CLI appSecurity and privacy

SkillSpector

Scan agent skills for malicious instructions, unsafe code, and supply-chain risks

Stars
13,153
Forks
1,066
License
Apache-2.0
Updated
Updated Jul 14, 2026

Checking live repository facts…

Project overview

NVIDIA SkillSpector examines Git repositories, URLs, archives, directories, or individual files before an agent skill is installed. It checks dozens of patterns spanning prompt injection, exfiltration, privilege escalation, dangerous code, dependency vulnerabilities, MCP least privilege, and tool poisoning, then produces terminal, JSON, Markdown, or SARIF reports with risk scores. Scanned skills are never executed. Optional LLM analysis sends file contents to the configured provider, while static-only mode keeps that content local.

Repository facts

Primary language
Python
License
Apache-2.0
Repository updated
Jul 14, 2026
Default branch
main

Resource types

CLI app

Use cases

Security and privacy

Runtime

Command lineLocal

Protocols & integrations

Model Context Protocol

Capabilities

Security guardrailVerification and evals

Related projects

Browse more similar projects