SkillFortify is the first formal security analysis tool for AI agent skills. Using the DY-Skill Dolev-Yao formal model, it detects skill injection, prompt leakage, unsafe tool invocations, and supply chain attacks across 22 agent frameworks — with zero false positives.
Zero false positives. Every vulnerability flagged is a real vulnerability. Formal verification guarantees.
LangChain, CrewAI, AutoGen, OpenAI, Claude, Semantic Kernel, and 16 more agent frameworks.
Dolev-Yao model adapted for agent skills. Sound static analysis with formal security proofs.
Agent Software Bill of Materials. Track every skill, its dependencies, and their security posture.
Validated against 540 real-world agent skills. 96.95% F1 score.
Already being cited by other security researchers. Recognized in the academic community.
SkillFortify: Securing the AI Agent Skill Supply Chain
Varun Pratap Bhardwaj, 2026
Read on arXiv →