Now in early access, book a 30-minute demo →
Agent Skill security

Reasonix

Open-source, DeepSeek-native coding agent for the terminal, browser, and ACP editors.

Reasonix

How skills run on Reasonix

Reasonix keeps a long-running agent loop over your codebase, reading and modifying files, running commands, and connecting to MCP servers. Because skills are injected into that loop as instructions, a malicious SKILL.md inherits every permission the session already holds.

Skill security, assessed

Every public skill in our index is assessed by the Anomity Skill Intelligence engine against its real source: remote code execution, credential and data exfiltration, prompt injection, and unsafe installers.

Browse the Skill Risk Index →

Govern the skill layer on Reasonix

Scanning a skill before use tells you what it claims to do. Anomity's Endpoint Sensor sees what agents actually do at runtime: it discovers every skill, agent, and MCP server on the endpoint, and policy can allow, deny, or log the tool calls a skill triggers on Reasonix and every other agent. Violations route to your SIEM, Slack, email, or Jira with a queryable 90-day audit trail.

Book a 30-minute demo to see your own agent and skill inventory.

Other agents

Ask AI about Anomity
ChatGPT Claude Perplexity Google AI Grok