Connect Clawsmith to your coding agent. Ship products like crazy.Unlimited usage during betaGet API Key โ†’
โ† Back to dashboard
clawsmith.com/signal/skillfortify-formal-verification-ai-agent-skills
๐Ÿ“ˆ TrendsUnknownSecurityLive

SkillFortify: First Formal Security Scanner for AI Agent Skills โ€” 22 Frameworks, 0% False Positives

Open-source tool that mathematically proves agent skills cannot exceed declared capabilities. Achieves 96.95% F1 score with 0% false positives on 540-skill benchmark. Backed by peer-reviewed research with five formal theorems.

Product Idea from this Signal

A security layer that vets ClawHub skills for malware and prompt injection before your agent installs them

79.8k โ–ฒ

ClawHub grew 380% to 13,729 skills in Q1 2026. Snyk found 36% contain prompt injection and 1,467 carry malicious payloads. The ClawHavoc campaign planted 1,184 weaponized skills in the marketplace. VirusTotal integration catches known malware but misses novel prompt injection, data exfiltration via tool outputs, and social engineering patterns unique to AI agent skills. This tool performs deep behavioral analysis of every skill before installation, catching threats that signature-based scanners miss.

SECURITYCLIDEVTOOLOPEN-SOURCE
CompetitiveView Opportunity โ†’

Score Breakdown

GitHub
550
HN
350

Frequently Asked Questions