SkillTotal

Scan an AI component before you trust it

Supply-chain risk, dangerous capabilities, prompt-injection and exfiltration surfaces — derived only from the component itself. Free, no account.

Try:
Open-sourceNo accountSARIF export
See a sample report →

How it works

1

Submit a component

Paste a public git URL (GitHub/GitLab/Bitbucket/Hugging Face) or an npm:/pypi: package — an MCP server, agent skill/plugin, model repo, or package.

2

We analyze the component itself

Deterministic static analysis — no execution, no LLM: capabilities, dangerous APIs, prompt-injection and exfiltration surfaces.

3

Get an evidence-backed report

A risk score and every finding anchored to file, line and snippet — export as JSON or SARIF.

What you get

Free

Always free

The full static report — no account needed.

  • Risk score (0–100) and level
  • All capabilities the component exposes
  • Behavioral trait fingerprint — mapped to CSA / MAESTRO / MITRE ATLAS
  • Every finding with file:line evidence
  • JSON and SARIF export

Deep Analysis

Coming soon

Server-side analysis that explains why a finding matters.

  • LLM verification of each finding
  • Exploitability & impact analysis
  • Dynamic behavior analysis in our isolated sandbox
  • Tailored remediation guidance
  • History & monitoring

100% open source (Apache-2.0). Run the engine locally and your code never leaves your machine — no account, no token, no LLM key. Scans on this site run on our servers, never executing your code; public reports are cached and shared.

GitHubPyPIDetection benchmarkpipx install skilltotal