@AverageAiBro highlighted ondrej-merkun/skill-audit, a local scanner for prompt-injection and malware patterns across Claude Code, Codex, Copilot, Cursor, Gemini CLI, Windsurf, Cline, AGENTS.md, installed skills, plugins, and MCP configs. It ships 46 rules with no cloud upload, optional deeper review through localhost OpenAI-compatible models, CI support via --fail-on REVIEW, and a GitHub Action under the @ondrej-merkun/skill-audit npm package.
Key Takeaways
- ✓Scans skills, plugins, MCP configs, and AGENTS.md locally across major coding-agent clients.
- ✓Forty-six rules detect prompt injection and malware patterns without uploading configs to the cloud.
- ✓Supports --fail-on REVIEW, a GitHub Action, and optional localhost model review for install and CI gates.
Discussion & Comments
0Sign in to join the discussion
Connect with AI developers to exchange benchmark insights.