跳到主要内容
知仓学习社ZHICANG

plugin-scanner

Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before …

不碰外部(只输出文字)无严重或高危命中hashgraph-online/awesome-codex-plugins

它会碰到什么

扫了多少1 个文本文件,3 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Plugin Scanner

Use HOL's local plugin-scanner when a user asks to inspect an AI agent skill, plugin, MCP server, agent package, or repository before installation or use.

The scanner is shipped by the open-source plugin-scanner Python distribution. It is built from the same HOL Guard source repository, but it is intentionally packaged separately from the hol-guard runtime CLI. Scanning runs locally and does not require Guard Cloud.

When to use this skill

Use this skill when the user asks to:

  • scan or audit a SKILL.md before installing it;
  • inspect an MCP server or agent plugin for security risks;
  • check a third-party agent repository before trusting it;
  • look for prompt injection, credential exposure, unsafe commands, or suspicious package/install behavior;
  • validate a skill/plugin repository in CI or before publishing it.

Safety rules

  • Never execute code from the target repository just to scan it.
  • Never run its install scripts, package lifecycle hooks, or arbitrary shell commands.
  • Never read .env files, credential stores, private keys, or unrelated user secrets.
  • Prefer scanning a local path or a repository the user has already chosen to inspect.
  • Treat scanner findings as security evidence, not a guarantee that a package is safe.
  • Ask before installing plugin-scanner if the command is not already available.

Workflow

1. Check for the scanner

command -v plugin-scanner

If it is not installed, explain that plugin-scanner is a separate open-source CLI distribution from the HOL Guard repository and, with user approval, install it in an isolated CLI environment:

pipx install plugin-scanner

Do not assume an existing hol-guard installation also provides the plugin-scanner command. If pipx is unavailable, point the user to the plugin-scanner installation instructions rather than silently changing their Python environment.

2. Scan the target without executing it

For a repository or directory:

plugin-scanner scan PATH --format markdown

For machine-readable results:

plugin-scanner scan PATH --format json

For Agent Skill / plugin structure validation:

plugin-scanner lint PATH
plugin-scanner verify PATH

Use the narrowest target path that contains the material the user asked to inspect.

3. Interpret findings

Summarize:

  1. the target that was scanned;
  2. the highest severity finding;
  3. concrete files/rules involved;
  4. whether the scanner found prompt-injection, secret/exfiltration, command-execution, dependency/install, or MCP-specific risks;
  5. the recommended next action.

Do not claim "safe" solely because no finding was returned. Say that no covered issue was detected by the current scan.

Common prompts

  • "Scan this skill before I install it."
  • "Check this MCP server for prompt injection or suspicious commands."
  • "Audit this agent plugin repository."
  • "Verify this SKILL.md and tell me what is risky."
  • "Run a security check on this AI tool before we add it to our project."

Source

  • Plugin Scanner source: https://github.com/hashgraph-online/hol-guard
  • Plugin Scanner package: https://pypi.org/project/plugin-scanner/
  • Distribution companion: https://github.com/hashgraph-online/hol-guard-plugin

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

它属于哪个仓库

星标★ 1,027
本站分层T1
该仓技能数1910
原文件路径plugins/hashgraph-online/hol-guard-plugin/skills/plugin-scanner/SKILL.md

同一个仓库里的其他技能

看这个仓库的全部 1910 个技能