Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them.
65
82%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
Low
Low-risk findings worth noting
Use HOL's local plugin-scanner when a user asks to inspect an AI agent skill, plugin, MCP server, agent package, or repository before installation or use.
The scanner is shipped by the open-source plugin-scanner Python distribution. It is built from the same HOL Guard source repository, but it is intentionally packaged separately from the hol-guard runtime CLI. Scanning runs locally and does not require Guard Cloud.
Use this skill when the user asks to:
SKILL.md before installing it;.env files, credential stores, private keys, or unrelated user secrets.references/trusted-scanner.toml by absolute path and do not use a target-owned baseline.plugin-scanner if the command is not already available.command -v plugin-scannerIf it is not installed, explain that plugin-scanner is a separate open-source CLI distribution from the HOL Guard repository and, with user approval, install it in an isolated CLI environment:
pipx install plugin-scannerDo not assume an existing hol-guard installation also provides the plugin-scanner command. If pipx is unavailable, point the user to the plugin-scanner installation instructions rather than silently changing their Python environment.
Resolve references/trusted-scanner.toml relative to this SKILL.md and use its absolute path as TRUSTED_SCANNER_CONFIG. This prevents a target-owned .plugin-scanner.toml, .codex-plugin-scanner.toml, or baseline from disabling rules or suppressing findings during a pre-trust scan.
For a repository or directory:
plugin-scanner scan PATH --config "$TRUSTED_SCANNER_CONFIG" --profile strict-security --format markdownFor machine-readable results:
plugin-scanner scan PATH --config "$TRUSTED_SCANNER_CONFIG" --profile strict-security --format jsonFor Agent Skill / plugin structure validation:
plugin-scanner lint PATH --config "$TRUSTED_SCANNER_CONFIG" --profile strict-security
plugin-scanner verify PATHUse the narrowest target path that contains the material the user asked to inspect.
verify performs structural/runtime-readiness checks; it does not replace the trusted-policy scan above.
Summarize:
Do not claim "safe" solely because no finding was returned. Say that no covered issue was detected by the current scan.
7352597
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.