AGENT SKILL SECURITY / POWERED BY CRUCIBLE

A new skill.
A new reason to look closer.

Your agent follows instructions. Know what they do.
Inspect skill bundles for hidden behavior before you install.

Nova + YARA Correlated evidence Commit-pinned reports
INSIDE THE BUNDLEILLUSTRATION
research-assistant/
SKILL.mdINSTRUCTIONS
scripts/collect.py
config.json
references/guide.md
LOOK BEYOND THE PROMPT

Instructions. Scripts. Context.

Related behavior tells the fuller story.
Exact commit. Defined scope.
PUBLIC GITHUB REPOSITORY01 / SUBMIT

Paste a repository or a link to a SKILL.md file. We inspect its bundled files, too.

Scan options
Just looking around?Explore an example report
02 / EXPLORE THE EVIDENCE

A few skills. The whole story.

Follow an example from bundled files to a readable report.

Fictional skills, illustrative results.
This replay does not submit a live scan.

EXAMPLE REPLAY01 / 03
  1. 01Pin the source
  2. 02Inspect the bundle
  3. 03Connect the evidence
  4. 04Read the report
skills/research-assistant/SKILL.md

Research assistant

RevisionIllustrative snapshotBundle8 files inspectedEnginesNova + YARA
Resolving the example revision

Illustrating the scan workflow. No requests are sent.

MORE THAN A KEYWORD MATCH Whole skill bundles Exact GitHub revisions Evidence you can inspect
03 / HOW WE LOOK CLOSER

Useful findings.
Without the guesswork.

Read the detection methodology
01

Pin the source

Resolve a GitHub revision and inspect a bounded snapshot. Each report records exactly what was scanned.

02

Connect the evidence

Nova and YARA identify signals. Correlation checks their file context and nearby behavior to prioritize review.

03

Make an informed call

Inspect the findings, coverage, and optional AI assessment. A match is a starting point for review.

A completed scan describes what the configured checks found.
It is not a guarantee of safety, and an incomplete scan is never presented as clean.

Understand the limits