Built on open-source detection
- NOVA Framework
- Prompt-pattern inspection and semantic signals in skill instructions.
- YARA
- Rule-based matching across the files included in a skill bundle.
- YARA Forge
- Community-maintained, standardized YARA rule collections. We credit the project and the wider rule-author community for their work.
- ClamAV
- Static malware signatures using an official database snapshot. Artifact reports identify its version and age.
- LIEF
- Structural metadata for PE, ELF and Mach-O binaries. Parsing does not establish that a file is safe.
- capa
- Static capability detection for supported binaries. Capabilities remain evidence to interpret, not a malicious verdict.
- LOLSkills by MagicSword
- The scanner brings these checks together, correlates their evidence, and records coverage. Optional advisory AI runs through the configured provider; each returned assessment identifies its model when recorded.
MagicSword provides this interface, orchestration, and report presentation. The upstream projects do not endorse individual reports, and their names are not a guarantee of safety.
Security research references
We use AI Security Matrix as a directory for researching security tools. The following skill scanners are candidates for future evaluation. These references do not contribute detections to current LOLSkills reports.
- Snyk Agent Scan — skill and agent security scanning. Registry integrations require Snyk’s designated API.
- Tencent AI-Infra-Guard Skill Scan — AI-assisted skill auditing with structured results.
- Cisco Skill Scanner — local static and behavioral analysis, with optional cloud analyzers.
Read our detection methodology for how these checks work and how to interpret a report.