NVIDIA/SkillSpector

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.

Open original source ↗

From the publisher

README & documentation

Source preview

Read the project’s overview, installation instructions and usage examples. The original README is the source of truth.

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, and security risks before installing agent skills. [](https://www.python.org/downloads/) [](https://www.apache.org/licenses/LICENSE-2.0) AI agent skills (used by Claude Code, Codex CLI, Gemini CLI, etc.) execute with implicit trust and minimal vetting. In the 31,132-skill analyzed subset of the research dataset, 26.1% of skills contain vulnerabilities and 5.2% show likely malicious intent. SkillSpector helps you answer: "Is this skill safe to install?" SkillSpector is part of the NVIDIA Verified Skills pipeline, which scans, evaluates, and signs agent skills before publication. Skills that pass are published to the NVIDIA skills catalog. Create and activate a virtual environment first (all make targets assume the venv is active). Use uv or pip; the Makefile uses uv if available, otherwise pip. Quick install with uv (CLI-only): If you plan to run skillspector mcp, install the MCP extra at install time: From source: Run SkillSpector without installing Python by…

NVIDIA/SkillSpector on GitHub A short preview, not the full document.

Read the full README ↗ · Preview checked 2026-09-29T13:59:09.707Z

Inside the original README — Document outline
  1. SkillSpector
  2. Overview
  3. Documentation
  4. Features
  5. Quick Start
  6. Installation
  7. Docker (no Python required)
  8. Basic Usage
  9. Size limits
  10. Output Formats
  11. Batch Scanning
  12. Suppressing False Positives (baseline)

Headings are captured from the source. Links open the publisher’s document, not a locally hosted copy.

Links from the README

References supplied by the publisher, not independently verified endorsements. Check the destination before downloading files or entering credentials.

Documentation belongs to its respective authors. Reported project/model license: Apache-2.0. A listing is not a grant of reuse or training rights. Confirm the document’s own terms at the source.

What this repository does

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.

Repository facts

Owner
NVIDIA
Primary language
Python
Stars
18,564
Forks
1,620
Open issues + pull requests
139
License
Apache-2.0
Archived
No
Default branch
main
Created
2026-03-21T00:28:43.000Z
Last push
2026-09-28T21:33:38.000Z

Topics and intended use

Owner-supplied topics: agent-security, agent-skills, agentic-ai, ai-security, claude-code, mcp, prompt-injection, security-scanner, security-tools, security-workflow, supply-chain-security

Review the README for scope, installation, examples and limitations. We do not run repository code or certify it.

Evaluate before installing

Review licensing and dependencies, inspect recent commits and unresolved issues, and test in an isolated environment before production use. Stars and forks alone cannot answer these questions.

README and project files

Issues and maintenance discussion

Releases and changelog

Source and freshness

Source: GitHub. Metadata observed 2026-09-29T12:04:09.244Z. Daily imports are snapshots, not real-time monitoring.

Popularity and source listings do not establish security, suitability, licensing rights or benchmark performance.

Open original source

Related repositories

public-apis/public-apis

EbookFoundation/free-programming-books

donnemartin/system-design-primer

vinta/awesome-python

practical-tutorials/project-based-learning

NousResearch/hermes-agent