{"uid":"cap_IT5gyal-9rncFW04V34LG","slug":"shieldapi-ai-skill-plugin-supply-chain-security-scanner-e83a7e08","name":"ShieldAPI AI Skill/Plugin Supply Chain Security Scanner","description":"ShieldAPI - AI skill/plugin supply chain security scanner","url":"https://shield.vainplex.dev/api/cdp/scan-skill","method":"POST","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["POST"],"type":"string"},"queryParams":{"type":"object","required":["skill"],"properties":{"skill":{"type":"string","maxLength":10000,"description":"Text of the skill or plugin to scan for vulnerabilities"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.02","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.02/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_pSMcyGdjpLl94M6IpAzgY","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.02","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Scans the text of an AI skill or plugin for supply chain vulnerabilities, prompt injection risks, and malicious patterns before an agent installs or executes it","exampleAgentPrompt":"Before I install this new AI skill, scan it for supply chain vulnerabilities and prompt injection risks — here's the full skill definition text: [paste skill text].","exampleUseCases":[{"title":"Vetting a third-party MCP tool before use","prompt":"I found an MCP tool on GitHub that claims to query stock prices — can you scan its full definition text for any hidden prompt injections, data exfiltration attempts, or supply chain risks before I add it to my agent?"},{"title":"Auditing a marketplace plugin pre-deployment","prompt":"We're about to deploy a plugin from the AI marketplace into our customer-facing agent — please scan this plugin's source text for any malicious patterns or vulnerabilities so I know it's safe."},{"title":"Checking an in-house skill before production","prompt":"Our team just wrote a new booking skill for our agent fleet — run a supply chain security scan on its definition to catch any injection risks or unsafe behaviors before we push it to production."}],"resultDescription":"Returns a structured security assessment of the submitted skill/plugin text, including identified vulnerabilities, prompt injection indicators, supply chain risk signals, and an overall security verdict or risk score.","failureModes":["Empty or missing skill text returns a validation error","Skill text exceeding 10,000 characters is rejected","Payment not fulfilled triggers HTTP 402 response","Malformed input object or missing required fields returns a schema validation error","Network timeout if the analysis takes too long for very large inputs"],"whenToPreferThis":"Choose this endpoint when you need to vet the text of an AI skill, plugin, or tool definition for supply chain attacks, prompt injection, or malicious behavior before your agent installs or executes it — especially when consuming third-party plugins from marketplaces, GitHub, or untrusted sources. Prefer this over generic code scanners when the target is specifically an AI agent skill or plugin format.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T06:36:34.492Z","isFirstParty":false}