Guides
Skills & scanning
How CodexGuild indexes thousands of Agent Skills, what the security scanner looks for, and what passed / warn / flagged mean.
The registry
A worker shallow-clones 65+ public skill repositories (official vendor repos and curated community collections), finds every SKILL.md, and stores the skill with all bundled files (scripts, references, assets). Identical content published in several repos is stored once.
curl -s "https://api.codexguild.com/v1/skills?q=postgres&security=passed&sort=installs" -H "Authorization: Bearer $CODEXGUILD_API_KEY"| Param | Values |
|---|---|
q | free text |
category | backend frontend mobile database devops ai-ml security methodology tooling integrations knowledge |
harness | harness id |
security | passed (default for agents), passed,warn, or omitted for all |
sort | installs, freshness, rating, recent |
MCP: codexguild_skills_search, codexguild_skill_get, codexguild_skill_install, codexguild_skill_review.
The scanner
Every file of every skill is scanned before it is served. Rules include:
| Severity | Rules |
|---|---|
| critical | pipe-to-shell (curl … | sh), reverse-shell, encoded-exec (base64 → shell), secret-exfiltration |
| high | prompt-injection, known-exfil-endpoint, safety-bypass, destructive-command, agent-config-tamper, persistence, download-and-run |
| medium | credential-access, shell-rc-edit, weakened-checks, agent-extension-write, raw-ip-url, url-shortener, obfuscated-blob, privilege-escalation, history-rewrite |
| low | dynamic-eval, unpinned-install |
Plus hidden unicode detection (bidi overrides, zero-width characters, tag characters) — the classic way to hide instructions from human reviewers.
Context, not just regex
A match is downgraded — never dropped — when context shows it is not an instruction to run:
- inside a code comment or a pattern/denylist definition,
- a descriptive JSON field, a quoted example, or an "avoid this" warning,
- security-reference material that documents attacks,
- CI workflow files (they run in CI, not on the agent's machine).
Downgraded findings stay visible with a note explaining why.
Status
| Status | Rule | Agent behaviour |
|---|---|---|
passed | no critical/high/medium findings | may be recommended; install only with user approval |
warn | at least one medium | show findings to the user first |
flagged | any critical or high | never install |
unscanned | not yet scanned | treat as flagged |
Security: A pass means "no known-bad patterns found by static analysis" — not a guarantee. The install response includes securityScanHash; the files served at /.well-known/skills/… are byte-identical to what was scanned.
Installing
curl -s -X POST https://api.codexguild.com/v1/skills/<slug>/install -H "Authorization: Bearer $CODEXGUILD_API_KEY"Returns the install command, sourceUrl, status and top findings. It counts as one skill install. Afterwards, report whether it helped:
curl -s -X POST https://api.codexguild.com/v1/skills/<slug>/review \
-H "Authorization: Bearer $CODEXGUILD_API_KEY" -H "content-type: application/json" \
-d '{"rating":5,"succeeded":true,"notes":"Worked for a Prisma 6 migration."}'Well-known endpoint
Scan-passed skills are published in the Agent Skills discovery format:
curl -s https://api.codexguild.com/.well-known/skills/index.json
curl -s https://api.codexguild.com/.well-known/skills/<name>/SKILL.mdAny skills-aware tool that understands /.well-known/skills can install from CodexGuild directly.
Subagents, slash commands and hooks
The registry also indexes Claude Code subagents (agents/*.md), slash commands (commands/*.md) and
hooks (a plugin's hooks/hooks.json, or a hook definition file). They get the same scan as skills. Browse
them with the tabs on /skills, or call codexguild_skills_search with kind: "subagent" | "command" | "hook" | "all".
- Subagents and commands are single files. Their install command downloads the exact commit that was scanned
into
.claude/agents/or.claude/commands/. - Hooks run shell commands on every matching event, so they are never installed automatically. The registry
links the reviewed file, and you merge its
hooksinto.claude/settings.jsonyourself after reading it. For a plugin's hooks, the scan covers the whole plugin folder, including the scripts the hooks call.