SCAN THE FILESYOUR AGENTSSILENTLY TRUST
SkillForge audits SKILL.md, AGENTS.md, CLAUDE.md, Cursor rules, Copilot instructions, and MCP configs before your team lets Claude, Codex, Cursor, or agent harnesses read them.
Full scans are paid. The sample report shows the exact inventory, findings, verdict, and mitigation format before checkout.
Agent Context Risk ReportRepository: acme/agent-workflowsVerdict: NEEDS TEAM REVIEWInventoried files- AGENTS.md Codex- CLAUDE.md Claude- .claude/skills/deploy/SKILL.md- .cursor/rules/release.mdc Cursor- .mcp.json MCPFindings[HIGH] Outbound curl in deploy skillCould exfiltrate release notesor environment values.[MEDIUM] Broad MCP filesystem accessAdd path allowlists before use.Next step: manual review before sharingthese instructions across the team.
How it works
FROM REPO URL TO
TRUST DECISION
Inventory
Paste a public GitHub repo or upload a ZIP. SkillForge discovers the agent files that Claude, Codex, Cursor, Copilot, and MCP can trust.
AGENTS.md, CLAUDE.md, SKILL.md, .mcp.json
Analyze
Static rules and AI review check for hidden instructions, shell execution, exfiltration, broad permissions, secrets, and unsafe installs.
safe / review / block verdict
Remediate
Download a report, fix risky instructions, and rescan through Pro or Team before approving the files for team use.
Markdown report for PRs and security review
Why teams pay
AGENT FILES ARE
SUPPLY CHAIN NOW
Your agents can read instructions, run tools, install packages, and touch repositories. SkillForge gives teams a review layer before those instructions become shared behavior.
Repo-wide context discovery
Finds SKILL.md, AGENTS.md, CLAUDE.md, Cursor rules, Copilot instructions, and MCP configs in one scan.
Agent-specific risk checks
Flags prompt injection, command execution, exfiltration, secrets, obfuscation, broad MCP permissions, and unsafe installs.
Platform influence map
Shows which files affect Claude, Codex, Cursor, Copilot, MCP, or generic agent harness behavior.
Clear install verdict
Every report ends with safe to trust, needs team review, or block until fixed.
Shareable risk report
Download a Markdown report with file inventory, severity findings, and remediation guidance.
Team review workflow
Keep scan history, share reports, and apply consistent policy thresholds across team repositories.
Agent Context Scanner
SEE WHAT YOUR AGENTS
WILL TRUST BY DEFAULT
Coding agents now load repo instructions, skills, rules, and MCP configs as trusted context. SkillForge inventories those files and flags behavior your team should review before adoption.
/10.0
5 files inventoried - 3 findings detected
Why this matters
These files can change how an agent uses tools, reads files, handles secrets, and executes shell commands. Review them like dependencies before sharing across a team.
Repo-level discovery
Scan the source, not just one uploaded file. The report maps every trusted agent instruction file it can find.
Static checks + AI review
Deterministic rules catch obvious dangerous patterns; AI review explains subtle risks in natural language.
Paid team workflow
Pro and Team plans unlock full scans, exports, scan history, and mitigation guidance for repeated review.
What we check
Pricing
PAID FROM DAY ONE,
BECAUSE TRUST IS THE PRODUCT
View the sample report before subscribing. Use Pro or Team when you need real repo scans, exports, and mitigation guidance.
Pro
For developers and small teams who want the full report.
- Repo and ZIP agent context scans
- Full Agent Context Risk Report
- Markdown export
- Mitigation recommendations
- Early access to API experiments
Team
For teams standardizing Claude, Codex, Cursor, or MCP.
- Up to 5 active repos
- Scan history
- Shareable reports
- Team policy thresholds
- Priority scanner improvements
Enterprise
For private repo workflows and procurement-heavy buyers.
- Private repo review
- Custom detectors and policies
- Audit export support
- Security questionnaire support
- SSO and admin controls roadmap
FAQ
Frequently Asked Questions
Product
Scanner
BEFORE YOUR TEAM
TRUSTS THE AGENT
Scan the instructions, rules, skills, and MCP configs that shape agent behavior. Then decide: safe, review, or block.
Works with Claude, Codex, Cursor, Copilot instructions, and MCP configs.