Safeskill
ThreatBook's scanner for AI agent skills and MCP servers
Overview
SafeSkill is ThreatBook's security scanner for the AI agent era: it inspects agent skills and MCP servers for prompt injection, data exfiltration and malicious code before installation, and runs a curated marketplace of scanned, badged skills.
Pricing
Pricing shown for reference only. These figures reflect RECATOOLS research as of 11 Jul 2026 and may be out of date or incomplete. This is not financial or purchasing advice — always confirm the current price on the provider’s official website before making any decision.
Use cases
ASEAN Perspective
Safeskill in Southeast Asia
ASEAN-region availability and pricing notes coming soon. Drop the editorial team a note via /contact/ if you can supply local context (Singapore/Malaysia/Indonesia/Thailand/Vietnam).
SafeSkill scans AI agent skills and MCP servers for prompt injection, data exfiltration and malicious code before installation, and pairs the scanner with a badged marketplace of verified skills. Launched by ThreatBook in May 2026 as part of its agentic-security relaunch, it targets a real gap as skill supply-chain attacks emerge, and ThreatBook's APAC footprint is useful for ASEAN buyers wanting regional support. It is only months old: no independent efficacy testing, thin pricing transparency, and free open-source rivals (Snyk's agent-scan, Cisco's IDE scanner) are already circling. Worth piloting for teams deploying agents at scale; too early to make it a standing dependency.
What people say
Snyk gives away an open-source scanner for AI agent skills; Cisco ships one inside the IDE. SafeSkill, launched by ThreatBook in May 2026, is betting enterprises will pay for the managed version: a multi-layered analysis engine that inspects agent skills and MCP servers for prompt injection, data exfiltration, malicious code and supply-chain tampering before they're installed, plus a curated marketplace where every listed skill is scanned, scored and badged. ThreatBook claims a hub of more than 100,000 verified skills.
The pipeline is more than a YARA pass: metadata extraction, pattern rules, AST analysis, a local small-model intent check, LLM intent analysis, URL threat-intelligence correlation, and sandbox execution for sub-file inspection. It launched alongside Flocks, ThreatBook's agentic SOC product, as part of a full company relaunch around agentic AI security. The problem it targets is real — skill tampering that hijacks identities, steals API secrets or plants backdoors is exactly the supply-chain channel attackers are moving into as agent adoption spreads.
What's missing is evidence. There's no independent efficacy testing, no meaningful user-review base, and no public pricing; detection-quality claims can't be verified from the outside yet, and the category is filling fast. ThreatBook's regional presence is a genuine plus for APAC and ASEAN teams that want local support. Treat it as a pilot candidate if you're deploying agents at scale, and re-evaluate once field results and third-party testing exist. One housekeeping note: this has nothing to do with the identically named workplace-safety training outfits.
Summary of public user & expert reviews, compiled by RECATOOLS.
Notable facts
- Research shows that adaptive security training reduces employee click rates on phishing simulations by 85% compared to generic annual training modules.
- Safeskill's AI analyses 50+ signals per employee including quiz scores, simulation performance, and training completion velocity to build each person's unique risk profile.
- The platform can reduce the time employees spend on mandatory security training by 60% by eliminating content they have already mastered.
Frequently asked questions
About this listing
This entry was compiled from publicly available data including Safeskill's official website, press releases, documentation, and reputable third-party publications. RECATOOLS is not affiliated with Safeskill unless explicitly stated.
Third-party AI tools update their pricing, features, availability, and policies frequently. Information here may be outdated by the time you read this — we make reasonable efforts to keep listings current, but cannot guarantee absolute accuracy.
For the latest details, please refer to Safeskill directly →
Spotted something out of date? Suggest an update →
Alternatives to Safeskill
More in Security & Safety