A guide for authorized security testing of AI products, agents, connectors, skills, plugins, code repositories, and related infrastructure. It uses harmless checks and collected evidence to identify and describe security risks.
Scan any agent skill for security risks before you install or use it. Powered by Tencent Zhuque Lab A.I.G (AI-Infra-Guard). 100% local static analysis — no file contents or credentials leave your device. Compatible with CodeBuddy, Cursor, Windsurf, Claude Code, OpenClaw and more. Triggers on: 这个 skill 安全吗, skill 安全扫描…
A market-scanning skill for China's A-share stock market, covering checks before trading, during trading, and after trading. It produces a market snapshot, unusual-movement checks, and a description of overall market mood.
Scans a Python AI project for EU AI Act compliance gaps using AIR Blackbox. Use when the user asks to check compliance, scan their code, audit their AI project, or mentions EU AI Act, Articles 9-15, or compliance checking.
Security scanner for AI Agent skills, plugins, and MCP servers. Use when: user asks to scan a skill, check if a plugin is safe, vet an MCP server, review skill security, detect malicious code, supply chain safety, or says 'is this safe to install', 'scan this skill', 'check this MCP server', 'security scan'…
Control scanners via scan-mcp MCP server to capture documents, photos, receipts, and pages. Use when user mentions scanning, scanners, or document types. CRITICAL: call startscanjob with {} (no params) unless user specifies requirements—server handles intelligent device selection and defaults. Override only for…
Configure scan-mcp MCP server in Claude Code's global configuration. Use when user wants to setup, configure, initialize, enable, or install the scan-mcp MCP server. Runs preflight checks for prerequisites (Node 22+, SANE tools, tiffcp), helps install missing dependencies, and adds server configuration with…
Automatically scan any npm package for supply-chain security risks BEFORE the user installs it. Trigger this skill whenever the user asks to install, add, or upgrade an npm package or dependency (e.g. "npm install X", "install X", "add X as a dependency", "yarn add X", "pnpm add X", "upgrade X"), or wants to…
An AI and MCP security scanner aligned with the OWASP MCP Top 10, a list of common risks for tool-connected AI systems. It checks for issues such as prompt injection, command injection, poisoned tools, leaked secrets, unsafe permissions, supply-chain attacks, SSRF, and banned Chinese-language content.