Rate a skill

Grade a skill before your agents run it.

Paste a URL or its SKILL.md. We attack it for prompt injection, data leakage and excessive agency, then grade it A to F with the evidence and the fix.

We fetch the skill's SKILL.md from the URL. It only ever runs inside our test harness.

Have the file but not a public URL? Upload it directly.

Your grade appears on the result page when it's ready. Sign in to also get it by email.

How it works ↓

How it works

Paste a skill, get a graded verdict

1

Paste a skill

A URL, or its SKILL.md file.

2

We attack it

Injection, data-leak, excessive agency, each mapped to the standards your auditors recognize.

3

You get the receipts

An A to F grade with the evidence quoted and the exact standard clause behind every finding.

A real SkillGrade report

Every finding cites the standard behind it

C
A document-processing skill

anonymized example · public attestation

Finding. Occasionally reproduced an instruction hidden in the content it processed, in 3 of 32 trials, instead of ignoring it.

How to fix. Treat fetched content as untrusted data, not instructions; strip embedded directives before acting on them.

Cited standard: OWASP LLM01 · Prompt Injection · measured over 32 trials · guidance, not a guarantee

Grade → Fix → Monitor

We don't just grade it, we tell you how to fix it

Grade

An independent A to F rating with the evidence quoted and the exact standard behind every finding.

Fix

Concrete remediation guidance on every finding, and free re-tests to confirm the fix and work your way to an A.

Monitor

Re-tested on every change, and when the standards move; alerted the day a grade drops.

Rate pricing

Simple, flat pricing

No credits. No metered bills.

Free check
$0
A fast screen and a grade.
  • Injection, leak, agency and more
  • Public result page + evidence
  • No account needed
Check a skill
Monitoring
$29 / month
Re-tested on every change; alerted the day a grade drops.
  • Re-tests when the skill changes
  • Regression alerts by email
  • Cancel anytime
Start monitoring

We only ever run a skill inside our test harness. We never execute skill code, and never generate media.

Get the State of AI Skill Security report

What we're measuring across the skills people actually run — the common failure modes, by the numbers. One email when it's out. No spam, unsubscribe anytime.