SkillSpector
Scan agent skills for malicious instructions, unsafe code, and supply-chain risks
- Stars
- 13,153
- Forks
- 1,066
- Updated
- Updated Jul 14, 2026
Scan agent skills for malicious instructions, unsafe code, and supply-chain risks
NVIDIA SkillSpector examines Git repositories, URLs, archives, directories, or individual files before an agent skill is installed. It checks dozens of patterns spanning prompt injection, exfiltration, privilege escalation, dangerous code, dependency vulnerabilities, MCP least privilege, and tool poisoning, then produces terminal, JSON, Markdown, or SARIF reports with risk scores. Scanned skills are never executed. Optional LLM analysis sends file contents to the configured provider, while static-only mode keeps that content local.
Resource types
Use cases
Runtime
Scan local agents, MCP servers, and skills for security risks.
Audit agent skills for commands, network access, secrets, and tools without executing them.
Protocols & integrations
Capabilities
Public GitHub facts last synced Jul 14, 2026.
Scan Claude Skills for risky network, file, command, and injection patterns.
Prove which AI agent wrote each line of code with signed Git records.