Now in early access, book a 30-minute demo →
Agent Skill security

Qwen Code

Open-source terminal coding agent from Alibaba's Qwen team, tuned for Qwen3-Coder models.

Alibaba Qwen

How skills run on Qwen Code

Qwen Code works from the command line with read and write access to project files, shell execution, and MCP tool connections. Any SKILL.md it loads is prompt text with that same reach, which makes unreviewed skills an execution risk.

Skill security, assessed

Every public skill in our index is assessed by the Anomity Skill Intelligence engine against its real source: remote code execution, credential and data exfiltration, prompt injection, and unsafe installers.

Browse the Skill Risk Index →

Govern the skill layer on Qwen Code

Scanning a skill before use tells you what it claims to do. Anomity's Endpoint Sensor sees what agents actually do at runtime: it discovers every skill, agent, and MCP server on the endpoint, and policy can allow, deny, or log the tool calls a skill triggers on Qwen Code and every other agent. Violations route to your SIEM, Slack, email, or Jira with a queryable 90-day audit trail.

Book a 30-minute demo to see your own agent and skill inventory.

Other agents

Ask AI about Anomity
ChatGPT Claude Perplexity Google AI Grok