Pricing
Free to use. The site states there are no hidden fees, subscriptions or premium versions.
Learn moreFree scanner that vets AI agent skills for threats before install

Bitdefender AI Skills Checker is a free web tool that scans AI agent skills from sources like skills.sh, LobeHub and GitHub for backdoors, data exfiltration, prompt injection and obfuscation, then returns a risk report.
Bitdefender AI Skills Checker is a free security scanner for the add-on skills that AI coding agents load and run. A skill is a bundle of instructions and files that extends what an agent can do, and a poorly written or deliberately malicious one can quietly steal data or run unwanted commands on a developer's machine. This tool inspects a skill before it is installed or shared, so problems surface while they are still cheap to deal with. Input is simple. A user pastes a link or uploads an archive in common formats such as zip, tar, tar.gz, 7z or rar, then runs the check. The scanner covers skills published through OpenClaw, SkillsMP, LobeHub, AgentSkill, Hermes and skills.sh, along with GitHub repositories that hold one or more skill files. Analysis happens in two passes. First, pattern-based detection compares the files against a library of known threat behaviors, including hidden backdoors, data exfiltration logic, prompt injection vectors, obfuscation techniques and suspicious file or system operations. Second, an AI model reviews each flagged item in context, aiming to discard false alarms and confirm the real problems. The result is a risk assessment report listing the issues found and the content that triggered them. The audience is mainly developers and power users who add third-party skills to agents such as Claude Code, Codex, OpenClaw, opencode and Hermes Agent. Besides the web page, the checker can be added as a skill itself through an npx command from skills.sh, which lets it be used from inside those agents. Among alternatives, it is a narrow, single-purpose utility rather than a full endpoint security suite. Its strengths are zero cost, no account requirement mentioned on the page, and the backing of an established security vendor with a long track record. Teams wanting continuous runtime monitoring of agents will need something broader, but for a quick pre-install review of an unfamiliar skill it fills a gap that manual code reading handles slowly.


Free to use. The site states there are no hidden fees, subscriptions or premium versions.
Learn moreChecks skills from OpenClaw, SkillsMP, LobeHub, AgentSkill, Hermes, skills.sh and GitHub repositories. Works in Claude Code, Codex, OpenClaw, opencode and Hermes Agent, and installs via npx from skills.sh.
Scans skills from a link or archive upload. Pattern-based detection flags backdoors, data exfiltration, prompt injection, obfuscation and suspicious file operations. An AI model then validates findings in context to reduce false positives, and a risk assessment report lists the issues.





