skill_scanner

Scans skills and tool descriptors for suspicious patterns before runtime use.


What it mitigates


ProfileactionOnCriticalstartup scanreload scan
localdenytruetrue
standardchallengetruetrue
unboundedalerttruetrue

Minimal config

moduleConfig:
  skill_scanner:
    scanOnStartup: true
    scanOnReload: true
    actionOnCritical: challenge
    requireSignature: false
    requireSbom: false
    requirePinnedSource: false
    onProvenanceFailure: challenge

Notes