Skip to main content

Skill Guard scans, Assistant questions and template lineage

· 4 min read

Skill Guard now scans the skills in your connected repositories for security risk and shows the result on each skill. The Assistant can ask you a question when it needs more information and entity pages show which template created them.

Skill Guard​

Skill Guard checks each skill for problems such as prompt injection attempts, unsafe commands and exposed credentials. Venue.sh scans a skill automatically the first time it discovers the skill. You do not need to start a scan yourself.

  • Model selection - A Venue administrator picks the model that Skill Guard uses under Settings > AI Settings. The list shows only models that Skill Guard supports.
  • Skill Guard tab - Each skill page now has an Overview tab, a Skill content tab and a Skill Guard tab. The Skill Guard tab shows the risk score, the recommendation, the number of findings for each severity and a list of findings that you can filter by severity.
  • Finding locations - A finding shows its file, line and rule ID. A finding that applies to the whole skill shows Bundle-level.
  • Coverage notices - If a scan could not inspect part of a skill, the tab says why. For example, a companion file was not stored, or a file was too large to scan.
  • Failure messages - If a scan fails, the tab explains the reason and links to the Support Portal. If the AI provider rejects the request, choose a different model in AI Settings.
  • Reingesting - Reingesting a repository now scans skills that have never been scanned or whose last scan failed, even when the repository content has not changed.
  • Model support - Skill Guard now works with Claude Opus 5.5 and Claude Sonnet 5.5. It also reuses a finished scan instead of repeating it.

See Skills for what a scan checks and how to read the result.

Assistant questions​

The Assistant in Venue.sh can now stop in the middle of a response and ask you a question. The question appears in the chat. Select one or more choices, add your own text if you want and submit your answer and the Assistant then continues the same conversation.

See Assistant for more about using the Assistant.

Skill install command​

The install row on a skill's Overview tab now has an Agent selector that helps you pick the right coding agent. Pick your coding agent and Venue.sh adds the matching --agent option to the command when you copy it. Pick Any agent to copy the command without the option. Your browser remembers your choice for other skills.

Template lineage​

The About card on an entity page now shows Created from template when a template created the entity. The text links to that template.

See Templates to browse and launch software templates.

Portal improvements​

  • Tables - Long text in a table cell now ends with an ellipsis and a tooltip shows the full text. Tables scroll sideways in a narrow window instead of squeezing the columns. Column resizing no longer shrinks a column on the first click of the divider.
  • Diagrams - Mermaid diagrams in Assistant responses now stay inside the message column.
  • Allowed Models - The model chips in the Allowed Models field in AI Settings are now centered.

Fixes​

  • GitLab template publishing - When a template fails to publish to GitLab, the step now shows the error from GitLab, such as a visibility restriction. Before, it reported that the repository already existed when it did not.
  • Template registration - The register step now uses the git connection from the template run when the step does not set one. A successful publish no longer fails at registration.