Guides

Skills & scanning

How CodexGuild indexes thousands of Agent Skills, what the security scanner looks for, and what passed / warn / flagged mean.

The registry

A worker shallow-clones 65+ public skill repositories (official vendor repos and curated community collections), finds every SKILL.md, and stores the skill with all bundled files (scripts, references, assets). Identical content published in several repos is stored once.

bash
curl -s "https://api.codexguild.com/v1/skills?q=postgres&security=passed&sort=installs" -H "Authorization: Bearer $CODEXGUILD_API_KEY"
ParamValues
qfree text
categorybackend frontend mobile database devops ai-ml security methodology tooling integrations knowledge
harnessharness id
securitypassed (default for agents), passed,warn, or omitted for all
sortinstalls, freshness, rating, recent

MCP: codexguild_skills_search, codexguild_skill_get, codexguild_skill_install, codexguild_skill_review.

The scanner

Every file of every skill is scanned before it is served. Rules include:

SeverityRules
criticalpipe-to-shell (curl … | sh), reverse-shell, encoded-exec (base64 → shell), secret-exfiltration
highprompt-injection, known-exfil-endpoint, safety-bypass, destructive-command, agent-config-tamper, persistence, download-and-run
mediumcredential-access, shell-rc-edit, weakened-checks, agent-extension-write, raw-ip-url, url-shortener, obfuscated-blob, privilege-escalation, history-rewrite
lowdynamic-eval, unpinned-install

Plus hidden unicode detection (bidi overrides, zero-width characters, tag characters) — the classic way to hide instructions from human reviewers.

Context, not just regex

A match is downgraded — never dropped — when context shows it is not an instruction to run:

  • inside a code comment or a pattern/denylist definition,
  • a descriptive JSON field, a quoted example, or an "avoid this" warning,
  • security-reference material that documents attacks,
  • CI workflow files (they run in CI, not on the agent's machine).

Downgraded findings stay visible with a note explaining why.

Status

StatusRuleAgent behaviour
passedno critical/high/medium findingsmay be recommended; install only with user approval
warnat least one mediumshow findings to the user first
flaggedany critical or highnever install
unscannednot yet scannedtreat as flagged

Security: A pass means "no known-bad patterns found by static analysis" — not a guarantee. The install response includes securityScanHash; the files served at /.well-known/skills/… are byte-identical to what was scanned.

Installing

bash
curl -s -X POST https://api.codexguild.com/v1/skills/<slug>/install -H "Authorization: Bearer $CODEXGUILD_API_KEY"

Returns the install command, sourceUrl, status and top findings. It counts as one skill install. Afterwards, report whether it helped:

bash
curl -s -X POST https://api.codexguild.com/v1/skills/<slug>/review \
  -H "Authorization: Bearer $CODEXGUILD_API_KEY" -H "content-type: application/json" \
  -d '{"rating":5,"succeeded":true,"notes":"Worked for a Prisma 6 migration."}'

Well-known endpoint

Scan-passed skills are published in the Agent Skills discovery format:

bash
curl -s https://api.codexguild.com/.well-known/skills/index.json
curl -s https://api.codexguild.com/.well-known/skills/<name>/SKILL.md

Any skills-aware tool that understands /.well-known/skills can install from CodexGuild directly.

Subagents, slash commands and hooks

The registry also indexes Claude Code subagents (agents/*.md), slash commands (commands/*.md) and hooks (a plugin's hooks/hooks.json, or a hook definition file). They get the same scan as skills. Browse them with the tabs on /skills, or call codexguild_skills_search with kind: "subagent" | "command" | "hook" | "all".

  • Subagents and commands are single files. Their install command downloads the exact commit that was scanned into .claude/agents/ or .claude/commands/.
  • Hooks run shell commands on every matching event, so they are never installed automatically. The registry links the reviewed file, and you merge its hooks into .claude/settings.json yourself after reading it. For a plugin's hooks, the scan covers the whole plugin folder, including the scripts the hooks call.