OCR yapar ve çıkartır.
Midjourney
Image Generation
Metin temelli muhteşem görüntü oluşturun
Pin AI
Workflow automation
Hiringi iş süreçlerin hızlandırılmasını sağlayarak süregelen işe alım için yetkin AI yardımcı.
Doozer Ai
Sales Agent
Dijital iş arkadaşlarınız ile operasyonel akıllı iş akışları otomatikleştirerek ekip verimliliğini artırın.








