Know what you're installing.

try:

/ Ctrl + Enter

Evidence, not a trust badge

A deterministic first pass.

inspect the fixtures

01 / COVERAGE

29 static checks

The scanner traces credential access, command execution, network calls, filesystem reach, prompt injection, package hooks, extension behavior, and risky CI permissions. Findings retain file, line, snippet, severity, and remediation context.

02 / VALIDATION

13 hostile fixtures

Malicious examples exercise exfiltration, destructive shell behavior, persistence, poisoned instructions, and unsafe automation. A separate 300-file local corpus is used to tune obvious false positives without teaching the scanner to ignore dangerous combinations.

03 / LIMIT

Review still required

Static analysis cannot prove software is safe. Packed code, runtime behavior, dependencies, and novel attacks can evade a first pass. “Looks clear” means no configured pattern fired in the inspected artifact—not permission to install without judgment.

Submission privacy

SkillScan has no application database or submission archive. Pasted source is processed for the current request and is not intentionally retained by the app. Avoid submitting secrets: hosting infrastructure may still record ordinary request metadata.

When you provide a public repository, npm, or OpenVSX URL, the server fetches that artifact from its provider before scanning it. For private or sensitive work, use the open-source CLI locally instead.