inkog_skill_scan
Scan SKILL.md packages and agent tool definitions for security vulnerabilities including tool poisoning, command injection, data exfiltration, and prompt injection. Maps findings to OWASP Agentic and MCP Top 10.
Instructions
Scan SKILL.md packages and agent tool definitions for security vulnerabilities. Detects tool poisoning, command injection, data exfiltration, prompt injection, excessive permissions, obfuscation, supply chain risks, and more. Maps findings to OWASP Agentic Top 10 and OWASP MCP Top 10. Set deep=true for AI-powered deep analysis (~10 min, catches novel threats). For MCP server scanning, use inkog_mcp_scan instead.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| repository_url | No | GitHub repository URL of the skill package | |
| path | No | Local path to skill package directory | |
| deep | No | Enable AI deep analysis |