A public, free, open-source security-scanning service for AI agents and the capabilities they run. We index them. We audit them. We scan the whole running agent. We publish the report.
AI agent skills, MCP servers, hooks, and plugins have exploded across eight platforms in eighteen months. There is no shared audit, no shared methodology, no shared trust signal. Every install is a leap of faith — and the data we have suggests that faith is misplaced.
SaferSkills is the answer to that gap. Anyone submits a public GitHub URL; thirty seconds later, a deterministic security report appears at a permalink. The same open methodology also scans the whole running agent — not just the pieces it installs. The rules are open. The methodology is open. The findings cite a rule ID and a line of evidence. Vendors get a right-of-reply on every public verdict.
Think VirusTotal, but for AI agents — audit the pieces, scan the whole agent.

20+ years in cybersecurity and enterprise infrastructure. Previously: CTO Ailevate · VP of Engineering Tenable (NASDAQ: TENB) · Co-Founder + CTO Alsid, identity security company acquired by Tenable. Deep background in identity security, attack-path analysis, and runtime enforcement.
Email is the right channel for security disclosures, press, partnerships, and methodology proposals. Each address routes to a real person, not a contact-form queue.
Our community Slack — the openlatch-community workspace — is a shared-stewardship space co-hosted with OpenLatch. It is a disclosed shared surface, alongside the footer attribution and the sending domain above; the scanning service itself stays brand-independent.
Audit the pieces. Scan the whole. Decide. ~30 seconds. Free. No account. The report URL is bookmarkable and persists for 90 days.