SkillVault: the scanned, sandboxed registry for agent skills and MCP servers
The problem
Agent skills and MCP servers are the new npm packages — except they arrive with shell access, credential access, and prompt-injection surfaces, and teams install them from random GitHub repos on vibes. ClawSecure's audit of 2,890+ OpenClaw skills found 41% with security vulnerabilities. Attackers have noticed: the Sandworm_Mode campaign specifically weaponized AI coding utilities, installing rogue MCP servers that exfiltrate SSH keys, AWS credentials, and LLM API keys via prompt injection. Supply-chain attacks now run continuously.
The idea
Why now
Three things arrived together: a scanner purpose-built for skills rather than code (ClawSecure, with its 41%-vulnerable finding across 2,890 skills), a sandbox with deferred-commit semantics (Sandlock 0.8.8 — review the blast radius, not just the code), and MCP's graduation from chat-tool protocol to first-class plugin platform (OpenAI MCP Extensions), which just 10x'd the attack surface. Sandworm_Mode is actively exploiting exactly this surface right now. The registry is the missing piece that binds scan, sandbox, and gateway.
What it combines
Four radar capabilities combine: (1) skill vulnerability scanning (ClawSecure) as the detection engine; (2) deferred-commit sandboxes (Sandlock) as the containment layer — every run returns a changeset and writes land only after review; (3) OpenAI MCP Extensions as the reason the surface just 10x'd — MCP is going mainstream; (4) single-gateway MCP (CoreSpeed) as the distribution-shaped hole — whoever controls the gateway controls the policy. The mix matters because scanning without enforcement is advice, and a sandbox without a registry is a one-off — bound together they are an install-time gate for the whole ecosystem.
MVP
Build: a CLI (skillvault install <repo>) that runs the ClawSecure-style scan, generates a permission manifest, and installs into a Sandlock-style deferred-commit sandbox where the user reviews the changeset. Skip: the hosted registry, ChatGPT MCP Extensions support, the enterprise policy engine, auto-updates.
Distribution
B2B2C via the agent platforms themselves: ship as the default skill registry and scan for OpenClaw, ZCode-class harnesses, and cloud IDEs — platform vendors adopt it free to de-risk their ecosystem; enterprises pay per seat for the private registry and policy engine. The wedge: the scan badges themselves are the viral loop ('SkillVault-scanned: 0 criticals').
Why it wins
Socket guards your node_modules; SkillVault guards your agent's hands. It maps what a skill or MCP server is allowed to touch (files, credentials, network) and enforces it at install and at runtime — which code scanners structurally cannot do.
Risks
Chicken-and-egg: a registry with no skills is useless, and skill authors will not publish to a registry nobody uses. De-risked because the MVP is useful without the registry — it is a safer installer for the skills people already pull from GitHub, and the scan results themselves are the viral loop.
Build it with
- ClawSecure: free security scanner for OpenClaw AI agent skillsThe free skill vulnerability scanner — the detection engine, with the 41%-vulnerable finding as the market proof.
- Sandlock 0.8.8: deferred commit for agent sandboxesDeferred-commit sandbox semantics — every run returns a changeset, writes land only after review.
- OpenAI MCP ExtensionsMCP's graduation to a first-class plugin platform — the 10x'd attack surface this product gates.
- CoreSpeed: One MCP for everything your agents needThe single-gateway MCP shape — whoever controls the gateway controls the policy enforcement point.
Repo to start from
skillvault-scanner — open skill/MCP manifest parser, vulnerability check rules, and permission-mapper; the hosted registry, private policy engine, and gateway enforcement stay closed.
Evidence
- New Sandworm_Mode supply-chain attack hits npm (SecurityWeek)
- Happy birthday, Shai-Hulud (Socket)
- Worm redux: fresh mini Shai-Hulud infections bite supply chain (Dark Reading)
Get the week's best AI launches, plus 3 ideas worth building
One email every Saturday. Ranked by traction, not hype. Free.