
CLI scanner that detects security threats in AI agent skills before installation.
CLI scanner that detects security threats in AI agent skills before installation.
Alice Caterpillar is a CLI-based security scanner designed to analyze AI agent skills (also referred to as AI coding assistant plugins or rules) for security threats before they are installed or used in a development environment. The tool scans skill files and directories, identifying a range of security issues across multiple categories: - Dangerous Permissions: Skills requesting excessive permissions beyond their stated functionality - Privacy Violations: Skills that collect personal information or track user activity without consent - Data Exfiltration: Skills that transmit sensitive data (source code, config files, database contents) to unauthorized external destinations - Obfuscation: Skills using encoded commands or intentionally confusing logic to hide true functionality - Social Engineering: Skills using deceptive UI elements, fake alerts, or manipulation to extract information - Supply Chain: Skills that tamper with package management, modify dependencies, or inject code into build processes - Credential Theft: Skills attempting to access or steal API keys, SSH keys, passwords, or authentication tokens - Network Attacks: Skills performing malicious network operations such as C2 communication or port scanning Caterpillar assigns letter grades (A through F) and severity levels to scanned skills, allowing users to make informed decisions about whether to keep, fix, or reject a skill. It is distributed as a free, open-source tool installable via curl or npm, and requires no API key to operate. It is intended for use by individual developers, security teams, DevOps engineers, and engineering managers. Supported skill types include Claude Skills, Cursor Rules, and MCP configs.
Common questions about Caterpillar including features, pricing, alternatives, and user reviews.
Caterpillar is CLI scanner that detects security threats in AI agent skills before installation, developed by Alice. It is a AI Security solution designed to help security teams with Agentic AI Security, MCP Security, LLM Security.
Caterpillar offers the following core capabilities:
Learn more at https://cybersectools.com/tools/caterpillar
Caterpillar is a free AI Security tool. This makes it accessible for organizations of all sizes, from startups to enterprises. Visit https://caterpillar.alice.io/ for download and installation instructions.
Popular alternatives to Caterpillar include:
Compare these tools and more at https://cybersectools.com/categories/ai-security
Caterpillar is for security teams and organizations that need Agentic AI Security, MCP Security, LLM Security, Supply Chain Security, Security Scanning. It's particularly suitable for small to medium-sized teams looking for cost-effective solutions. Other AI Security tools can be found at https://cybersectools.com/categories/ai-security
NLP-based security scanner for AI agent skill files detecting behavioral threats.
Agentic AI security platform with continuous scan, analyze, remediate & evaluate loop.