SkillTracer
Live sandboxAI Vulnerability Scoring System (AIVSS)OWASP Agentic Top 10

Skills lie.
We stop that.

Metano observes what a skill actually does at runtime, what it accesses, what tools it calls, and what data it sends. It then compares those actions to the skill's stated purpose and the user's intent. Any mismatch is alerted.

Open methodology · Reproducible scoring · No card required
AI Threat score and Risk score
Static and dynamic analysis
OWASP Top 10 mapped
Leading industry models

The only scanner that runs the skill.

Existing tools check what a skill says. SkillTracer checks what it does - by detonating every skill in an instrumented sandbox, across multiple models at once, and reporting what each one actually did.

Dynamic detonationActually runs the skill, not just reads it
MetanoSkillTracerYes
NVIDIASkillSpectorNo
CiscoAI DefenseNo
OthersPartial
Multi-model detonationOne skill run against many models at once
MetanoSkillTracerYes
NVIDIASkillSpectorNo
CiscoAI DefenseNo
OthersNo
Agentic-threat awareUnderstands skill / agent attacks, not just malware
MetanoSkillTracerYes
NVIDIASkillSpectorYes
CiscoAI DefenseYes
OthersPartial
Runtime egress + honeytokensEgress proxy, canary credentials, runtime trace
MetanoSkillTracerYes
NVIDIASkillSpectorNo
CiscoAI DefenseNo
OthersPartial
Scans MCP servers
MetanoSkillTracerPartial
NVIDIASkillSpectorYes
CiscoAI DefenseYes
OthersPartial
Open, reproducible AIVSS scoreRecompute the number yourself
MetanoSkillTracerYes
NVIDIASkillSpectorNo
CiscoAI DefenseNo
OthersNo
Public report / feed
MetanoSkillTracerYes
NVIDIASkillSpectorNo
CiscoAI DefenseNo
OthersPartial
Free to use
MetanoSkillTracerYes
NVIDIASkillSpectorYes
CiscoAI DefensePartial
OthersPartial
MetanoSkillTracerNVIDIASkillSpectorCiscoAI DefenseOthers
Dynamic detonationActually runs the skill, not just reads itYesNoNoPartial
Multi-model detonationOne skill run against many models at onceYesNoNoNo
Agentic-threat awareUnderstands skill / agent attacks, not just malwareYesYesYesPartial
Runtime egress + honeytokensEgress proxy, canary credentials, runtime traceYesNoNoPartial
Scans MCP serversPartialYesYesPartial
Open, reproducible AIVSS scoreRecompute the number yourselfYesNoNoNo
Public report / feedYesNoNoPartial
Free to useYesYesPartialPartial

Static scanners pattern-match the text and never run it. SkillTracer is the only open, reproducible, multi-model detonation. See a live report →

Submit an artifact, get a verdict.

A live detonation flow for the agent ecosystem - built to be transparent end to end.

1

Submit

Drop a SKILL.md (or a folder of skills). No install - nothing runs on your machine.

2

Detonate

We run it in an instrumented, default-deny sandbox seeded with honeytokens - on our infra, not yours.

3

Analyze

Deterministic heuristics plus a Claude scan map behavior to the OWASP Agentic Top 10 and MITRE ATLAS.

4

Verdict

A reproducible, Threat score and AIVSS-aligned Risk score with evidence-quoted findings - shareable as a public report.

What SkillTracer checks.

Deterministic heuristics plus a Claude-graded rubric. Every finding maps to an OWASP Agentic Top 10 or MITRE ATLAS code.

Credential & secret access

Hardcoded API keys (AWS, OpenAI, GitHub, Slack), keychain reads, and env-var harvesting.

ASI06

Data exfiltration

Env vars, files, or conversation history sent to external or raw-IP endpoints.

MCP10

Prompt injection & override

Hidden or obfuscated directives, “ignore previous instructions”, host-agent hijack.

ASI01

Remote code execution

curl|bash fetch-and-run, eval of fetched content, and install-time side effects.

MCP04

Obfuscation

base64 blobs, zero-width / bidirectional Unicode, and homoglyphs that hide behavior.

ASI01

Excessive capability

Permissions out of proportion to the stated purpose - a “formatter” that reads ~/.ssh.

ASI03

Tool & MCP poisoning

Malicious behavior hidden inside tool / skill descriptions.

MCP03

Deception & destructive ops

Description-vs-body mismatch, suppressed logging, mass-delete without confirmation.

ASI09

Dynamic today.
Broader coverage next.

Shipped

Dynamic, multi-model detonation

Every skill is run in an instrumented sandbox - runtime tracing, an egress proxy, and credential honeytokens - against multiple models at once, so you see what each one actually did.

Shipped

Open AIVSS scoring + public feed

Reproducible 0-10 scores, evidence-backed findings mapped to OWASP Agentic / MCP, shareable public reports and README badges.

Coming soon

More artifacts + CI

MCP servers and agent plugins; a CI GitHub Action that fails the build on score > threshold.

Detonate your first skill.

It runs on our infrastructure, in a real sandbox. You just drop a file.

All product names, logos, and trademarks are property of their respective owners.
References to these names, logos, and brands are for identification purposes only and do not imply endorsement.

Get In Touch