Product · Skills review

Review every skill before it runs

Skills, hooks, and context files auto-load into agent sessions with no signing, no sandbox, and no review. Ospiri scans them pre-flight — and blocks the ones that shouldn't run.

Book a demo
The problem

An unsigned, auto-loading supply chain

What auto-loads into sessions

  • Skill files — markdown instruction bundles dropped into local skill folders auto-load next session; distributed through open registries with no signing or review.
  • Hooks — event-driven shell commands that execute on session start and around every tool call.
  • Context files — project-level instruction files injected into every session in a repo.

Documented in the wild

  • Poisoned skills at scale — independent research found roughly a third of publicly shared skills carried flaws, from embedded secrets to malware droppers.
  • Hook-based RCE — project-file hooks used as a remote-code-execution vector (patched, class persists).
  • Instruction injection — context files quietly steering agents into unapproved workflows.
No native layer reviews these. Skills load with no scan, hooks fire silently, and context files are trusted by default — on every machine that has them.
How it works

Pre-flight scanning, continuous re-review

Discover
Every skill, hook, and context file across the fleet is inventoried — including the ones users installed themselves.
Scan
Scanned pre-flight and re-scanned on update — poisoned instructions, embedded secrets, and malware droppers surfaced before a line executes.
Enforce
Unapproved workflows blocked by policy; approved skills tracked by version so a malicious update can't ride an earlier approval.
Alert
Findings land in your stack with full context — which file, which machine, which agent would have run it.

Scan your fleet's skill files

Book a demo. We'll scope a deployment for your environment.

Book a demo