SkillCheck by Repello
Scans MCP skills and AI agent tools for security flaws, prompt injection, and data exfiltration risks before deployment.

SkillCheck is a security scanner for AI skills and agent tools that helps teams review skills before they are deployed into production. It focuses on identifying vulnerabilities, prompt injection risks, and potential data exfiltration paths so security concerns can be surfaced before a skill is put into use.
Built around a straightforward upload-and-scan workflow, SkillCheck gives teams a lightweight way to inspect third-party and internal AI skills. Instead of treating AI agent security as only a traditional code review problem, it focuses on what an AI skill or agent tool could be manipulated into doing.
Key Features
AI Skill Vulnerability Scanning
SkillCheck scans uploaded AI skills for potential security issues before deployment. This gives teams an early review point for identifying concerns in skills they are considering for production use.
- Scan AI skills before deployment
- Review third-party and internal skills
- Surface potential security concerns early
- Designed around an upload-and-scan workflow
Prompt Injection Detection
AI skills can contain instructions that influence how an agent behaves. SkillCheck looks for prompt injection risks that could cause a skill to override expected behavior or introduce unwanted instructions into an agent workflow.
- Detect potential prompt injection patterns
- Flag skills that may attempt to override expected behavior
- Review findings before approving a skill for production
Data Exfiltration Risk Review
SkillCheck also examines skills for potential data exfiltration risks. This helps teams identify ways an AI skill could potentially expose or mishandle sensitive information before it becomes part of an agent workflow.
- Identify potential data exposure paths
- Surface data exfiltration concerns
- Review security findings before rollout
Severity-Based Findings
Security findings are organized around severity so teams can identify which issues deserve attention first. The severity view provides a simple way to prioritize security concerns discovered during a scan.
- View findings by severity
- Prioritize higher-risk concerns
- Review security issues before deployment
Upload-and-Scan Workflow
SkillCheck keeps the security review process focused on the skill itself. Teams can upload skills or relevant assets and run them through the scanner before deciding whether they are ready to use.
- Upload AI skills as files or assets
- Scan newly added skills
- Review results before production approval
- Maintain a simple inventory of scanned skills
Built For AI Agent Security Teams
SkillCheck is designed for teams working with MCP skills and AI agent tools where security review needs to account for agent behavior, instructions, and access to information.
It can be useful for:
- Security-minded builders reviewing AI skills before deployment
- Platform teams responsible for approving agent tools
- AI engineering teams evaluating third-party skills
- Internal teams reviewing custom skills before production use
- Security teams looking for prompt injection and data exfiltration risks
Common Use Cases
Review Third-Party AI Skills
Scan externally sourced skills before adding them to an internal agent environment. SkillCheck provides a security checkpoint for identifying potential vulnerabilities and risky behavior.
Approve Internal Agent Tools
Run internally developed skills through a security review before they become available to production agents. This creates an additional inspection step alongside existing development and security processes.
Screen MCP Skills
Review MCP skills and agent tools for vulnerabilities, prompt injection concerns, and potential data exfiltration risks before incorporating them into modern agent workflows.
Prioritize Security Findings
Use severity information to distinguish higher-risk findings from lower-priority concerns and focus review efforts where they matter most.
Lightweight AI Skill Security Review
SkillCheck focuses on a specific security problem: understanding the risks inside AI skills and agent tools before they go live. Its interface centers on scanned skills, recent uploads, names, and severity information, suggesting a lightweight review workflow rather than a broad AI governance suite.
For teams adopting agentic workflows, this provides a practical checkpoint between acquiring or building a skill and allowing it to run in production.
Why It Matters
AI agent tools can introduce security considerations that extend beyond traditional application code. A skill may contain instructions that influence agent behavior or provide paths through which sensitive information could potentially be exposed.
SkillCheck brings those concerns into a focused pre-deployment review process, helping teams inspect AI skills before they become part of a live agent workflow.
Review AI Skills With SkillCheck
Scan MCP skills and AI agent tools for vulnerabilities, prompt injection risks, data exfiltration concerns, and severity-ranked findings before approving them for production use.