SkillGuard · AI skill supply-chain security
Admit only the skillsthat keep you on course.
SkillGuard reads every AI skill before you run it: what it can do, what it touches, and where a chain of harmless-looking skills becomes a data-exfiltration path. Below is the literal output on a real public repo, not an example. The practitioner door names the skills this discipline asks you to acquire.
Read: Every skill is read before anything runs — capabilities extracted, nothing executed.
Where SkillGuard fits
The gate on the “apply a skill” step.
A function climbs by applying skills. SkillGuard is not a tool off to the side, it is the pre-check every skill passes before it is applied. Then the proof below runs it on a real public repo.
Read the function
The maturity check finds the gate-blocking gaps: the controls sitting below target.
Fit the skills
The reading names the ready-made skills that close each gap, the capability to add.
SkillGuard admits
Every prescribed skill passes the scan before it can be applied.
See the pre-check →Move the lever
Only admitted skills are applied: the People, Process, or Technology change that raises the control.
Watch it move
Re-run the check: governance rises, the gate opens, autonomy may climb, safely.
↻ Re-assess feeds the next diagnose, each turn earning the next rung.
Upstream · what stocks 02 Prescribe
02 Prescribe draws from a living library, and a governed autonomous agent (Hermes) keeps it current: it watches the field and proposes new skills from a chat window, inside a gate of three tools it cannot cross. SkillGuard admits what it proposes, so the loop never runs on unvetted capability. How we govern our own agent →
We scanned 56 public skills. Every finding is triaged and resolved.
This is the literal output of our own scanner run against a real public repository — not an illustration.
Scanned 56 public skills at github.com/binu8/aisecskills-reference@0be309e. Reproduce it: python3 tools/gen_reference_skillbom.py.
Go deeper
How the scan actually works — capability extraction, the detection patterns, triage discipline, and how skill combinations become attack chains — lives on the method page. The practitioner story around it is one page up. See the scan methodology →