-
Notifications
You must be signed in to change notification settings - Fork 26
[Scanner]: skills-inspector — offline static analyzer for agent extensions #53
Copy link
Copy link
Closed as not planned
Closed as not planned
Copy link
Labels
P3Low-risk cleanup, docs, polish, ergonomics, or speculative feature.Low-risk cleanup, docs, polish, ergonomics, or speculative feature.clawsweeper:needs-maintainer-reviewClawSweeper marked this issue as needing maintainer review before automation.ClawSweeper marked this issue as needing maintainer review before automation.clawsweeper:needs-product-decisionClawSweeper marked this issue as needing a product or behavior decision.ClawSweeper marked this issue as needing a product or behavior decision.clawsweeper:no-new-fix-prClawSweeper does not recommend queueing a new automated fix PR for this issue.ClawSweeper does not recommend queueing a new automated fix PR for this issue.enhancementNew feature or requestNew feature or requestimpact:securityThis issue is about security boundaries, credentials, authz, sandboxing, or sensitive data.This issue is about security boundaries, credentials, authz, sandboxing, or sensitive data.issue-rating: 🌊 off-meta tidepoolIssue quality rating does not apply to this item.Issue quality rating does not apply to this item.
Description
Activity
Metadata
Metadata
Assignees
Labels
P3Low-risk cleanup, docs, polish, ergonomics, or speculative feature.Low-risk cleanup, docs, polish, ergonomics, or speculative feature.clawsweeper:needs-maintainer-reviewClawSweeper marked this issue as needing maintainer review before automation.ClawSweeper marked this issue as needing maintainer review before automation.clawsweeper:needs-product-decisionClawSweeper marked this issue as needing a product or behavior decision.ClawSweeper marked this issue as needing a product or behavior decision.clawsweeper:no-new-fix-prClawSweeper does not recommend queueing a new automated fix PR for this issue.ClawSweeper does not recommend queueing a new automated fix PR for this issue.enhancementNew feature or requestNew feature or requestimpact:securityThis issue is about security boundaries, credentials, authz, sandboxing, or sensitive data.This issue is about security boundaries, credentials, authz, sandboxing, or sensitive data.issue-rating: 🌊 off-meta tidepoolIssue quality rating does not apply to this item.Issue quality rating does not apply to this item.
Type
Fields
Priority
None yet
Scanner name
skills-inspector
Upstream URL
https://github.com/atarico/skills-inspector
Request type
New built-in scanner adapter
CLI/API shape
skills-inspector --json
Prints a single JSON document to stdout. Supports skill and plugin targets
(it walks up from a SKILL.md to the enclosing .claude-plugin/plugin.json,
marketplace.json or opencode.json when one exists, since auditing a SKILL.md
without its manifest produces a false clean).
Note on gating: the exit code is always 0 by design — the tool reports and
has no veto. Gate policy would need to be JSON-path based rather than
blockOnExitCode.
Credentials and setup
None. No API keys, no network access, no LLM calls, no telemetry.
Python 3.10+, standard library only, zero runtime dependencies.
Install: pip install "git+https://github.com/atarico/skills-inspector.git@"
Expected artifact
A JSON report. Each finding carries rule id, severity, confidence,
disclosure status (undeclared / euphemistic / declared), capability,
file+line, sanitized evidence, and impact.
The report also carries mandatory "not_analyzed" and "coverage_limits"
sections — a report that omits what it could not inspect implies a
completeness the tool does not have.
I'm currently adding a published JSON Schema and a schema_version key
before proposing anything concrete.
Example proof
I've been building this for about two months. It's a detection engine
rather than a harness: 111 implemented rules across 14 families, plus
single-file taint tracking (source → sink across variables, redirects and
env exports), a reachability graph that separates active from conditional
and dormant files, structural parsing of the agent control plane
(settings.json, .mcp.json, opencode.json, hooks, subagents, permissions),
and disclosure-gap scoring against the unit's own description.
Corpus: 143 fixtures (56 benign / 82 malicious / 3 documented known-misses),
with exact per-fixture expected finding sets pinned in fixtures/EXPECTED.json.
Those numbers are self-measured and I'd rather not lean on them — I'm working
toward running it against SkillTrustBench and clawhub-security-signals so
there's an external number to compare against clawscan-static on the same
corpus.
Rules catalogue: https://github.com/atarico/skills-inspector/blob/main/RULES.md
I'm not proposing a PR yet. Before that I want to land packaging, the
published schema, and those benchmark numbers. Two questions that would
shape the work:
precedent in docker/clawscan-runtime/Dockerfile, or is PyPI publication
expected for a new adapter?
separately? CONTRIBUTING.md asks for one topic per PR, but the adapter
isn't usable in the default Docker sandbox without the image entry.
Separately: docs/scanners.md and CONTRIBUTING.md both link to
docs/scanners.md#adding-a-built-in-scanner-adapter, but that heading
doesn't exist in the tree. Happy to send a docs-only PR writing that
section if it'd be useful.