Sherif Kozman

SkillShield - Security-scored directory for AI skills and agent tools

by
The first security-scored directory for AI skills. Scan GitHub/GitLab repos with SKILL.md files through 4-layer security analysis: manifest, static code, dependency, and LLM behavioral checks. Get 0-100 trust scores, real-time vulnerability detection, and security badges. 8,890+ skills scanned, 6,300+ findings identified. Part of The Red Council security suite. Discover trusted AI capabilities or validate your own.

Add a comment

Replies

Best
Sherif Kozman
Maker
📌
Hey Product Hunt! 👋 I'm excited to launch SkillShield - the security-scored directory for AI skills. **The Problem:** As AI agents become more powerful, they're being given access to external tools and "skills" - but how do you know if those skills are safe? A malicious or vulnerable skill could leak data, expose APIs, or worse. **The Solution:** SkillShield scans AI skill repositories (SKILL.md files) through 4 security layers: - Manifest analysis - Static code analysis - Dependency graph checking - LLM behavioral safety testing Each skill gets a 0-100 trust score, making it easy to identify safe capabilities. **What's Live:** ✅ 8,890+ skills already scanned ✅ Real-time vulnerability detection ✅ Security badge generation ✅ Filter by trust score, findings, and category ✅ Part of The Red Council security suite (165+ attack patterns) **Why Now:** With Claude's Computer Use, OpenAI's function calling, and the explosion of AI agent frameworks, we need security standards before things break at scale. I'd love your feedback! What security features would make you trust an AI skill?
Charles Sturt

Interesting - I launched skillshield.dev on Feb 6 with the same concept. Would love to chat about how our approaches differ...

Sherif Kozman

@charlescsturt Sure would love to. Great website too

Sarrah Pitaliya

Hey @sherif_kozman

A visible trust score + layered scanning (especially behavioral LLM testing) is a smart way to make security actionable instead of abstract.

We’re seeing a similar shift at ZeroThreat.ai Automation is scaling fast, and security needs to be embedded, not bolted on later.

Would like to know how are you validating business logic abuse or privilege escalation between chained skills? That’s usually where things get tricky.

Sherif Kozman

@sarrah_pitaliya Happy to share. Also each skill has its own dedicated report page with findings and different scans processed