Independent security review and use will determine whether SkillPreflight reliably identifies dangerous or unreliable AI-agent skills before installation and reduces agent supply-chain risk.
state: expiredheat: lowuncertainty: highknownscott: lowagentic-security agent-harnesses developer-toolsAgent Contracts
What is this?
SkillPreflight is presented in a Show HN post as a developer tool from Agent Contracts that scores AI-agent skills before installation, aiming to flag dangerous or unreliable packages and reduce agent supply-chain risk. The supplied search results establish the broader need for pre-installation review—skills may access files, credentials, and shells—and show that several scanners already target malicious patterns, permissions, and dependency risks. However, none of the snippets independently documents SkillPreflight’s implementation, scoring method, accuracy, or adoption; one result also reports that agent-skill scanners can be bypassed, making independent validation central to the case.
Why it matters to Scott
The radar already tracks essentially the same unvalidated pre-install scanning proposition in “AgentShield — offline agent scanner” and “Kenwea — npm install sandbox,” while Scott’s Agent Provenance Stack and Architecture, Not Vibes already treat artefact review as only one layer beneath verifiable provenance and runtime containment. With no supplied details on SkillPreflight’s method, accuracy, or independent results, this is another example of an established pattern rather than evidence that extends or challenges Scott’s position.
ip:framework.agent-provenance-stackip:framework.architecture-not-vibesradar:agentshield-offline-agent-scannerradar:kenwea-npm-install-sandboxradar:concept.agent-skillsradar:concept.software-supply-chain
queries asked of Scott's wikis
- agent skill trust and pre-installation security
- coding-agent harness permission boundaries
- static scanning versus runtime monitoring for agents
- agent supply-chain threat model
- capability scoring and trust contracts
- sandboxing untrusted agent tools and skills
Measured heat
no measured readings yet — the hourly heat pass fills this in
How the heat travelled
no chain yet — the hourly chain pass fills this in
Evidence (4) — ⭐ canonical anchor
Interpretation history
2026-08-29T23:25:25Z
Refreshed comments only repeat generic containment advice and analogies to older supply-chain attacks; they provide no reproducible exploit, independent SkillPreflight evaluation, adoption, or bypass result. The product-specific launch has faded without earning differentiation from existing scanner cases.
2026-08-29T18:31:39Z
The poisoned-skill anecdote adds another weak signal for the broader agent supply-chain threat, but provides no reproducible exploit or evidence about SkillPreflight’s detection quality. The product-specific case remains an unvalidated duplicate of established pre-install scanning efforts.
2026-08-29T18:24:28Z
evidence attached: reddit.post.1w1tjbv — Although anecdotal and unverified, this is directly relevant corroborating evidence for poisoned agent skills creating software-supply-chain risk.
2026-08-28T12:25:42Z
The repository-vetting skill adds another implementation of the broader preflight-review pattern, but it neither evaluates SkillPreflight nor demonstrates that static scoring catches agent-skill security failures. The product-specific case remains unvalidated and duplicative despite a hot surrounding topic.
2026-08-28T12:23:51Z
evidence attached: reddit.post.1w0nsb3 — A released skill that checks repository provenance, licensing, maintenance, source, and vulnerabilities materially contextualizes agent-skill supply-chain vetting.
2026-08-26T19:30:45Z
The empirical study strengthens the underlying threat model for pre-installation skill auditing, but it does not evaluate SkillPreflight or reveal whether its scoring detects credential-leakage risks. The product-specific hypothesis therefore remains unvalidated and duplicative of already tracked scanner cases.
2026-08-26T19:24:17Z
evidence attached: hn.story.49453521 — This empirical study provides relevant security evidence that agent skills can leak credentials, strengthening the case for pre-installation skill auditing.
2026-08-25T10:41:40Z
The one-time re-evaluation adds no validation, adoption, or discussion; SkillPreflight remains an untested instance of an already tracked pre-install scanning pattern. The case still depends on independent testing or real-world use to become informative.
2026-08-25T10:33:39Z
grounded: known/low — The radar already tracks essentially the same unvalidated pre-install scanning proposition in “AgentShield — offline agent scanner” and “Kenwea — npm install sa
2026-08-25T10:31:35Z
case created — The released pre-installation skill-scoring tool creates a distinct security episode, but currently has no independent testing or meaningful discussion.
Decision trace
- 08-30 09:25expireRefreshed comments only repeat generic containment advice and analogies to older supply-chain attacks; they provide no reproducible exploit, independent SkillPreflight evaluation, adoption, or bypass
- 08-30 09:25alert_silentThe comment refresh adds no verified event, product finding, or new protective action; the broader risk and containment response are already established and can wait for routine coverage elsewhere.
- 08-30 09:25alert_routeThe comment refresh adds no verified event, product finding, or new protective action; the broader risk and containment response are already established and can wait for routine coverage elsewhere.
- 08-30 09:21sensor_dirtycomment_update
- 08-30 04:31repriceThe poisoned-skill anecdote adds another weak signal for the broader agent supply-chain threat, but provides no reproducible exploit or evidence about SkillPreflight’s detection quality. The product-s
- 08-30 04:31alert_silentThe new post lacks an accessible source, reproduction, mechanism, or verified impact and does not evaluate SkillPreflight; it adds no consequential fact that Scott needs before the next briefing.
- 08-30 04:31alert_routeThe new post lacks an accessible source, reproduction, mechanism, or verified impact and does not evaluate SkillPreflight; it adds no consequential fact that Scott needs before the next briefing.
- 08-30 04:24alert_silentA low-engagement Reddit post asserts that poisoned skill files can induce Claude to install malware, but supplies no accessible source, reproduction, affected configuration, mechanism, or verified imp
- 08-30 04:24alert_routeA low-engagement Reddit post asserts that poisoned skill files can induce Claude to install malware, but supplies no accessible source, reproduction, affected configuration, mechanism, or verified imp
- 08-30 04:24attachAlthough anecdotal and unverified, this is directly relevant corroborating evidence for poisoned agent skills creating software-supply-chain risk.
- 08-30 04:22propose_attachAlthough anecdotal and unverified, this is directly relevant corroborating evidence for poisoned agent skills creating software-supply-chain risk.
- 08-28 22:25repriceThe repository-vetting skill adds another implementation of the broader preflight-review pattern, but it neither evaluates SkillPreflight nor demonstrates that static scoring catches agent-skill secur
- 08-28 22:25alert_silentThe new evidence is a low-evidence builder release aimed at repository selection, not an independent SkillPreflight test or a demonstrated security result; it can wait for routine review unless evalua
- 08-28 22:25alert_routeThe new evidence is a low-evidence builder release aimed at repository selection, not an independent SkillPreflight test or a demonstrated security result; it can wait for routine review unless evalua
- 08-28 22:24alert_silentThis is a low-evidence builder post about a different pre-build repository-selection skill, not an independent evaluation of SkillPreflight or evidence that pre-install scanning reliably reduces agent
- 08-28 22:24alert_routeThis is a low-evidence builder post about a different pre-build repository-selection skill, not an independent evaluation of SkillPreflight or evidence that pre-install scanning reliably reduces agent
- 08-28 22:23attachA released skill that checks repository provenance, licensing, maintenance, source, and vulnerabilities materially contextualizes agent-skill supply-chain vetting.
- 08-28 22:22propose_attachA released skill that checks repository provenance, licensing, maintenance, source, and vulnerabilities materially contextualizes agent-skill supply-chain vetting.
- 08-27 05:30repriceThe empirical study strengthens the underlying threat model for pre-installation skill auditing, but it does not evaluate SkillPreflight or reveal whether its scoring detects credential-leakage risks.
- 08-27 05:30alert_silentOnly the study title is available, with no findings, methodology, affected systems, or connection to SkillPreflight; this can wait for routine review until technical details or an independent product
- 08-27 05:30alert_routeOnly the study title is available, with no findings, methodology, affected systems, or connection to SkillPreflight; this can wait for routine review until technical details or an independent product
- 08-27 05:24alert_silentAn arXiv paper reportedly studies credential leakage through LLM-agent skills, but the supplied evidence contains only its title and no findings, methodology, affected systems, or actionable mitigatio
- 08-27 05:24surface_candidateAn arXiv paper reportedly studies credential leakage through LLM-agent skills, but the supplied evidence contains only its title and no findings, methodology, affected systems, or actionable mitigatio
- 08-27 05:24alert_routeAn arXiv paper reportedly studies credential leakage through LLM-agent skills, but the supplied evidence contains only its title and no findings, methodology, affected systems, or actionable mitigatio
- 08-27 05:24attachThis empirical study provides relevant security evidence that agent skills can leak credentials, strengthening the case for pre-installation skill auditing.
- 08-27 05:23propose_attachThis empirical study provides relevant security evidence that agent skills can leak credentials, strengthening the case for pre-installation skill auditing.
- 08-25 20:41repriceThe one-time re-evaluation adds no validation, adoption, or discussion; SkillPreflight remains an untested instance of an already tracked pre-install scanning pattern. The case still depends on indepe
- 08-25 20:41alert_silentNo new consequential delta occurred: the launch remains at one point with no comments, technical evidence, or independent evaluation, so it can wait for routine monitoring.
- 08-25 20:41alert_routeNo new consequential delta occurred: the launch remains at one point with no comments, technical evidence, or independent evaluation, so it can wait for routine monitoring.
- 08-25 20:38alert_silentA low-engagement Show HN submission establishes that SkillPreflight exists, but supplies no method, accuracy data, independent evaluation, or distinctive capability beyond already tracked pre-install
- 08-25 20:38alert_routeA low-engagement Show HN submission establishes that SkillPreflight exists, but supplies no method, accuracy data, independent evaluation, or distinctive capability beyond already tracked pre-install
- 08-25 20:33groundThe radar already tracks essentially the same unvalidated pre-install scanning proposition in “AgentShield — offline agent scanner” and “Kenwea — npm install sandbox,” while Scott’s Agent Provenance S
- 08-25 20:31createThe released pre-installation skill-scoring tool creates a distinct security episode, but currently has no independent testing or meaningful discussion.