2026-10-11 17:10 UTC

Independent security review and use will determine whether SkillPreflight reliably identifies dangerous or unreliable AI-agent skills before installation and reduces agent supply-chain risk.

state: expiredheat: lowuncertainty: highknownscott: lowagentic-security agent-harnesses developer-toolsAgent Contracts

What is this?

SkillPreflight is presented in a Show HN post as a developer tool from Agent Contracts that scores AI-agent skills before installation, aiming to flag dangerous or unreliable packages and reduce agent supply-chain risk. The supplied search results establish the broader need for pre-installation review—skills may access files, credentials, and shells—and show that several scanners already target malicious patterns, permissions, and dependency risks. However, none of the snippets independently documents SkillPreflight’s implementation, scoring method, accuracy, or adoption; one result also reports that agent-skill scanners can be bypassed, making independent validation central to the case.

Why it matters to Scott

The radar already tracks essentially the same unvalidated pre-install scanning proposition in “AgentShield — offline agent scanner” and “Kenwea — npm install sandbox,” while Scott’s Agent Provenance Stack and Architecture, Not Vibes already treat artefact review as only one layer beneath verifiable provenance and runtime containment. With no supplied details on SkillPreflight’s method, accuracy, or independent results, this is another example of an established pattern rather than evidence that extends or challenges Scott’s position.
ip:framework.agent-provenance-stackip:framework.architecture-not-vibesradar:agentshield-offline-agent-scannerradar:kenwea-npm-install-sandboxradar:concept.agent-skillsradar:concept.software-supply-chain
queries asked of Scott's wikis
  • agent skill trust and pre-installation security
  • coding-agent harness permission boundaries
  • static scanning versus runtime monitoring for agents
  • agent supply-chain threat model
  • capability scoring and trust contracts
  • sandboxing untrusted agent tools and skills

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (4) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hn ⭐Show HN: SkillPreflight – score AI agent skills before installing them80709286210
🟧 hnCredentials Are Leaked by LLM Agent Skills: An Empirical Studygeox20
🟠 redditBuilt a skill to search and vet any available GitHub repo before building anything
ClaudeAI
trogloditan11
🟠 redditClaude can be tricked into installing malware through poisoned skill files.
ClaudeAI
Novel_Bedroom_3466147

Interpretation history

Decision trace