skillcap-lock is by DebadityaHait — not by us.
We indexed this project so people can find it. We are not selling it, we host no copy of the code, and we are not affiliated with or endorsed by its authors — get it from them.
Indexed Sep 28, 2026 · 0 stars at index time. Maintainers: claiming verifies your identity and unlocks a higher assurance tier. Removal requests are honored.
AI agent · for humans & their agents
skillcap-lock
unclaimed listingactively maintainedFreeMIT
Review what an Agent Skill can newly do, not just what bytes changed
by Open Source Community · New publisher
Review what an Agent Skill can newly do, not just what bytes changed
DebadityaHait/skillcap-lock is an open-source project by DebadityaHait: Review what an Agent Skill can newly do, not just what bytes changed. Indexed here so it can be found — not resold.
It is free. Get it from the upstream repository: https://github.com/DebadityaHait/skillcap-lock
From the project's own README (excerpt, reproduced for discovery under its MIT license):
SkillCap Lock
Review what an Agent Skill can do before an agent loads it. SkillCap Lock validates the Agent Skills specification, hashes every file, extracts observable capability evidence, scores instruction quality and risk, and compares the result with a reviewed baseline.
Position in the ecosystem
skills, skillpm, skills-lock, sklock, and Tank focus on discovery, installation, dependency resolution, or reproducible distribution. skill-check focuses on structural quality. SkillCap Lock is the static review layer for capability change and quality policy; it never installs or executes a skill.
Install
Node.js 20 or newer is required.
Baseline and CI
The generated skillcap.lock.json stores file hashes, redacted capability evidence, quality/risk scores, validation issues, and provenance. It does not store skill bodies or secret values.
Evidence and scoring
Capabilities are reported with kind, value, file, line, provenance, and confidence:
Evidence Examples --- --- network URLs and remote destinations command / interpreter npm, curl, python, shell and runtime invocations write / path filesystem mutation language and paths executable bundled scripts and executable filenames env / secret environment names and token-shaped strings (redacted)
Each skill has: • a risk score reflecting observable network, command, write, executable, and secret signals; • a quality score reflecting valid frontmatter, useful descriptions, body size, and completeness; • stable validation IDs (SKV001–SKV006) and capability delta IDs (SKC001–SKC008).
Static evidence is deliberately conservative. It can miss behavior hidden behind indirection and can over-approximate examples; it is a review aid, not a sandbox or security certificate.
Policies
Run npx…
01Capabilities
Does
- No capabilities recorded
Doesn’t
- No exclusions declared
02Requirements & stack
Depends on
No declared dependencies
Credentials needed
None declared
Stack
03Community
No endorsements yetNo verified confirmations yet — be the first.
Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.
Sign in to confirm — weight comes from verified usage, not vote count.
Issues 0
Open an issueNobody has reported anything yet — a success counts as a report too.
04Trust Passport
Full passport →0/0 automated components pass. An automated score is never a security guarantee.
This listing is unclaimed, so publisher identity cannot be verified and it stays below the “verified” tier by design — that is a statement about the listing, not about the project’s quality. Our automated scans still ran; a maintainer who claims it unlocks identity verification.
05Versions
Full history →| Version | Channel | Released | Notes |
|---|---|---|---|
| 0.0.0 | stable | Sep 28, 2026 | Indexed listing — see the upstream repository for real release history. |