1
NVIDIA's scanner for Agent Skills: finds prompt injection, exfiltration and supply-chain risks
★ 19k · +765 this week · Apache-2.0 · updated 2026-09-30
8.3/10
What it does SkillSpector is NVIDIA's open-source security scanner for Agent Skills. It answers one question before you install a skill: is this safe? Skills run inside agents with a lot of trust and little vetting. NVIDIA's research dataset found a large share of published skills with vulnerabilities, and some with malicious intent. SkillSpector inspects a skill folder, a single… Read more →
Pros
- Official NVIDIA tool used in its verified-skills pipeline
- Static plus optional LLM analysis; never executes the skill
- SARIF output, baselines and an MCP tool for gating installs
Cons
- Pattern-based scanning can yield false positives and misses
- LLM stage sends file contents to your chosen provider
Pricing: Open source · security scanner prompt-injection supply-chain mcp
2
Security auditing skills from the Trail of Bits research team
★ 7.3k · +102 this week · CC-BY-SA-4.0 · updated 2026-10-02
8.2/10
What it does This is a plugin marketplace from security firm Trail of Bits. Its skills are built for security analysis, auditing and testing work with a coding agent. The skills turn the firm's audit practice into repeatable steps. For example, they tell the agent to build context on a codebase before hunting for bugs, to check suspected findings for… Read more →
Pros
- From a respected security firm
- Practical audit workflows
Cons
- Security-focused first, with a few general development plugins
Pricing: Free · security audit
3
Agent Skills for solving CTF challenges across web, pwn, crypto, reverse, forensics and OSINT
★ 3.4k · +32 this week · MIT · updated 2026-09-13
7.0/10
What it does CTF Skills is a set of Agent Skills for solving capture-the-flag challenges. It groups techniques by category and loads the relevant one automatically from what you describe, so an agent can work through web exploitation, binary pwn, cryptography, reverse engineering, forensics, OSINT, malware analysis and miscellaneous puzzle categories. Each category skill carries concrete techniques, runnable template scripts… Read more →
Pros
- Broad category coverage with an orchestrator and writeup skill
- Ships runnable exploit templates and payload generators
- Installer with dry-run and verify modes
Cons
- Installs a large security toolchain and clones an external payload repo
- Useful mainly inside CTFs or authorized labs
Pricing: Open source · ctf agent-skills pwn crypto forensics
4
Skill bundle for authorized bug hunting and external red-team work, with scope gates and reporting
★ 4.7k · +86 this week · MIT · updated 2026-10-02
6.5/10
What it does Claude BugHunter is a large skill bundle that turns a coding agent into a bug-hunting and external red-team assistant, scoped to work you are authorized to do. It covers the external attack surface: web applications, APIs, GraphQL, OAuth and JWT, plus internet-facing enterprise platforms and cloud misconfiguration. Skills load automatically from what you describe in plain English,… Read more →
Pros
- Wide coverage of web and enterprise attack surface
- Built-in scope and accepted-impact gates before submission
- Runs on several agent harnesses
Cons
- Only for assets you own or are authorized to test
- Enterprise CVE chains demand a real engagement and care
Pricing: Open source · bug-bounty red-team application-security recon reporting