{"_id":"@bioperl/skill-guard","_rev":"3-7daa0e2c03eb9e2c252900e0f1005fa3","name":"@bioperl/skill-guard","dist-tags":{"latest":"0.1.2"},"versions":{"0.1.0":{"name":"@bioperl/skill-guard","version":"0.1.0","keywords":["opencode","skillspector","security","cli","nvidia"],"_id":"@bioperl/skill-guard@0.1.0","maintainers":[{"name":"bioperl","email":"a8802137@gmail.com"}],"bin":{"skill-guard":"bin/skill-guard.js"},"dist":{"shasum":"733aa11b118de8d332d428fd7d50bb9b0f6eb9a6","tarball":"https://registry.npmjs.org/@bioperl/skill-guard/-/skill-guard-0.1.0.tgz","fileCount":10,"integrity":"sha512-B0lnyQNNwO3L93271RcMKh9cLGnC8kpfAJS38cpBJj5h6ySpfjqh1NmZ8MRVn6Vcp6B1JSCo/I49YMR4382TeQ==","signatures":[{"sig":"MEUCIHv7eSYLYOMFlZy/w6aSMthI9uRj1yy94DNo3sw7EgveAiEA4DcMr6ojc3WdFRY3SGJpazJSa04M23u9RAx/y1qiMv0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":16599},"type":"module","engines":{"node":">=18"},"gitHead":"cfb958ddefd93402b0e3b31b5c4b3f107ed225bf","scripts":{"test":"node --experimental-vm-modules node_modules/jest/bin/jest.js"},"_npmUser":{"name":"bioperl","email":"a8802137@gmail.com"},"_npmVersion":"11.12.1","description":"Security scanner wrapper for OpenCode skill installation","directories":{},"_nodeVersion":"22.22.2","dependencies":{"nanoid":"^5.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^30.4.2","@types/jest":"^30.0.0"},"_npmOperationalInternal":{"tmp":"tmp/skill-guard_0.1.0_1780493639575_0.8021300752409501","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@bioperl/skill-guard","version":"0.1.1","keywords":["opencode","skillspector","security","cli","nvidia"],"_id":"@bioperl/skill-guard@0.1.1","maintainers":[{"name":"bioperl","email":"a8802137@gmail.com"}],"bin":{"skill-guard":"bin/skill-guard.js"},"dist":{"shasum":"fee061eb7a062c9b9b4eba3fa09fa9205a111263","tarball":"https://registry.npmjs.org/@bioperl/skill-guard/-/skill-guard-0.1.1.tgz","fileCount":10,"integrity":"sha512-eF9z+UlGNJ+46pANkLP9eo/CpSOuif/oeUI3VkXNlehOjZyvsZorsnopAACuHCScxugDKtnsqdijuR6F7/clBg==","signatures":[{"sig":"MEQCIGPbUoj3RsHb0REhb3ufZTQFN8RajhvCMdPBQ7PvsWzbAiBrcnJGGlh0fJ/ERk0mplZAbWY6y0AvtHewaEP4mKAYRA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":17019},"type":"module","engines":{"node":">=18"},"gitHead":"75a41948cb448419bd5d9c114bf80db286a29765","scripts":{"test":"node --experimental-vm-modules node_modules/jest/bin/jest.js"},"_npmUser":{"name":"bioperl","email":"a8802137@gmail.com"},"_npmVersion":"11.12.1","description":"Security scanner wrapper for OpenCode skill installation","directories":{},"_nodeVersion":"22.22.2","dependencies":{"nanoid":"^5.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^30.4.2","@types/jest":"^30.0.0"},"_npmOperationalInternal":{"tmp":"tmp/skill-guard_0.1.1_1780495324172_0.9367957535694784","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@bioperl/skill-guard","version":"0.1.2","description":"Security scanner wrapper for OpenCode skill installation","keywords":["opencode","skillspector","security","cli","nvidia"],"publishConfig":{"access":"public"},"type":"module","bin":{"skill-guard":"bin/skill-guard.js"},"dependencies":{"nanoid":"^5.0.0"},"engines":{"node":">=18"},"scripts":{"test":"node --experimental-vm-modules node_modules/jest/bin/jest.js"},"devDependencies":{"@types/jest":"^30.0.0","jest":"^30.4.2"},"gitHead":"0245e5e833e2ff29f1d2ffe4b77d2a049ff03ce5","_id":"@bioperl/skill-guard@0.1.2","_nodeVersion":"22.22.2","_npmVersion":"11.12.1","dist":{"integrity":"sha512-eGgVYSVkOHhhTJc9CQTb4KWBdIFkFgECPNd5fRLRUt2yUoK7kPd682bA54aqCJo59or/YT4NFGMcfz7vhA+Hew==","shasum":"f6d79a19a854f7e78fc970f82784b11b91871790","tarball":"https://registry.npmjs.org/@bioperl/skill-guard/-/skill-guard-0.1.2.tgz","fileCount":10,"unpackedSize":17391,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIFQKlBY2LKH4qmz1a03chovJ1iu37Qqt/zID+Rb9E/E9AiBO69I5zpCyLuyWX+SfZ8Of/sipX773ohXiVcKEOP0Evw=="}]},"_npmUser":{"name":"bioperl","email":"a8802137@gmail.com"},"directories":{},"maintainers":[{"name":"bioperl","email":"a8802137@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/skill-guard_0.1.2_1780495668046_0.11419959838837812"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-03T13:33:59.387Z","modified":"2026-06-03T14:07:48.300Z","0.1.0":"2026-06-03T13:33:59.722Z","0.1.1":"2026-06-03T14:02:04.308Z","0.1.2":"2026-06-03T14:07:48.189Z"},"keywords":["opencode","skillspector","security","cli","nvidia"],"description":"Security scanner wrapper for OpenCode skill installation","maintainers":[{"name":"bioperl","email":"a8802137@gmail.com"}],"readme":"# skill-guard\n\n> Security scanner wrapper for OpenCode skill installation.\n\nWhen you install a skill from an untrusted source, you're effectively running arbitrary code. **skill-guard** runs [NVIDIA SkillSpector](https://github.com/NVIDIA/skillspector) before every install — static analysis that checks for 64+ vulnerability patterns (sensitive API calls, file operations, network access, deserialization risks) — and decides: **auto-approve / ask the user / block**.\n\n## Prerequisites\n\n| Tool | Version | Install |\n|------|---------|---------|\n| Node.js | >= 18 | [nodejs.org](https://nodejs.org) |\n| Python | >= 3.12 | [python.org](https://python.org) |\n| SkillSpector | latest | `pip install git+https://github.com/NVIDIA/skillspector.git` |\n>\n> It is recommended to install SkillSpector inside a Python virtual environment to avoid dependency conflicts.\n\n## Install\n\n```bash\nnpm install -g @bioperl/skill-guard\n```\n\nOr use it without installing:\n\n```bash\nnpx @bioperl/skill-guard install <ref>\n```\n\n> **Windows users:** If `skill-guard` is not recognized after installing, use `npx @bioperl/skill-guard install <ref>` instead. This does not require a global install.\n\n## Usage\n\n```bash\n# Install a skill with automatic security scan\nskill-guard install superpowers@git+https://github.com/obra/superpowers.git\n\n# Install from a local path\nskill-guard install /path/to/local/skill\n\n# Skip the scan (not recommended)\nskill-guard install --force-skip-security some-skill\n\n# Show help\nskill-guard --help\n```\n\n### Supported reference formats\n\n| Format | Example | Behavior |\n|--------|---------|----------|\n| `git+https` | `name@git+https://github.com/user/repo.git` | `git clone` to temp dir |\n| Local path | `/home/me/skills/my-skill` | Copy to temp dir |\n| `file://` | `file:///home/me/skills/my-skill` | Same as local path |\n\n## Score reference\n\n| Score | Behavior | Can override? |\n|-------|----------|---------------|\n| **0–20** SAFE | Auto-approve, installs immediately | — |\n| **21–80** CAUTION | Shows report, asks for confirmation | Yes (`y`) |\n| **81–100** BLOCK | Blocks installation, shows report | — |\n| **Scan error** | Aborts with error message | Must fix environment first |\n\n## How it works\n\n```\nskill-guard install <ref>\n  → parseSkillRef()      Detect git+https / local / file://\n  → fetchToTemp()        Clone or copy to temp directory\n  → runScan()            Invoke SkillSpector (static analysis)\n  → Should warn/block?\n     SAFE    → installFromTemp()    → Move to ~/.cache/opencode/packages/\n     CAUTION → askUser()            → install or cancel\n     BLOCK   → exit(1) with report\n```\n\n## Configuration\n\nCreate a `skillSecurity` section in your `opencode.jsonc`:\n\n```jsonc\n{\n  \"skillSecurity\": {\n    \"enabled\": true\n  }\n}\n```\n\n- `enabled: false` disables scanning (equivalent to `--force-skip-security`)\n- Defaults to `true` if omitted entirely\n\n## Integration with OpenCode\n\nskill-guard works alongside OpenCode by:\n\n1. Cloning the skill to `~/.cache/opencode/packages/<name>/`\n2. Registering it in your `opencode.jsonc` under the `plugin` array\n3. Restart OpenCode to load the new skill\n\n## Related projects\n\n- [OpenCode](https://opencode.ai) — The AI coding assistant that uses skills\n- [SkillSpector](https://github.com/NVIDIA/skillspector) — NVIDIA's skill security scanner\n- [Superpowers](https://github.com/obra/superpowers) — Community skill collection\n\n## License\n\nMIT\n","readmeFilename":"README.md"}