Skill scanning and safety review
Glean scans Skills uploaded locally and Skills imported from a third-party repository for unsafe instructions, malicious code, and other risky content, so moderators can catch problems before a Skill spreads. Skills from Glean are safe by default and aren't scanned. This page covers when scans run, what each status means, how to review findings or turn a risky Skill off, and how to manage scanning as a billed advanced feature.
Scanning runs in the background, and a Skill stays usable while its scan runs. A Skill becomes unusable only when a moderator turns it off. See Understand the safety model.
You need the Skills Moderator, Admin, or Super Admin role to review findings and turn off Skills. You need the Admin or Super Admin role to turn Skill scanning on or off for your organization. See Set up Skills and manage access and About Role Based Access Control (RBAC).
Skill scanning is on by default for Skills uploaded locally and for third-party Skill repositories, and it applies regardless of your runtime guardrail configuration. It's a billed advanced feature. Admins can view its pricing and turn it off from Admin console → Advanced features. See Turn Skill scanning on or off.
Know when a scan runs
Glean scans a Skill when its executable content first appears or changes:
- Someone uploads a Skill locally.
- Someone imports a Skill from a third-party repository, such as GitHub.
- The instructions or bundled files of one of those Skills change, whether edited in Glean or pulled in from a repository sync.
Glean doesn't scan Skills from Glean. They're safe by default, so adding one or changing its content doesn't start a scan.
Each time that content changes, Glean starts a fresh scan of that version and clears results from the previous version.
Metadata-only changes don't trigger a new scan. Renaming a Skill, changing its description, adjusting sharing, or turning it on or off leaves the current scan and its results in place.
Scanning is asynchronous, so there's a short delay between saving a Skill and its scan starting. The Skill is usable during that window. If a scan doesn't start, Glean queues it again automatically.
Read scan statuses
Each Skill shows one security status for its latest content. Moderators see these statuses on Admin console → Skills → Manage. Statuses include text labels, so they don't rely on color alone.
| Status | What it means | Skill usable? |
|---|---|---|
| Not scanned | No scan has run yet, or a scan couldn't finish. A failed scan shows a Retry scan action. | Yes |
| Scan in progress | The scan is queued or running. | Yes |
| Pass | The scan finished with no findings. | Yes |
| Review recommended | The scan finished and reported one or more findings for review. | Yes, unless turned off |
| Disabled | A moderator turned the Skill off because of findings. | No |
A finished scan shows Pass when there are no findings, or Review recommended when there are. A Skill with findings stays usable until a moderator turns it off, which changes the status to Disabled.
A failed scan means Glean couldn't complete the check, not that the Skill is unsafe. It shows as Not scanned with a Retry scan action, and the Skill stays usable. Editing the Skill also starts a new scan.
Review findings and severity
When a scan reports findings, each finding includes:
- A rule ID identifying the check that matched, such as
skill.prompt_injection. - A severity: Low, Medium, High, or Critical.
- A plain-language description of the issue.
- An optional source location pointing to the file and line range the finding applies to. A finding with no location applies to the whole Skill.
If one issue affects multiple files or separate line ranges, Glean reports it as multiple findings so each points to a single location. The Skill's overall severity is the highest among its findings.
Scanning currently runs these checks:
- Prompt injection — instructions that try to hijack or override the assistant
- Malicious code — code patterns that look harmful
- Harmful content — content that violates safety policy
- Bundle structure — unsafe or duplicate file paths, or files that can't be inspected (for example, non-text files or files that are too large)
The set of checks may expand over time.
Fix with Glean
When an owner opens a Skill with findings, they see a Fix with Glean action. Applying a fix saves a new version of the Skill and starts a new scan of the updated content. The earlier scan no longer applies.
Understand the safety model
Scanning is informational and fail-open. A Skill remains usable while its scan hasn't run, is queued or running, has failed, or reports findings. The only thing that prevents use is a moderator turning off the Skill.
A provider outage or a scan failure doesn't turn off Skills your teammates rely on. Findings alone don't stop a Skill from running, even High or Critical ones. A moderator decides what happens next.
Normal Skill status and permission checks still apply. A Skill that's in draft, turned off by its owner, or not shared with someone stays unavailable to them regardless of its scan result.
Only the current scan matters. When a Skill's content changes, its previous scan and any decision on it no longer apply, and a new scan begins.
Review findings
Moderators review Skills shared at their scope from Admin console → Skills → Manage. Open a Skill with Review recommended status to see its findings, each with a rule ID and description, and the date of the last scan.
A moderator can take these actions:
| Action | What it does |
|---|---|
| Dismiss findings | Clears the review warning for you. The Skill stays usable. |
| Disable skill | Turns off the Skill across discovery and execution right away. Its status becomes Disabled. |
| Enable skill | Turns a Skill back on after it was turned off for security. |
| Retry scan | Re-runs a scan that failed. |
Turning off a Skill is the only action that changes whether it can be used. Dismissing findings hides the warning for that reviewer and doesn't change availability.
When an owner fixes a turned-off Skill and saves a new version, the earlier decision no longer applies. The new version starts a fresh scan and the Skill is usable again, until a moderator turns off the new version.
Review actions apply to the scan you're looking at. If the Skill's content changes while you review, Glean starts a new scan and rejects a decision made against the old one. Refresh the Skill to see the latest scan and decide again.
Example of turning off a Skill
- A teammate creates a Skill, and Glean queues a scan.
- The scan completes with findings, including a Critical one. The Skill shows Review recommended and stays usable.
- A moderator reviews the findings and turns off the Skill. It immediately becomes unusable for everyone and shows Disabled.
- The owner fixes the Skill with Glean or edits it by hand, which creates a new version and starts a new scan. The Skill is usable again unless a moderator turns off the new version.
See what people see
What a person sees depends on their relationship to the Skill:
- Anyone with access to a Skill that's still being scanned sees a short notice that the scan is in progress. The Skill stays usable while the scan runs.
- Owners and moderators see a Review recommended warning on a Skill with findings, listing each finding's rule and description. They can dismiss the warning, which hides it only for that person. Owners also see a Fix with Glean action.
- Anyone with access to a Skill that a moderator has turned off sees a short notice that the Skill is temporarily turned off for security reasons, with a link to learn more. This notice can't be dismissed, and the Skill can't be used until its owner saves a new version or a moderator turns it back on.
Dismissal is per user and applies only to the current scan. If the Skill's content changes, a new scan begins and the warning returns.
Turn Skill scanning on or off
Skill scanning is on by default. Because each scan consumes usage, admins can turn it off for the whole organization.
- Navigate to Admin console → Advanced features.
- Find Skill scanning. The card shows the feature's current state and its price.
- Turn the feature off or on.
When scanning is off, Glean stops starting new scans. Skills stay usable. Moderators can still turn Skills off or on from Admin console → Skills → Manage. When you turn scanning back on, Glean scans a Skill the next time its content changes.
Turning scanning off removes the automated safety check on Skills uploaded locally and on third-party Skill repositories. Skills from Glean aren't scanned either way. Keep it on unless you review that content another way.
Billing
Skill scanning is a billed advanced feature. Each scan Glean runs counts toward your organization's usage, in the same way as other advanced features such as Deep research and Image generation.
- To see the price, open Admin console → Advanced features and find Skill scanning.
- To see how much scanning your organization has consumed, open Admin console → Usage and select Advanced features. Skill scanning appears alongside the other advanced features. See Usage dashboard: Enterprise Flex or Usage dashboard: Glean Core Suite and Model Hub.
Scanning usage counts toward the limits you configure. See Set usage limits and alerts. For questions about how scanning maps to your contract, contact your Glean account team.
Troubleshooting
Frequently asked questions
See also
- Skills — how teammates create, use, and manage Skills
- Share Skills — share and publish Skills to wider audiences
- Set usage limits and alerts — cap advanced feature spend by organization, department, or user