---
name: multi-agent-scan
language: en
description: "Skill security scan: walks local skill directories against a tiered pattern catalog. Use when local skill directories need checking for unsafe or unexpected content."
user-invocable: true
argument-hint: "[--strict] [--target <path>]  -  optional: --strict enables CI failure mode, --target picks a custom directory"
---

# multi-agent-scan

Single command  -  scans `pipeline/skills/` (or `~/.claude/skills/`, `~/.copilot/skills/`) for security patterns. Catches the case where a teammate unknowingly pulls a third-party malicious skill, or corrupted content slips in during a sync. **Warn-only by default** (always exit 0)  -  use `--strict` for CI.

## Usage

```bash
# Default: warn-only, threshold=medium
multi-agent-scan

# CI-grade: non-zero exit code if there are findings
multi-agent-scan --strict

# Critical + high only
multi-agent-scan --threshold high

# JSON (automation)
multi-agent-scan --json

# Verify the installed tree
multi-agent-scan --root ~/.copilot/skills
```

## Severity catalog

| Tier | Detects |
|------|-----------|
| 🚨 critical | Shell-pipe exec (curl\|bash), base64-decode exec, eval-of-network, unicode bidi override |
| ⚠ high | JS `eval()`/`new Function()`, Python `exec()`/`eval()` (except re.compile + subprocess), hardcoded credential, pastebin/bit.ly raw fetch, chmod+exec chain |
| ⓘ medium | Long base64 blob (>200 char)  -  executable files only (.sh/.py/.js) |
| · low | Unknown network endpoint, missing SKILL.md frontmatter |

## Steps

1. Run the script:
   ```bash
   bash "$HOME/.claude/scripts/scan-skills.sh" $ARGUMENTS
   ```

2. Interpret the output:
   - `critical=0 high=0 medium=0 low=0` → ✓ clean
   - If critical/high → inspect the file, roll back the skill if needed
   - Medium/low → informational

3. Strict exit codes: 0 clean · 1 critical · 2 high · 3 medium · 4 low

## Integration

- **install.js** pre-deploy hook (automatic, warn-only high-threshold)
- **CI** `.github/workflows/smoke.yml` step (strict)
- **Standalone** this skill

Cross-CLI parity: `/multi-agent:scan` on Claude Code, `multi-agent-scan` on Copilot CLI. Same source script, same behavior.
