STEPSECURITY has introduced two complementary inventories to map AI agent skills in your development environment: on developer machines through Dev Machine Guard, and in GitHub repositories via an Agent Skills page under GitHub. The Dev Machine Guard view inventories skills detected across devices, including in shared directories like ~/.agents/skills, agent-specific folders (for example, ~/.claude/skills), project-level skill folders, and the skills[.]sh lock file.
It covers 18 AI coding agents such as Claude Code, Codex, GitHub Copilot, Cursor, Gemini CLI, Windsurf, and OpenClaw, and displays for each skill which agents can load it, its scope (global, project, or machine-wide), its origin (skills[.]sh, agent plugin, Local), and flags such as code, hooks, and shell content. It also shows content hashes to reveal variation across devices, usage counts, and the number of devices with the skill.
The GitHub view inventories skills committed to repositories on GitHub[.]com, scanning the default branch daily for non-archived repos, and presenting the skill’s name, path, provenance, source, files and scripts, and the same execution flags, enabling teams to see what is being distributed through codebases. Notably, GitHub Enterprise Server is not supported.
The article emphasises that agent skills are a supply-chain surface because they can execute, pre-approve tools, and resemble documentation. It cites evidence of attackers targeting AI agent skill files, referencing the Miasma worm’s June compromise that planted configuration files in Microsoft repositories to run credential-harvesting payloads when a repository is opened in Claude Code, Gemini CLI, Cursor, or VS Code, as well as prior incidents involving the s1ngularity Nx attack and the Cline v2.3.0 compromise.
The piece recommends practical review workflows: prioritise shell execution, check pre-approved tools in repositories, fix invalid frontmatter, verify provenance of managed skills, and monitor content variation and unmanaged Local skills, using coordinated checks across both Dev Machine Guard and GitHub inventories.