Vol. I · No. 01Skill Scanner
Skill Scanner — free while in beta

Doesthisskillbehavelikeitsaysitdoes?

Most agent skills are dropped into a workspace and trusted on the strength of a one-paragraph SKILL.md. Novingly reads what they actually do — the shell calls, the network requests, the file writes, the secrets they reach for — and gives a short, honest report on whether the behavior matches what the skill says about itself.

Paste any public GitHub URL. We read it like a careful reviewer reads code: with the assumption that something interesting is hiding. A 0–100 trust score, line-level reasoning, and a permanent shareable report.

01

What it actually does.

Static analysis flags shell-exec, network calls to non-public hosts, file writes outside declared scope, obfuscated strings, and unpinned dependencies. Then a Claude pass reads the SKILL.md against the handler code and calls out what doesn't match.

02

A score, not a verdict.

Skills get a 0–100 trust score with the reasoning shown — line-level, not vibes. Not a pass/fail. The reader decides if that one network call to api.example.com is a feature or a leak.

03

Verified by Orion.

Skill authors who score above 85 can claim a Verified badge to embed on their listing. A small fee covers re-verification each quarter; the public scan stays free for everyone.

Recently scanned

The skills we’ve read this week.

See the full index →
  1. I
    DeepBitsTechnology/claude-plugins
    github.com/DeepBitsTechnology/claude-plugins
    100
  2. II
    openclaw/openclaw
    github.com/openclaw/openclaw
    100
  3. III
    Agents365-ai/drawio-skill
    github.com/Agents365-ai/drawio-skill
    100
  4. IV
    jzOcb/writing-style-skill
    github.com/jzOcb/writing-style-skill
    100
  5. V
    kevin0x5/elasticsearch-insight-store
    github.com/kevin0x5/elasticsearch-insight-store
    100
Sister desks

More from Novingly.

Get early access

Want a Verified badge for your skill?

We’re launching the Verified badge program this week — a public signal that your skill does exactly what it says. Drop your email and we’ll ping you when paid tiers go live.

No spam. Just the invite when Novingly is ready.