Skip to main content

bastionskill

Static scanner for skill-poisoning. Point it at an agent skill (a SKILL.md plus its bundled scripts) and it inspects the bundled executable code for malicious behavior — then reports the shadow: what the code does that the skill's description never declared.

Agent skills bundle scripts that run when the skill is invoked, and can install hooks that run afterward. That is an arbitrary-code-execution surface. bastionskill is the code-layer leg of the bastion suite; the prompt-layer (malicious SKILL.md text) is bastionsupply's job.

Install

pip install bastionskill
# optional: full prompt-layer scanning via bastionsupply
pip install "bastionskill[prompt]"

Zero required dependencies. Python 3.10+.

Use

bastionskill scan ./some-skill              # scan a local skill dir
bastionskill scan ~/.claude/skills          # batch-scan every skill under a dir
bastionskill scan owner/repo                # pre-flight a REMOTE skill (shallow clone, no exec)
bastionskill scan https://github.com/o/r    #   ... by full URL
bastionskill scan ./skill --prompt          # + hidden-unicode / prompt-layer
bastionskill scan ./skill --json            # machine-readable
bastionskill scan ./skill --report out.json # signable manifest (per-file hashes, verdict)
bastionskill scan ./skill --record          # append result to the local ledger
bastionskill scan ./skill --fail-on block   # CI gate: block|review|none (default: review)
bastionskill harden ./skill -o skill-policy.yaml   # v2 verdict(s), pinned by digest
bastionskill install owner/repo --to ~/.claude/skills   # install only if it passes
bastionskill install ./skill --to ~/.claude/skills --policy skill-policy.yaml
bastionskill ledger                         # list previously scanned skills + dates

install: the gate that enforces the verdict

install copies a skill into a skills dir (~/.claude/skills, or a project's .claude/skills) only if it passes. It stages the copy first and scans and hashes that copy, so the verdict covers exactly the bytes installed.

  • No policy: the scan decides at --fail-on (default review).
  • --policy (a harden file): a deny matching the skill's name or digest refuses it. An allow counts only through its digest, the sha256 of every file installed: a reviewer can approve a skill the scanner rates review by flipping its entry to allow, and that approval covers those exact bytes only. If the skill changes (a rug-pull), the allow no longer matches and the scan decides again.
  • A folder of skills installs all-or-nothing. The skill's own .bastionskillignore is not honored here (the author can't hide files from the check that admits them), symlinks are refused, and an existing install needs --force.

harden on a folder writes one verdict file for every skill in it; names that collide (nested copies) are keyed by their path.

Verdict, not a wall of severities

The scan ends in one of three verdicts, because capability is not malice — a legit power-tool exercises network, secrets, and hooks too:

  • allow — clean, or capability the skill legitimately has (even a lot of it).
  • review — a poisoning signal a human should eyeball: a shadow (the code exercises a capability SKILL.md never declared), obfuscation, an opaque binary, or the exfil pattern (reads secrets and has egress).
  • block — hard malice with no honest use: a staged-exec (decode piped to a shell).

Capability findings are reported as informational context, not as blockers. --fail-on (block|review|none, default review) is the CI gate. See docs/github-action.md.

--sarif emits SARIF 2.1.0 (file + line per finding) for GitHub code scanning:

- run: bastionskill scan ./skill --sarif > bastionskill.sarif
  continue-on-error: true
- uses: github/codeql-action/upload-sarif@v3
  with:
    sarif_file: bastionskill.sarif

Remote pre-flight shallow-clones the repo to a temp dir, scans statically, and deletes it. The skill's own code is never executed.

Ledger & rug-pull. --record writes each scan to ~/.bastionskill/ledger.jsonl (source, content hash, date, verdict). Re-scan the same source after it changes and you get a ! DRIFT warning — the poisoned-update vector.

What it catches (code-layer)

Detector Example
hook-install (lead) a script that writes a PostToolUse hook into settings.json = persistence
network egress socket.connect, requests.post, curl/wget, fetch()
secret read ~/.aws/credentials, id_rsa, .env
obfuscation `base64 -d
dynamic exec exec(), eval(), getattr(m,n)() (Python AST tier)
destructive rm -rf, Remove-Item -Recurse
lateral-tamper writes to CLAUDE.md, MCP config, or other skills
opaque-binary bundles a compiled/loadable file it can't inspect (incl. renamed binaries, magic-byte sniffed)
shadow code exercises a capability SKILL.md never declared

Python files get a real ast pass (stdlib) on top of regex, so dynamic exec / import / attribute-built calls survive reflow. Bash and JS use regex heuristics.

Findings are reported regardless of dead-code or if False: / env-flag guards — the scanner reads source, it never runs it, and malware hides behind guards too.

How it fits the suite

  • Prompt-layer → bastionsupply (dependency, optional extra)
  • Runtime gating → bastiongate
  • harden emits a policy_version: 2 skill verdict (allow/deny, the checks and capabilities that tripped it, and a content digest) under the skill: block; bastionskill install --policy enforces it. agentbastion and bastiongate don't run skills: they load the file, ignore the block, and get no tool policy from it.

Test fixture

The inert, defanged demo skill this scanner is built against lives at Rinkia/poisoned-skill-demo — a "markdown formatter" that actually exfiltrates and installs a hook. See its EXPECTED.md for the findings oracle.

bastionskill scan Rinkia/poisoned-skill-demo   # scan the demo straight off GitHub

License

MIT © 2026 Stefano Rizzello

Metadata

Release files for bastionskill 0.5.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for bastionskill 0.5.0
File Size Uploaded
bastionskill-0.5.0.tar.gz 37.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for bastionskill 0.5.0
File Interpreter ABI Platform
bastionskill-0.5.0-py3-none-any.whl Python 3 none any Details

Total release size: 70.1 kB

Release files / bastionskill-0.5.0.tar.gz

Download URL bastionskill-0.5.0.tar.gz
Size 37.2 kB
Tags Source
SHA-256 checksum
How to use checksums
937a31f2c3249b79b25a3bfbc5e0309af5616e92d9af83f20c6257e6dfda9fe4
BLAKE2b-256 checksum
How to use checksums
737afd49764eb7a6ff4fa158fca93f1a71c5596523cd25ca9f53854bf4df0255
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.

Transparency log

Release files / bastionskill-0.5.0-py3-none-any.whl

Download URL bastionskill-0.5.0-py3-none-any.whl
Size 33.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
dbcb6f83d601a4750ddd2d158cd14c401e9160b31889b68d5b8afd5613fa86c0
BLAKE2b-256 checksum
How to use checksums
0819b797f6b77a7dd9b5acf06d15860693a1aabfae5cbaee62486bccfe906411
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.

Transparency log

Release history Release notifications | RSS feed

0.9.0

2 release files

0.8.0

2 release files

0.7.0

2 release files

0.6.0

2 release files

This release

0.5.0 This release

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page