hol-guard
72Protect AI Harnesses with HOL Guard
Local AI harnesses can expose risky tools, plugins, and configuration changes. HOL Guard guides controlled setup, approval review, evidence collection, and package verification.
Scan AI Plugins Before Installation
Unreviewed agent extensions can contain prompt injection, unsafe commands, secret exposure, or supply-chain risks. This skill guides local scanning and clear interpretation before trust.
Copia esta solicitud en tu Agente. Incluye la página canónica del Skill y el manifiesto.
Review the Skillstore skill "plugin-scanner" from https://skillstore.io/skills/hashgraph-online-plugin-scanner.md and its manifest at https://skillstore.io/api/skills/hashgraph-online-plugin-scanner/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.Tu Agente debe seguir mostrando su plan y solicitar cualquier confirmación exigida por la política de seguridad.
Usa estos enlaces cuando un agente de IA, crawler o script necesite contexto limpio en vez de leer la página completa.
Usando "plugin-scanner". Scan the skill at ./skills/calendar-helper before installation.
Resultado esperado:
The scan found one high-severity prompt-injection rule in SKILL.md. Review the cited instruction and remove the override language before installation.
Usando "plugin-scanner". Verify the MCP server in ./integrations/search-server.
Resultado esperado:
Usando "plugin-scanner". Check ./plugins/reporter and tell me whether it is safe.
Resultado esperado:
No covered issue was detected by the current scan. This result is limited to supported rules and does not guarantee safety.
All 21 static findings are false positives caused by Markdown formatting, safety prohibitions, or documentation links. The workflow does present one real supply-chain risk because it proposes installing an unpinned package from PyPI. No prompt injection or secret-access intent was found.
Comparte el informe de evaluación versionado, la insignia neutral, la tarjeta insertable y las citas. Skillstore presenta evidencias sin decidir si este Skill es seguro.
https://skillstore.io/skills/hashgraph-online-plugin-scanner/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report[](https://skillstore.io/skills/hashgraph-online-plugin-scanner?utm_source=security_passport_badge)<a href="https://skillstore.io/skills/hashgraph-online-plugin-scanner?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/hashgraph-online-plugin-scanner/security.svg" alt="Skillstore security assessment" loading="lazy"></a><iframe src="https://skillstore.io/embed/skills/hashgraph-online-plugin-scanner.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>hashgraph-online. (2026). plugin-scanner security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/hashgraph-online-plugin-scanner/audits/1@techreport{hashgraph-online-hashgraph-online-plugin-scanner-2026,
author = {hashgraph-online},
title = {plugin-scanner security audit report (audit version 1)},
institution = {Skillstore},
year = {2026},
number = {1},
url = {https://skillstore.io/skills/hashgraph-online-plugin-scanner/audits/1},
note = {Author version unspecified}
}cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "plugin-scanner security audit report (audit version 1)"
version: "unspecified"
type: report
authors:
- name: "hashgraph-online"
date-released: "2026-08-27"
url: "https://skillstore.io/skills/hashgraph-online-plugin-scanner/audits/1"
identifiers:
- type: other
value: "skillstore:hashgraph-online-plugin-scanner:audit:1"
description: "Skillstore immutable audit report identifier"
Scan a local skill directory and summarize security findings before adding it to an agent environment.
Inspect an MCP server repository for prompt injection, command execution, credential exposure, and suspicious installation behavior.
Run scan, lint, and verification checks before publishing an agent plugin or skill.
Scan [PATH] as an agent skill and summarize the highest severity finding, affected files, and recommended action.
Audit the MCP server at [PATH] for prompt injection, secret exposure, unsafe commands, and suspicious installation behavior.
Scan, lint, and verify [PATH], then report structural failures, security findings, and publication blockers.
Analyze the machine-readable scan of [PATH], group evidence by risk category, and prioritize remediation without claiming the target is safe.
Autor
hashgraph-onlineLicencia
Apache-2.0
Revisión de Skillstore
r1
Aviso de versión
El autor no declaró una versión.
Ref.
40175672d649fa6482bff53a7acf4ecdd6a04a96
Actualidad del mantenimiento
27/8/2026
Uso
1 descargas · 0 vistas
Estructura de archivos
📄 SKILL.md
Audit AI Agent Skills Before Installation
por superagent-ai
Unvetted agent skills can hide prompt injection, credential theft, persistence, or unsafe dependencies. This skill combines offline scanning with guided semantic review.
Revisar el riesgo de vulnerabilidades con la guía de OWASP
por sickn33
Las revisiones de seguridad suelen perder contexto cuando los hallazgos se enumeran sin rutas de ataque ni riesgo empresarial. Esta habilidad combina la guía de OWASP, comprobaciones locales y prompts de priorización para un trabajo de seguridad accionable.
Audit GitHub Actions Workflows
por superagent-ai
GitHub Actions workflows can expose credentials, repositories, and releases through subtle configuration errors. This skill applies a structured security review and proposes concrete fixes.
Auditar la seguridad de dependencias y generar SBOM
por Doyajin174
Las actualizaciones de dependencias pueden introducir paquetes vulnerables o no confiables. Esta habilidad guía auditorías, actualizaciones más seguras, la creación de SBOM y comprobaciones de CI.
Auditar riesgos de seguridad con listas de verificación estructuradas
por ClementWalter
Las revisiones de seguridad pueden pasar por alto controles importantes cuando los equipos dependen de preguntas ad hoc. Esta habilidad guía a Claude, Codex y Claude Code mediante auditorías estructuradas en dominios de aplicaciones, infraestructura, cadena de suministro, criptografía, contratos inteligentes y ZK.
Auditar la seguridad de dependencias
por CuriousLearner
Las vulnerabilidades en dependencias crean riesgos de lanzamiento y exposición en la cadena de suministro. Esta skill ayuda a Claude, Codex y Claude Code a revisar paquetes y planificar correcciones.