Public GitHub · Static pre-install scan

Inspect an agent skillbefore it runs.

Paste a public GitHub repository, folder, or file URL. Longxia reads supported text files, maps risky capabilities, and shows the exact evidence. Repository code is never executed.

Public repositories only · 10 anonymous scans per day

Reports expire after 30 days

Instructions + code

Scans SKILL.md, scripts, manifests, and supported configuration files together.

Zero execution

Downloaded content is treated as untrusted text and never run by the scanner.

Evidence, not a badge

Every finding includes the source file, line, evidence, and a practical remediation.