emploidai Marketplace

skillward privacy policy

Policy content supplied in the product package by its publisher.

← Back to skillward

Privacy

English

This plugin sends one Agent Skill or MCP project source, the selected scan options, and the configured LLM API settings to the SkillWard Sentinel endpoint built into the plugin. The source can be an uploaded zip archive, a public Git repository URL, or a remote MCP URL. For this Marketplace release, the plugin calls the SkillWard Sentinel /api/scan/archive endpoint only.

The selected source may contain SKILL.md, related Skill files, or MCP project files. For URL-based sources, the plugin forwards the URL as target and marks it with the matching target_type. The SkillWard backend receives the source, scans it, and returns a structured security report to Dify.

Uploaded archives and extracted files are used only for the requested scan. They are not published, shared, sold, or redistributed by the plugin. Temporary working files created for extraction and scanning are removed after the scan finishes.

Depending on the scan target and options selected by the user, the hosted SkillWard backend may run Skill security scanning, MCP security scanning, LLM-based safety evaluation, and Docker sandbox runtime verification. The configured LLM API key, base URL, model name, and optional API version are sent to the SkillWard backend for the requested scan. Relevant Skill or MCP project content may be sent to that model service for the purpose of producing the security assessment.

The plugin does not store API credentials, uploaded files, or scan results in the Dify plugin package. The hosted SkillWard service may keep operational logs needed for service reliability and abuse prevention, such as request time, status code, latency, and error information. These logs are not intended to contain the full uploaded archive or full LLM API key.

Do not upload private, proprietary, regulated, or otherwise restricted materials unless you are authorized to do so and the configured SkillWard API service is approved for that data.

If you need deletion support for data handled by a hosted SkillWard endpoint, contact the SkillWard service provider through the source repository or your Fangcun-AI contact.

简体中文

此插件会将一个 Agent Skill 或 MCP 项目来源、所选扫描选项以及配置的 LLM API 设置发送到插件内置的 SkillWard Sentinel 地址。来源可以是上传的 zip 压缩包、公开 Git 仓库 URL,或远程 MCP URL。此 Marketplace 版本只调用 SkillWard Sentinel /api/scan/archive 接口。

所选来源可能包含 SKILL.md、相关 Skill 文件或 MCP 项目文件。对于 URL 来源,插件会将 URL 作为 target 并附带对应的 target_type 转发。SkillWard 后端会接收该来源、完成扫描,并将结构化安全报告返回给 Dify。

上传的压缩包和解压后的文件只用于本次扫描。插件不会发布、分享、出售或转发用户上传的压缩包。用于解压和扫描的临时工作文件会在扫描完成后删除。

根据用户选择的扫描对象和扫描选项,托管版 SkillWard 后端可能会执行 Skill 安全扫描、MCP 安全扫描、LLM 安全评估和 Docker 沙箱运行时验证。用户配置的 LLM API key、基础地址、模型名称以及可选 API version 会被发送到 SkillWard 后端用于本次扫描。相关 Skill 或 MCP 项目内容可能会被发送到该模型服务,用于生成安全评估结果。

插件本身不会在 Dify plugin package 中存储 API 凭证、上传文件或扫描结果。托管版 SkillWard 服务可能会保留服务可靠性和防滥用所需的运行日志,例如请求时间、状态码、耗时和错误信息。这些日志不应包含完整上传压缩包或完整 LLM API key。

请勿上传私有、专有、受监管或其他受限材料,除非你已获得授权,并且所配置的 SkillWard API 服务被允许处理这些数据。

如果你需要删除托管版 SkillWard 端点处理过的数据,请通过源代码仓库或你的 Fangcun-AI 联系人联系 SkillWard 服务提供方。