{"repo":"HuTa0kj/vetix","free":true,"listed":false,"github":"https://github.com/HuTa0kj/vetix","clone":"git clone https://github.com/HuTa0kj/vetix.git","description":"Vetix — Automated scanning, identification, and assessment of SKILL security risks.","language":"Python","stars":61,"topics":["agent","agent-skills","agents","llm-agent","llm-security","llm-tools","skill","skill-security","skills","claude-code"],"license":"MIT","category":"ai-agents","readme_excerpt":"Vetix An LLM-agent-based scanner for SKILL directories. Vetix pairs deterministic plugin rules with an LLM behavioral analyst so that both obvious indicators of compromise and subtle, obfuscated attack chains get caught in a single pass. 中文文档 Features - Plugin-based static scanning — rules catch deterministic security risks. - LLM cross-validation — every plugin hit is re-judged against the real file content by an LLM, so high-recall rules don't drown the final report. - Behavioral analysis agent — inside a virtual filesystem, traces the full chain \"instruction → tool call → host impact\" to uncover risks the rules miss: disguised commands, Base64 payloads, remote code loading, prompt injection, credential theft, persistence, and more. - Defense-in-depth sandbox — virtual filesystems, explicit read allow-lists, and a blanket write deny isolate the real host. - LangSmith tracing — every agent run is observable end-to-end. Detection Categories The behavioral analysis agent classifies risks into 10 categories: Category Description --- --- Remote Execution Remote code loading and execution, including curl\\ sh , wget\\ bash , and unofficial package installations Data Exfiltration Unauthorized collection and transmission of sensitive data to external addresses Persistence Backdoor mechanisms that survive reboots — crontab injection, SSH key planting, startup item modification Destructive Actions that corrupt data, delete files, or otherwise damage the host system Obfuscation Delibera","default_branch":null,"files":null,"tree":[],"storefront":"/r/HuTa0kj","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/HuTa0kj/vetix/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}