nowfound

Alternatives

Products that do what SkillRisk does

Security scanner for Claude Code & MCP skills.

  1. 1
    Skillkit252

    The package manager for AI agent skills

    Feb 2026 · agenstskills.com

  2. 2

    Audit your AI agent skills to avoid malware

    Apr 2026 · labs.snyk.io

  3. 3

    The AI-Powered Antivirus for AI Agents

    Mar 2026 · clawsecure.ai

  4. 4

    Detect Security Threats in Agent Skills

    Jan 2026

  5. 5

    The AI-Powered Antivirus for AI Agents

    May 2026 · clawsecure.ai

  6. 6MS

    I noticed the growing security concerns around MCP (https://news.ycombinator.com/item?id=43600192) and built an open source tool that can detect several patterns of tool poisoning attacks, exfiltration channels and cross-origin manipulations. MCP-Shield scans your installed servers (Cursor, Claude Desktop, etc.) and shows what each tool is trying to do at the instruction level, beyond just the API surface. It catches hidden instructions that try to read sensitive files, shadow other tools' behavior, or exfiltrate data. Example of what it detects: - Hidden instructions…

    2025 · github.com

  7. 7

    Security-scored directory for AI skills and agent tools

    Feb 2026 · skillshield.io

  8. 8
    0xAudit110

    The security layer for AI agents to scan, fix verify via MCP

    Feb 2026 · 0-x-audit.com

  9. 9FL

    Hi HN! We just launched Codacy Guardrails, an IDE extension with a CLI for code analysis and MCP server that enforces security & quality rules on AI-generated code in real-time. It hooks into AI coding assistants (like VS Code Agent Mode, Cursor, Windsurf), silently scanning and fixing AI-suggested code that has vulnerabilities or violates your coding standards, while the code it’s being generated. We built this because coding agents can be a double-edged sword. They do boost productivity, but can easily introduce insecure or non-compliant code. One recent research team at NYU found that 40%…

    2025

  10. 10

    Scans AI agent skills for malicious code

    11d ago · github.com

  11. 11

    AI Skill & MCP server management for teams & enterprises

    Jul 2026 · localskills.sh

  12. 12

    Scan untrusted AI-agent repos before your agent runs them

    Jul 2026 · github.com

  13. 13SA

    Hi HN — I'm Scott. Skillscript is a small language I built to write what I want my local agent to actually do, in a form I can read and version, instead of hoping the model gets it right each time. The itch started with something small. I wanted my NanoClaw agent to run my morning brief the same way every day. Check overnight tickets, summarize the deploy pipeline, flag anything urgent. Every session, it would re-figure out how to do this from scratch, drift a little, and cost tokens for what's basically a fixed procedure. I could put it in a system prompt or an MD skill file, but those are…

    Jul 2026 · github.com

  14. 14

    Open-source malware scanner and runtime guard for AI agents

    Jul 2026 · panguard.ai

  15. 15

    Contribute to alpbahadur/interns-review-plugin development by creating an account on GitHub.

    1d ago · github.com

  16. 16WB

    Hey HN, We’re two developers (co-founders) with a team of 20 who got tired of spending hours reviewing PRs, so we built Infinitcode.ai, an AI-powered code reviewer that: - *Summarizes PRs in plain English*: No more deciphering 1,000-line diff jungles - *Catches more than bugs*: Security holes, performance pitfalls, code smells, even typos (yes, we’ll flag “vurnerabilities” and vulnerabilities) - *Zero onboarding*: Works instantly—no “let me learn your codebase for weeks” nonsense. Why we’re posting: We’re in alpha and need brutal honesty. Roast our tool, mock our UI, or tell us why AI will…

    2025 · infinitcode.ai

  17. 17

    Ranked directory of Claude Code, Codex, Grok, Cursor skills

    26d ago · skillselion.com

  18. 18IM

    At my work they provided a single Claude subscription for everyone on the team. To be honest I like kiro better as it provides a way better SDD management. But the company can't provide it and I can't afford it yet. Turns out I had the skill creator skill in my claude instance so I made use of it to create this Skill. I made it fully by using Claude but I wanted to make it open source, so I asked it to help me make tests and preparations for it, even a CI to run python tests. Well, we got this results with it: - Phase 2A: 67 static assertions (Python script, runs in CI) - Phase 2B: 15…

    May 2026 · github.com

  19. 19MS

    Hi HN! We kept seeing devs get pwned through MCP tools in ways that security scanners completely miss. So we built an open-source analyzer to catch these attacks. Our first OSS by Mighty team. The problem: At Defcon, we saw MCP exploits with 100% success rate against Claude and Llama. Three attack patterns: Hidden Unicode in "error messages" - Paste a colleague's error into Claude, your SSH keys get exfiltrated Trusted tool updates - That database tool you've used for months? Last week's update added credential theft Tool redefinition - Malicious tool redefines "deploy to prod" to run…

    2025 · github.com

  20. 20

    Scan skills before install. Ship safer AI workflows.

    Feb 2026 · npmjs.com

  21. 21

    Stop AI skills from silently breaking across platforms

    Apr 2026 · github.com

  22. 22

    Scans agent skill and rule files for poisoned instructions.

    Jun 2026 · github.com

  23. 23

    Give your AI agent expert skills before it builds

    May 2026 · npmjs.com

  24. 24

    Security audit for AI skill files in GitHub

    Feb 2026 · skillaudit.sh

Ranked by how close each launch is in meaning, then by votes. Refine with a description →