by fangcunai · v0.0.10
SkillWard enables security review of AI Agent Skills and MCP projects before they are published or deployed, reducing the potential risks of Agent usage. Beyond static analysis and LLM evaluation, it executes suspicious Skills in isolated Docker sandboxes, replacing uncertain warnings with runtime evidence.
This community listing does not yet include every recommended support, privacy, pricing, and permission disclosure. Review the available package permissions before installing.
Available inside your emploidai workspace after installation.
Available inside your emploidai workspace after installation.
Author: Fangcun-AI Version: 0.0.10 Type: Tool plugin
SkillWard scans AI Agent Skills and MCP projects before they are published or deployed. This Dify tool plugin connects a Dify workflow to a running SkillWard Sentinel service and returns a structured security report.
This Marketplace release focuses on one stable workflow: provide a Skill or MCP source from Dify and scan it through the hosted SkillWard Sentinel backend.
Version 0.0.10 exposes the scan_skill_archive tool only.
The tool accepts exactly one source: an uploaded Skill/MCP .zip archive or one URL. The plugin forwards uploads as file with target_type=package, and forwards URLs as target with the selected target_type to the SkillWard Sentinel /api/scan/archive endpoint.
SkillWard is under active development. A major update is planned after this initial Marketplace release. The next major version is expected to improve the hosted scanning workflow and provide a more polished security report experience.
Configure the provider credential:
llm_api_key: OpenAI-compatible API key required by SkillWard Sentinel.llm_base_url: OpenAI-compatible API base URL.llm_model: Model name.llm_api_version: Optional API version for providers that require one.The hosted SkillWard Sentinel endpoint is built into the plugin and does not need to be configured in Dify.
Add the Scan Skill Source tool to a Dify Workflow, Chatflow, or Agent.
Provide exactly one scan source:
archive_file: A single uploaded Skill/MCP .zip archive. The backend automatically detects whether it is a Skill or MCP project.target_url: A Git repository URL or remote MCP URL.url_type: Required when target_url is provided. Use git_repo for Git repositories or remote_mcp for remote MCP URLs.archive_file and target_url are mutually exclusive. Exactly one of them is required.
Expected scan options:
use_llm: Whether to enable SkillWard LLM safety evaluation.use_runtime: Whether to enable Docker sandbox runtime verification.enable_after_tool: Whether to enable post-runtime tool-chain analysis.lang: Report language, en or zh.Expected output:
summary: A short human-readable scan summary.report: The full structured SkillWard scan report.verdict: The SkillWard verdict, such as SAFE or UNSAFE.skill_name: Name of the scanned Skill when available.error: Error details when the scan request fails.With the hosted SkillWard Sentinel backend, MCP security scanning, model evaluation, and Docker sandbox runtime checks run in the SkillWard API service. They do not run inside the Dify plugin process.
The Dify plugin only packages the request, sends it to SkillWard Sentinel, and returns the result to the workflow.
If you are testing against a local SkillWard backend, start guardian-api first:
cd /path/to/SkillWard/guardian-api
python guardian_api.py --port 8899
Verify the service:
curl http://localhost:8899/api/health
Then configure the required LLM credentials in Dify.