plugin-scanner
69Scan AI Plugins Before Installation
Unreviewed agent extensions can contain prompt injection, unsafe commands, secret exposure, or supply-chain risks. This skill guides local scanning and clear interpretation before trust.
Protect AI Harnesses with HOL Guard
Local AI harnesses can expose risky tools, plugins, and configuration changes. HOL Guard guides controlled setup, approval review, evidence collection, and package verification.
Copia esta solicitud en tu Agente. Incluye la página canónica del Skill y el manifiesto.
Review the Skillstore skill "hol-guard" from https://skillstore.io/skills/hashgraph-online-hol-guard.md and its manifest at https://skillstore.io/api/skills/hashgraph-online-hol-guard/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.Tu Agente debe seguir mostrando su plan y solicitar cualquier confirmación exigida por la política de seguridad.
Usa estos enlaces cuando un agente de IA, crawler o script necesite contexto limpio en vez de leer la página completa.
Usando "hol-guard". Check whether this Codex workspace is protected.
Resultado esperado:
HOL Guard detected the Codex workspace. Protection is not confirmed because the status check did not prove an active Guard installation.
Usando "hol-guard". Review the pending Guard approval before I decide.
Resultado esperado:
The request remains pending. The review identifies its requested scope, risk reason, related configuration difference, and available receipt evidence.
Usando "hol-guard". Verify this skill package for release.
Resultado esperado:
Package verification completed with one unresolved scanner failure. Release readiness is not confirmed until that failure is inspected and resolved.
Most static matches are false positives caused by Markdown backticks, command fences, and a rule prohibiting .env access. Confirmed findings involve package installation, harness configuration, approval actions, and optional cloud synchronization; these are legitimate features with operational security risk.
Estas son capacidades locales reales que pueden esperarse para esta habilidad, por lo que requieren revisión, pero no se cuentan como comportamiento malicioso confirmado.
Comparte el informe de evaluación versionado, la insignia neutral, la tarjeta insertable y las citas. Skillstore presenta evidencias sin decidir si este Skill es seguro.
https://skillstore.io/skills/hashgraph-online-hol-guard/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report[](https://skillstore.io/skills/hashgraph-online-hol-guard?utm_source=security_passport_badge)<a href="https://skillstore.io/skills/hashgraph-online-hol-guard?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/hashgraph-online-hol-guard/security.svg" alt="Skillstore security assessment" loading="lazy"></a><iframe src="https://skillstore.io/embed/skills/hashgraph-online-hol-guard.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>hashgraph-online. (2026). hol-guard security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/hashgraph-online-hol-guard/audits/1@techreport{hashgraph-online-hashgraph-online-hol-guard-2026,
author = {hashgraph-online},
title = {hol-guard security audit report (audit version 1)},
institution = {Skillstore},
year = {2026},
number = {1},
url = {https://skillstore.io/skills/hashgraph-online-hol-guard/audits/1},
note = {Author version unspecified}
}cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "hol-guard security audit report (audit version 1)"
version: "unspecified"
type: report
authors:
- name: "hashgraph-online"
date-released: "2026-08-27"
url: "https://skillstore.io/skills/hashgraph-online-hol-guard/audits/1"
identifiers:
- type: other
value: "skillstore:hashgraph-online-hol-guard:audit:1"
description: "Skillstore immutable audit report identifier"
Install Guard integration, run a dry check, and verify protection for Codex, Claude Code, or another supported harness.
Inspect queued approvals, risk reasons, receipts, and configuration differences before deciding whether work may continue.
Lint and verify plugins, skills, MCP servers, or marketplace packages before publishing a release.
Check whether HOL Guard and plugin-scanner are installed. Report availability and recommend isolated installation steps without changing my environment.
Protect my [harness] workspace with HOL Guard. Run a dry check first, explain planned changes, and verify final status with command evidence.
Inspect Guard request [request-id]. Explain its risk reason and scope, show relevant evidence, and wait for my decision before approving or denying.
Audit this mixed agent workspace. Verify packages, inspect Guard status and evidence, then identify unresolved release risks without claiming readiness prematurely.
Autor
hashgraph-onlineLicencia
Apache-2.0
Revisión de Skillstore
r1
Aviso de versión
El autor no declaró una versión.
Ref.
40175672d649fa6482bff53a7acf4ecdd6a04a96
Actualidad del mantenimiento
27/8/2026
Uso
1 descargas · 0 vistas
Estructura de archivos
📄 SKILL.md
Audit Software Releases with Evidence
por glenskii
Release decisions often rely on incomplete evidence and inconsistent standards. This skill applies structured controls, deterministic scoring, and mandatory gates to assess readiness.
Audit Python Web Apps Before Release
por glenskii
Python teams need repeatable checks for common application security controls. This skill provides configurable pytest coverage with clear evidence, boundaries, and release decisions.
Implementar gobernanza de seguridad ISO 27001
por davila7
Los equipos de salud digital y MedTech necesitan programas estructurados de seguridad ISO 27001 que conecten riesgos, controles, incidentes y auditorías. Esta skill guía la planificación del ISMS, la evaluación de riesgos, la selección de controles y la preparación para la certificación usando ISO 27001 e ISO 27002.
Gestionar archivos de riesgo de dispositivos médicos
por alirezarezvani
Los equipos de dispositivos médicos necesitan evidencia coherente de gestión de riesgos en el trabajo de diseño, regulatorio y poscomercialización. Esta habilidad guía la planificación, el análisis, los controles y el mantenimiento de archivos conforme a ISO 14971.
Auditar controles del SGSI ISO 27001
por alirezarezvani
Las auditorías del SGSI requieren un alcance claro, evidencias y prioridades basadas en el riesgo. Esta skill guía la planificación de auditorías ISO 27001, las pruebas de controles y el trabajo de preparación.
Crear flujos de autenticación de CloudBase en Node
por tencentcloudbase
El trabajo de autenticación de CloudBase en el servidor puede combinar la identidad del llamador, la búsqueda de usuarios y detalles de inicio de sesión personalizado. Esta skill guía a agentes de Node.js mediante métodos correctos del SDK y patrones seguros de backend.