epistemedeus/skillguard
by Various
Scan a Claude Code skill, plugin, or MCP server for malware before you install it. Static-only: never runs the scanned code.
MCP
epistemedeus/skillguard
Added 13 Sept 2026
Overview
Scans a Claude Code skill, plugin, or MCP server for malware before installation. Performs static analysis only and never executes the scanned code. Built in JavaScript.
Best for
Best for
Claude Code users who want a quick static check before installing community skills or plugins.
Use cases
- Reviewing a third-party Claude Code skill before adding it to a project
- Checking a plugin or MCP server for suspicious code patterns
- Auditing files from an untrusted repository without running them
How to use
Install
npx github:epistemedeus/skillguard https://github.com/owner/repo Tools exposed
env-exfilexfil-hostprompt-injectionsecret-literalcommitted-binaryforced-artifactdangerous-permsinstall-hook
Tested with
Claude Code
Notes
Scans a Claude Code skill, plugin, or MCP server for malware before installation. Performs static analysis only and never executes the scanned code. Built in JavaScript.
0 stars on GitHub. Last updated 2026-06-24.
Use cases
- Reviewing a third-party Claude Code skill before adding it to a project
- Checking a plugin or MCP server for suspicious code patterns
- Auditing files from an untrusted repository without running them
Pros
- Static-only scanning reduces risk of accidental execution
- Focused on Claude Code ecosystem artifacts
- Simple to run before installation
Cons
- No dynamic analysis, so runtime behavior is not observed
- Zero stars and no usage history to gauge reliability
- May miss obfuscated or multi-stage threats
Indexed from awesome-mcp-servers-punkpeye and enriched against its public facts.
Pros
- Static-only scanning reduces risk of accidental execution
- Focused on Claude Code ecosystem artifacts
- Simple to run before installation
Cons
- No dynamic analysis, so runtime behavior is not observed
- Zero stars and no usage history to gauge reliability
- May miss obfuscated or multi-stage threats
Pairs with
Other entries in the index that connect to this one. Click through to see the chain.
Get the free Developer’s Field Guide
A 27-page field guide to the AI coding workflow with Claude. Claude Code, MCP servers, the prompt patterns that work, and what to delegate. Free.
Enter your work email. We send it straight over, plus a few short notes worth knowing. Unsubscribe any time.
