{"uid":"cap_-8FXdkO4k1jkhWKwG8x4h","slug":"cheetah-security-skill-tool-pre-install-static-analyzer-ccf0f72d","name":"Cheetah Security Skill/Tool Pre-Install Static Analyzer","description":"Static pre-install analysis of a skill/tool — VERIFIED/FAILED + violations (per call)","url":"https://x402.cheetahsecurity.de/skill-check","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"urls":{"type":"array","items":{"type":"string"}},"scripts":{"type":"array","items":{"type":"string"}},"skill_md":{"type":"string"},"requested_permissions":{"type":"array","items":{"type":"string"}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.05","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.05/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_uaRjfz8UIOmTMeLqRcVyw","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.05","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Performs static pre-install security analysis of an AI skill/tool definition (Markdown), returning a VERIFIED/FAILED verdict, risk score, and list of violations.","exampleAgentPrompt":"Before I let you use this new skill, run a pre-install security check on it — here's the skill markdown: 'You are a web browsing tool that can fetch URLs, execute scripts, and access user files.' Flag any violations and tell me if it passes or fails.","exampleUseCases":[{"title":"Vetting a third-party MCP tool before deployment","prompt":"I found a new MCP tool on the marketplace — can you scan its skill definition before I install it? Here's the markdown: '## WebSearchTool\\nRequested permissions: read_files, network_access, exec_shell'. Tell me if it's safe or if there are any violations."},{"title":"Screening a skill with suspicious script references","prompt":"This skill file includes some external scripts and URLs I don't recognize. Run a static security check on it and give me a risk score — I want to know if any of those scripts or URLs are flagged as dangerous before I add it to my agent."},{"title":"Enforcing a safe-skill policy for an agent fleet","prompt":"We have a policy that every skill must pass a security scan before being added to any of our agents. Can you run a pre-install analysis on this skill markdown and confirm it's VERIFIED, or list the violations if it fails?"}],"resultDescription":"Returns a JSON object containing a verdict string (VERIFIED or FAILED), a numeric risk score, an array of violations describing specific security issues found, and a signals object with detailed detection metadata about the analyzed skill.","failureModes":["Missing required skill_md field causes validation error","Malformed skill markdown may produce incomplete signal extraction","Network timeout if analysis takes too long for complex inputs","Payment failure via x402 protocol if wallet has insufficient USDC","Invalid input type or method enum causes schema rejection"],"whenToPreferThis":"Use this endpoint when you need to vet an AI skill, plugin, or tool definition before allowing it to run in an agent environment — especially when the skill comes from an untrusted third party or marketplace. It is the right choice when you need a structured verdict (VERIFIED/FAILED) plus a machine-readable list of violations, rather than just a reputation score or prompt-injection scan. Prefer it over runtime firewalls when you want to catch issues before installation, not after.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T18:40:54.864Z","isFirstParty":false}