SkillSpector 🧩 Skill Open source
NVIDIA's scanner for Agent Skills: finds prompt injection, exfiltration and supply-chain risks
- GitHub stars
- 19k
- Stars this week
- +765
- Forks
- 1.7k
- Licence
- Apache-2.0
- Last push
- 2026-09-30
- Maintainer
- NVIDIA
uv tool install git+https://github.com/NVIDIA/skillspector.gitThird-party agent skills run with your permissions. Read the source before installing, and prefer pinned versions.
Works with
About SkillSpector
What it does
SkillSpector is NVIDIA's open-source security scanner for Agent Skills. It answers one question before you install a skill: is this safe? Skills run inside agents with a lot of trust and little vetting. NVIDIA's research dataset found a large share of published skills with vulnerabilities, and some with malicious intent. SkillSpector inspects a skill folder, a single SKILL.md, a Git repository, a URL or a zip file. It reports what it finds with a risk score from 0 to 100 and a recommendation. The same tool is used in NVIDIA's own pipeline that verifies and signs skills before they are published.
What is inside
- 71 detection patterns in 17 categories, including prompt injection, data exfiltration, privilege escalation, supply-chain risk, excessive agency, memory poisoning, MCP tool poisoning and least-privilege problems
- Two stages: fast static analysis using regex, Python AST and YARA rules, then an optional LLM review of file contents
- Live CVE lookups against OSV.dev for declared dependencies, with an offline fallback
- Reports in terminal, JSON, Markdown and SARIF formats for CI
- Baselines for suppressing accepted findings, so repeat scans show only new issues
- An MCP server exposing a
scan_skilltool, so an agent can check a skill before installing it
Works with
The CLI scans skills written for any agent. Its MCP server is documented for Claude Code, Codex CLI and Gemini CLI, and there are extensions for OpenCode and Pi. For the LLM stage you can use hosted APIs, Ollama, or the login of your local claude, codex, gemini or opencode CLI.
How to install
It needs Python 3.12 or newer:
uv tool install git+https://github.com/NVIDIA/skillspector.git
Then run skillspector scan ./my-skill/.
Maintenance and safety
The project is Apache-2.0 licensed, maintained by NVIDIA and updated frequently. It never runs the skill it scans: every check is static or done by an LLM reading the files. Dependency names are sent to OSV.dev, and file contents go to your LLM provider unless you pass --no-llm. It flags risks but does not sandbox anything you install afterwards.
Who should use it
Anyone installing third-party skills, and teams that want to block risky skills in CI or through their agent.
Pros
- Official NVIDIA tool used in its verified-skills pipeline
- Static plus optional LLM analysis; never executes the skill
- SARIF output, baselines and an MCP tool for gating installs
Cons
- Pattern-based scanning can yield false positives and misses
- LLM stage sends file contents to your chosen provider
Similar agent skills
All security skills →Trail of Bits Skills 🧩 SkillFree
Security auditing skills from the Trail of Bits research team
CTF Skills 🧩 SkillOpen source
Agent Skills for solving CTF challenges across web, pwn, crypto, reverse, forensics and OSINT
claude-bughunter 🧩 SkillOpen source
Skill bundle for authorized bug hunting and external red-team work, with scope gates and reporting
Anthropic Agent Skills 🧩 SkillFree
Anthropic's official collection of Agent Skills, including document, design and developer skills
Superpowers 🧩 SkillFree
A skills library that makes coding agents plan, test-first and debug systematically
Frontend Design skill 🧩 SkillFree
Guides the agent to build distinctive, production-grade UIs instead of generic "AI-looking" designs