{"repo":"spiffy-oss/artguard","free":true,"listed":false,"github":"https://github.com/spiffy-oss/artguard","clone":"git clone https://github.com/spiffy-oss/artguard.git","description":"Open-source AI artifact scanner. Detect malicious agent skills, MCP servers, and IDE rule files before they run.","language":null,"stars":31,"topics":["ai-agent","ai-governance","ai-safety","ai-security","claude-code","cursorrules","mcp","prompt-injection","supply-chain-security","trust-score"],"license":"MIT","category":"mcp-servers","readme_excerpt":"artguard A Claude Code prompt that autonomously scaffolds a full AI artifact scanner CLI. Paste the prompt into Claude Code and it builds artguard — a working Python CLI that scans agent skills, MCP server configs, and IDE rule files for security threats, privacy violations, and instruction-level attacks. The problem Enterprises are installing AI agent skills, MCP servers, and IDE rule files ( .cursorrules , .clinerules , .windsurfrules ) with zero security review. No existing scanner covers them. Traditional scanners are built for code packages. AI artifacts are hybrid — part code, part natural language instructions — and the attack surface lives in the instructions themselves. A YARA rule won't catch a skill that tells your coding agent to approve vulnerable PRs. Static analysis won't surface an artifact that claims \"no data stored\" while writing to disk. What artguard scans Artifact Type Examples --- --- Agent skill files skills.md , skill.json , tool definitions MCP server configs mcp.json , server manifests IDE rule files .cursorrules , .clinerules , .windsurfrules Plugin manifests manifest.json , API schemas Three detection layers Layer 1 — Privacy posture analysis (differentiator) Detects the gap between what an artifact claims to do with your data and what it actually does. Undisclosed storage, covert telemetry, third-party sharing, retention policy mismatches. Layer 2 — Semantic instruction analysis (differentiator) LLM-powered detection of behavioral manipulation, p","default_branch":null,"files":null,"tree":[],"storefront":"/r/spiffy-oss","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/spiffy-oss/artguard/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}