Works with the AI tools you already use
ZeroDay Scanner
Read-only Windows scan for supply-chain worms and AI-assistant persistence that antivirus misses — with wiper-safe cleanup.
$20
ZeroDay Scanner
Example session with this skill installed
Scan my Windows machine for supply-chain worms and hijacked AI-assistant configs, then show me anything suspicious:
powershell -ExecutionPolicy Bypass -File .\scripts\scan.ps1
- Read your context and instructions
- Compiled the zeroday scanner
- Generated the document
Result: 2 FLAG(S)
| Check | Status | Detail |
| py-startup | PASS | No sitecustomize/usercustomize startup hooks |
| compromised-pkgs | FLAG | PyPI 'rlask' found in requirements.txt (known typosquat) |
| ai-config | PASS | Claude/Cursor/VS Code hooks unchanged, no exfil patterns |
| mcp | PASS | 52 MCP server defs across 14 configs, all known/clean |
| skill-integrity | FLAG | Hidden Unicode (prompt-injection vector) in skill 'foo' |
| persistence | PASS | Run keys, Startup, tasks, services match baseline |
Report: reports\scan-20260710-1421.md (exit code 1)
zeroday-scanner.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
ZeroDay is a read-only Windows scanner that hunts the new wave of supply-chain and AI-assistant attacks traditional antivirus misses: self-propagating npm/PyPI worms (Shai-Hulud, Miasma/TeamPCP class), malicious Python startup hooks (.pth / sitecustomize), hijacked AI coding-assistant configs (Claude, Cursor, VS Code — hooks, tasks.json, MCP servers), tampered agent skills/plugins, prompt-injection via invisible Unicode, credential-exfil GitHub repos, and stealth persistence (Run keys, Startup, scheduled tasks, services).
It runs 11 checks against a baseline you capture once, writes a clear markdown report plus a live self-refreshing status dashboard, and never modifies your system while scanning. When you confirm a threat, a separate, wiper-safe cleanup tool (quarantine.ps1) preserves a forensic copy first, then optionally neutralizes it (reversible) or removes it — and a plain-English REMOVAL.md walks you through the correct isolate-first order that avoids triggering a worm's file-wiper retaliation.
ZeroDay improves itself over time. Supply-chain campaigns churn constantly, so its detection signatures live in an updatable feed (signatures.json), not buried in code. A built-in research-and-merge workflow finds threats disclosed since your last update, verifies each indicator against authoritative advisories (GitHub Advisory Database, OSV / OpenSSF malicious-packages, npm/PyPI, Socket, Microsoft, StepSecurity), and merges only high-confidence, low-false-positive indicators — new worm packages, dropper filenames, exfil hosts, and repo-name patterns — via update-signatures.ps1, which validates and de-duplicates every entry so a bad signature can never flag everything. The scanner unions these with built-in fallbacks and reminds you when signatures go stale, so coverage keeps growing without ever touching the tool's logic.
No install, no dependencies beyond PowerShell, no admin required, and no data leaves your machine. Every release is sealed with a SHA-256 integrity manifest (verify-integrity.ps1) so you can confirm the download is untampered before you trust it.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 2 months ago
- Passed all security checks, Safe to install