Skip to main content
Glama

scan_skill

Security scanner for AI agent skills. Fetches the skill's script, runs static analysis checking 30+ dangerous patterns: sensitive file reads (.env, .ssh, $HOME), remote code execution (curl|bash, base64 decode + exec), obfuscation signals, reverse shells, credential leaks, affiliate link abuse. Uses pattern matching for fast results and optional DeepSeek AI for deeper review. Returns safety score 0-100, flagged violations, and recommendations.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
deepNoRun DeepSeek AI analysis on the script content for deeper inspection. Default: true.
slugYesClawHub skill slug to scan. Example: "shell", "task-planner". Required.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Added

TDQS

A4.1/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries full responsibility for disclosing behavior. It does so effectively by explaining the workflow: fetches the script, runs static analysis on 30+ patterns, uses pattern matching with optional DeepSeek AI, and returns a score, violations, and recommendations. It does not mention potential failures or limitations, but the core behavior is well covered.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single paragraph that is information-dense yet concise. It front-loads the core purpose and provides concrete examples of threat patterns. While it is slightly long, every sentence adds value, making it well-structured for an agent to parse key details quickly.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool's moderate complexity and lack of an output schema, the description adequately covers inputs, process, and outputs (safety score, violations, recommendations). It does not address edge cases like nonexistent skills or error handling, but the essential information for an agent to invoke the tool correctly is present.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema already provides thorough descriptions for both parameters (slug and deep), achieving 100% schema description coverage. The description reinforces the overall purpose but does not add additional parameter-level semantics beyond what the schema offers, so the baseline score of 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool is a 'Security scanner for AI agent skills' and details its specific actions: fetching the skill's script and running static analysis for dangerous patterns. It distinguishes itself from sibling tools like evaluate_skill or score_skills by focusing on security vulnerabilities and providing a safety score, making its purpose unambiguous.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description establishes clear context for when to use the tool: whenever a security assessment of an AI agent skill is needed. It does not explicitly mention exclusions or alternatives, but the detailed focus on threat patterns and the output format imply the intended use case strongly enough that an agent can select it appropriately.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources