Now in early access, book a 30-minute demo →
Agent Skill security

Crush

Terminal coding agent with multi-model support and per-project sessions.

Charm

How skills run on Crush

Crush ships as a single binary that reads, writes, and executes code with the developer's own shell and git history as its workspace. Skill files it loads become model instructions, and shell access means a bad instruction runs as the logged-in user.

Skill security, assessed

Every public skill in our index is assessed by the Anomity Skill Intelligence engine against its real source: remote code execution, credential and data exfiltration, prompt injection, and unsafe installers.

Browse the Skill Risk Index →

Govern the skill layer on Crush

Scanning a skill before use tells you what it claims to do. Anomity's Endpoint Sensor sees what agents actually do at runtime: it discovers every skill, agent, and MCP server on the endpoint, and policy can allow, deny, or log the tool calls a skill triggers on Crush and every other agent. Violations route to your SIEM, Slack, email, or Jira with a queryable 90-day audit trail.

Book a 30-minute demo to see your own agent and skill inventory.

Other agents

Ask AI about Anomity
ChatGPT Claude Perplexity Google AI Grok