Public beta · Static pre-install security

Know what youragent can do.

Longxia scans source and instruction files from public GitHub agent skills before they touch your machine. The scanner never executes repository code.

No credit cardEvidence-backed findingsPublic scans stay free

Sample skill risk report

openclaw/research-agent · v2.4.1

Blocked

Risk score

82/ 100
FILES24
RULES127
SCAN TIME4.8s

3 actionable findings

Hidden shell execution

scripts/install.sh · line 42

Critical

Unscoped credential access

SKILL.md · tool permissions

High

Remote content injection

references/setup.md · external URL

High

Illustrative preview. Open the real report to review source evidence from the Git commit actually scanned.

STATIC RULESET · SAMPLE DATAONLINE

Supported source and instruction formats

SKILL.mdAGENTS.mdpackage.jsonpyproject.tomlShell scriptsYAML + TOML

The missing trust layer

Agents install trust at machine speed.

A skill is more than code. It is instructions, dependencies, permissions, and live access to your files and accounts. A clean repository can still teach an agent to do something dangerous.

Instructions

Natural-language files can ask an agent to ignore boundaries or hide behavior.

Commands

Install scripts can execute remote payloads, read secrets, or modify broad filesystem locations.

Dependencies

Unpinned packages and downloads can change what eventually reaches the machine.

Read Snyk Agent Scan research

What the public beta does

Security that speaks agent.

Longxia combines instruction and source-pattern checks, then exposes the evidence. It is a narrow pre-install review tool, not runtime protection.

01 · SCAN

Inspect before install

Analyze instructions, scripts, dependencies, and tool calls as one attack surface—not isolated files.

02 · MAP

See the real blast radius

Turn vague manifests into a plain-English map of files, secrets, services, and commands a skill can reach.

03 · TRACE

Review the evidence

See the rule, file, line, source excerpt, severity, and practical remediation behind every finding.

04 · SHARE

Share one point-in-time report

Send an unlisted report tied to the exact Git commit. Reports remain available for 30 days.

Simple by design

From unknown to understood.

A security decision your developer, IT lead, and founder can make from the same report.

01

Paste

Enter a public GitHub repository, folder, or file URL.

02

Analyze

Longxia evaluates code, natural-language instructions, and permissions together.

03

Review

Use the risk score, capability map, and source evidence to decide what to inspect next.

Zero execution by design

Fetched files are size-limited, parsed as text, and never run or installed by Longxia.

Source-only boundary

Real public scans

Three skills. Three different decisions.

Each case is a point-in-time static scan of a public GitHub source. Open the report to inspect its commit, files, rules, evidence, and remediation.

  • BlockedRisk score 49 / 100

    openai/skills · sentry

    A remote installer should stop the install.

    The instructions pipe a downloaded installer directly into Bash. Verify the source and checksum before proceeding.

    Findings
    2
    Commit
    49f948faa925
    Open blocked report
  • ReviewRisk score 24 / 100

    anthropics/skills · webapp-testing

    Local command execution needs review.

    Two Python calls start or run local commands. That may be intentional for testing, but the capability deserves human review.

    Findings
    2
    Commit
    b29e7cf65e5c
    Open review report
  • PassRisk score 0 / 100

    vercel-labs/agent-skills · web-design-guidelines

    No known high-risk pattern matched.

    This one-file instruction skill triggered no current rules. A pass is a review starting point, never a safety guarantee.

    Findings
    0
    Commit
    7c180d9044c9
    Open pass report

Results describe exact commits and the Longxia ruleset at scan time. A verdict is not a malware classification or endorsement; project names identify public sources only.

Public beta access

Start with one public skill.

The implemented scanner is free while Longxia validates the workflow with real users. There is no checkout or paid plan today.

Available now

Public scanner

For reviewing public GitHub agent skills before installation.

  • 10 anonymous scans per day
  • Repository, folder, and file URLs
  • Capability map and source evidence
  • Shareable reports available for 30 days
Scan a public skill

Roadmap · Not yet available

Private and team scanning

Longxia is evaluating local/private source analysis, update monitoring, policy gates, and team workflows. No pricing has been announced.

  • Private repositories and local bundles
  • Commit and permission drift monitoring
  • CI checks and organizational policies
Request early access

FAQ

Good questions are a security feature.

Longxia is early, direct, and transparent about what agent security can—and cannot—do.

What does Longxia scan?+

The public beta scans supported text files in a public GitHub repository, folder, or file. That includes Markdown instructions, JavaScript and TypeScript, Python, shell and PowerShell, JSON, TOML, YAML, manifests, and common lockfiles.

Is this only for OpenClaw?+

No. Longxia looks for risky behavior in source and instruction files, so the same scan can help review repositories made for OpenClaw, Claude Code, Codex, Cursor, or another agent. It does not claim full runtime coverage for those platforms.

Can I scan a private repository?+

Not in the current public beta. Longxia accepts only public GitHub URLs and has no account or GitHub authorization flow. Private and local scanning are roadmap items, not available features.

Can a scan guarantee a skill is safe?+

No. Longxia is a rule-based, point-in-time static scan. It can miss malicious behavior and can produce false positives. Use the report as evidence for manual review, sandboxing, least privilege, and other security controls.

Your agent moves fast.Trust should keep up.

Scan your first agent skill free and see exactly what you are about to trust.

Public GitHub only · 10 scans per day · Reports expire in 30 days