Installing agent skills from GitHub shouldn’t mean skipping a safety check.
This is a dev post classified by Jev as Security (a tool drop), kept by the Dev Radar because it carries real work, not commentary.
Installing agent skills from GitHub shouldn’t mean skipping a safety check. RoleCraft is a security-first, zero-dependency CLI for managing AI-agent skills and MCP servers across supported agent setups. It helps you install and manage agent tooling with more visibility by running static security analysis on every install and supporting skills from several sources. Key features: • Security scoring – scans installs for prompt injection, command injection, obfuscated code, and credential harvesting • Flexible sources – install skills from a local folder, GitHub, GitLab, SSH URL, or npm packag
Posted by Dan Kornas (99.1k followers) 1 h ago · 4 likes · 626 views · view the original post on X. Kept by the Dev Radar as Security.
More dev work like this
- ICYMI: The Agentic SOC is getting some backup. — @splunk
- NEAR Co-Founder. LLM co-inventor. @ekang426 husband. — @NEARProtocol
- Your AI agent can run commands. It should not get a free pass. — @DanKornas
- Digital forensics investigations can stall in the handoffs. This repo keeps the evidence… — @DanKornas
- Pentest is not a workflow, It is a search problem. — @0x0SojalSec
- ‼️Security researcher MSNightmare has released a Windows Defender update Denial of… — @DarkWebInformer
- deGDID: Deletes all instances of Microsoft's GDID and prevents minting of new ones — @DarkWebInformer
- I just built the open-source version of this — @imarikchakma
Every post is read and classified by Jev (TypeSafe): what it is, which market it belongs to, and whether the link is a real tool. 16.1k posts from 4.9k X accounts over the last 21 days, 1.8k tools, 12 markets. Collected every 5 minutes, fully re-ranked every hour — last update 2026-09-20 19:24 UTC. Full method.