Forward Future Tools Library

SkillProvenance Scan logo

SkillProvenance Scan

SkillProvenance Scan reviews agent skills for provenance, permission changes, injection risks, and install evidence, with workflows for independent authors, security teams, and enterprise IT.

Try SkillProvenance Scan →

skillprovenancescan.space·From $19.50/mo·Checked 2026-09-29

SkillProvenance Scan screenshotRELEASED] World Space Canvas UI - Community ShowcasesIssue with World Space UI and Render Sorting - AskWorld Space UI - General DiscussionSpace Game UI by Acasas
SkillProvenance Scanskillprovenancescan.space
SkillProvenance Scan screenshot
SkillProvenance Scanskillprovenancescan.space

›What is SkillProvenance Scan?

SkillProvenance Scan is a hosted scanner for reviewing agent skills before installation or upgrade. It accepts skill and GitHub URLs, maps source provenance, compares trusted and proposed versions, flags injection patterns, and records permission changes. Paid plans add allowlists, upgrade advisories, rollback notes, and PDF or HTML trust reports.

›What are the pros and cons of SkillProvenance Scan?

Strengths

Combines provenance, permission, injection, and upgrade review in one workflow
Shows capability expansion in a version-to-version review table
Supports repeatable install gates with allowlists, reviewer notes, and rollback targets
Provides exportable PDF and HTML evidence for approval and assessment workflows

Trade-offs

Full provenance and permission reports require a paid plan
Scan quotas vary by plan, from 50 scans on Maker to 10,000 scans on Enterprise
API access, repository policy packs, queue jobs, and reviewer evidence history are limited to Enterprise
The service states that it does not provide legal advice, formal certification, or a guarantee that a third-party skill is safe

›What are SkillProvenance Scan’s key features?

Scans skill URLs and GitHub repositories
Maps authors, repositories, forks, licenses, versions, and recent change activity in a provenance graph
Compares trusted and proposed versions for new tools, network calls, external services, write paths, and install commands
Flags credential requests, disguised system instructions, destructive install steps, and runtime override language
Maintains enterprise allowlists, baseline versions, reviewer notes, rollback targets, and upgrade status
Exports review evidence as PDF or HTML trust reports

›What are the best use cases for SkillProvenance Scan?

Review an agent skill before installing it in a production environment
Compare a proposed skill upgrade with a trusted version before approval
Check repository history, permissions, external services, and injection risks during security review
Create evidence packets for customer reviews, marketplace QA, or internal approval workflows

›What is the pricing for SkillProvenance Scan?

PlanPriceDetails
Maker$19.50/moIncludes 50 scans, skill directory and GitHub URL intake, a provenance graph summary, a permission and tool inventory, and an injection red-flag scan.
Team$74.50/moIncludes 1,000 scans, version-to-version permission diffs, an enterprise allowlist workflow, upgrade advisories, rollback notes, and PDF/HTML trust report export.
Enterprise$249.50/moIncludes 10,000 scans plus API access, queue jobs, repository policy packs, reviewer evidence history, and a priority support channel.

Annual billing is selected by default and saves 50%. The listed annual totals are $234 for Maker, $894 for Team, and $2994 for Enterprise.

Checked 2026-09-29 · source

›Who is SkillProvenance Scan best for?

enterpriseEnterprise IT and platform teams can use allowlists, policy packs, reviewer history, and API access to manage recurring skill install gates.
security teamsSecurity reviewers get a focused view of provenance, permissions, injection indicators, external services, and upgrade deltas.
developersDevelopers can check a skill or GitHub repository before installation and inspect the changes introduced by an upgrade.
soloIndependent skill authors can use the Maker plan for URL intake, provenance summaries, permission inventories, and injection scans.
Not for
  • Teams seeking legal advice, formal certification, or a guarantee that a third-party skill is safe
  • Buyers who only need occasional curiosity checks and do not want to pay to unlock full reports
  • Organizations requiring API access, repository policy packs, or reviewer evidence history without the Enterprise plan

›What are the best SkillProvenance Scan alternatives?

›Where can I try SkillProvenance Scan?

Open skillprovenancescan.space →