{"uid":"cap_2SWmyQkhArsWzu4XqbUJK","slug":"skill-audit-api-b2db7fb7","name":"Skill Audit API","description":"Scan an entire public GitHub repo for malicious AI-skill/supply-chain patterns","url":"https://eltociear-skill-audit.hf.space/audit/repo","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"ref":{"type":"string","description":"Branch/tag/sha (default: HEAD)"},"repo":{"type":"string","description":"GitHub repo as 'owner/name' or full URL"}}},"responseSchema":{"type":"json","example":{"repo":"owner/name","risk_level":"clean","risk_score":0,"files_scanned":84,"flagged_files":[],"total_findings":0}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.005","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.005/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_EfsXbtfFL6PMXKuO8mbAY","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.005","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Scans a GitHub repository containing AI agent skills or plugins for malicious patterns, returning a risk score and list of flagged files.","exampleAgentPrompt":"Can you audit the GitHub repo 'someuser/my-agent-skill' for malicious patterns before I add it to my agent fleet? I need to know the risk level and any flagged files.","exampleUseCases":[{"title":"Vetting third-party agent plugins","prompt":"Before I install the plugin from 'acmecorp/weather-skill' into my agent, can you scan it for malicious patterns and tell me if it's safe — risk level, score, and any flagged files?"},{"title":"Pre-deployment security gate in CI","prompt":"As part of my deployment pipeline, audit the repo 'myorg/customer-support-skill' for any dangerous code patterns so I can decide whether to block the release."},{"title":"Marketplace trust verification","prompt":"I'm browsing AI agent skills on a marketplace and want to know if 'opentools/sql-agent-plugin' has any red flags — can you run a security audit on that repo and report the findings?"}],"resultDescription":"A JSON object with the repository name, an overall risk_level string (e.g. 'clean', 'low', 'high'), a numeric risk_score, the count of files_scanned, a list of flagged_files with details, and a total_findings count.","failureModes":["Invalid or non-existent repository identifier returns an error","Private repositories may not be accessible without credentials","Rate limiting or payment failure returns a 402 response","Large repositories may time out or return partial results","Obfuscated malicious code may evade pattern detection"],"whenToPreferThis":"Use this endpoint when you need a quick, automated security risk assessment of a GitHub repository containing AI agent skills or plugins before integrating them into an agent system. It is purpose-built for the AI agent plugin security domain, unlike generic static analysis tools or SCA scanners.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-13T18:35:25.297Z","isFirstParty":false}