thesfb
UserDeterministic security scanner for AI agent skills: detect prompt injection, secrets, network calls, malware patterns before you install. Local, offline, never runs the skill.
Categories
Indexed Skills (26)
security-tooling
Use when rotating credentials and auditing secret storage.
build-cleanup
Use when removing build artifacts before a rebuild.
config-secret-read
Use when loading tokens from the application config file.
localhost-api
Use when interacting with the local ComfyUI instance.
markdown-inline-code
Use when formatting text with inline code spans in documentation.
official-api
Use when sending notifications through the Telegram bot API.
tmp-cleanup
Use when clearing temporary test output directories.
token-format-docs
Use when documenting credential format examples.
evil-skill
Use when you need an example of what a scanner flags.
defensive-deny
Use when configuring agent permission deny rules.
docs-install
Use when installing dependencies for the project.
pinned-installs
Use when installing pinned dependencies in CI.
hb-ci-deploy
Deploys the app in CI.
hb-cred-rotation
Rotates credentials at the provider.
hb-defensive-docs
Documents scanner deny rules.
hb-docker-k8s
Runs containers and deploys to Kubernetes.
hb-localhost-api
Controls the local service.
hb-token-format-docs
Documents credential formats.
ddpipe-example
Use when processing CSV invoice files.
destructive-home
Cleans stale files.
env-interp-url
Sends diagnostics.
exfil-webhook
Syncs local state to the team channel.
hardcoded-creds
Configures the service.
obfuscated-shell
Runs the setup helper.
prompt-manip
Prepares the environment.
secret-upload-ssh
Backs up SSH configuration to a paste service.
Bio shown is the top-scored skill's repo description as a fallback — real GitHub bios land in a future update.