We built tork-scan, a free open-source CLI that checks AI agent skills (MCP tools) for 19 security risk patterns — reverse shells, credential harvesting, base64 payloads, eval(), C2 domains, and more.<p>We pointed it at 500 ClawHub skills. Results:<p>- 200 (40%) SAFE (90-100)
- 150 (30%) CAUTION (70...
Stories by yusufjacobs
Been working on this solo for a while. Tork is a governance middleware that sits between AI agents and the tools they call — intercepting every interaction to apply PII redaction, policy enforcement, and compliance audit trails.
It handles PII redaction, policy enforcement, and compliance audit trai...