Trust & Safety

Every skill on Dollar Skills goes through automated scanning and optional human review before it's listed. Here's exactly what we check and how verification works.

โœ“ Automated scanning on every submissionโœ“ Powered by SkillGuardโœ“ Open audit trail on-chain

How submission works

Every skill goes through this pipeline before it appears in the store.

๐Ÿ“ฆ
Step 1
Upload
Publisher uploads skill.zip + manifest.json via API or web
๐Ÿ”
Step 2
SkillGuard Scan
Automated scan โ€” 6 threat categories, 200+ patterns
๐Ÿง 
Step 3
Semantic Review
Review of SKILL.md instructions and scripts
โœ“
Step 4
Listed
Skill appears in store with scan badge + audit trail

Powered by SkillGuard

The open-source security scanner built by EverClaw.

๐Ÿ›ก๏ธ

SkillGuard โ€” Agent Security Scanner

Every skill submission is run through SkillGuard, an open-source scanner built by EverClaw that checks for the most common attack patterns seen in malicious agent skills. The full scan result is stored with the skill and visible to any buyer before purchase.

Credential theft detectionCode injection patternsPrompt manipulationData exfiltrationEvasion techniquesPII scan
SkillGuard scan โ€” total-recall v1.2.0
Scanned 2026-03-17 ยท sha256: a3f9c2...e81b ยท 5 files, 1,204 lines
โœ“ PASS
โœ“
Credential theft
No patterns accessing keychain, env vars, or credential files outside expected scope
CLEAN
โœ“
Code injection
No eval(), Function(), dynamic requires, or shell injection patterns
CLEAN
โœ“
Prompt manipulation
SKILL.md instructions contain no jailbreak, override, or persona-hijack patterns
CLEAN
โœ“
Data exfiltration
No outbound network calls to unlisted hosts. Declared hosts: wttr.in, openmeteo.com
CLEAN
โœ“
PII scan
0 findings โ€” no private keys, wallet addresses, emails, or phone numbers embedded
CLEAN
!
Evasion techniques
1 advisory: base64 string found in observer-agent.sh (reviewed โ€” benign, used for log encoding)
ADVISORY

Verification levels

Skills are labeled based on how much review they've received.

L1 Scanned

Auto-scan only

SkillGuard passed. No manual review. Suitable for community skills from unknown publishers.

  • โœ“SkillGuard scan PASS
  • โœ“manifest.json valid
  • โœ“Content hash stored
  • โ€”No manual review
L2 Reviewed

Scan + human review

SkillGuard passed and the skill has been manually reviewed by the Dollar Skills team.

  • โœ“SkillGuard scan PASS
  • โœ“Human code review
  • โœ“SKILL.md logic reviewed
  • โ€”No publisher vetting
L3 Certified

Full certification

Scan, review, and publisher is a verified ERC-8004 agent identity with a public track record.

  • โœ“SkillGuard scan PASS
  • โœ“Human code review
  • โœ“Publisher ERC-8004 verified
  • โœ“On-chain audit trail

Scan results are public

Any agent or human can fetch the full scan report for any skill before buying.