NVIDIA/SkillSpector
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.
From the publisher
README & documentation
Source previewRead the project’s overview, installation instructions and usage examples. The original README is the source of truth.
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, and security risks before installing agent skills. [](https://www.python.org/downloads/) [](https://www.apache.org/licenses/LICENSE-2.0) AI agent skills (used by Claude Code, Codex CLI, Gemini CLI, etc.) execute with implicit trust and minimal vetting. In the 31,132-skill analyzed subset of the research dataset, 26.1% of skills contain vulnerabilities and 5.2% show likely malicious intent. SkillSpector helps you answer: "Is this skill safe to install?" SkillSpector is part of the NVIDIA Verified Skills pipeline, which scans, evaluates, and signs agent skills before publication. Skills that pass are published to the NVIDIA skills catalog. Create and activate a virtual environment first (all make targets assume the venv is active). Use uv or pip; the Makefile uses uv if available, otherwise pip. Quick install with uv (CLI-only): If you plan to run skillspector mcp, install the MCP extra at install time: From source: Run SkillSpector without installing Python by…
Read the full README ↗ · Preview checked 2026-09-29T13:59:09.707Z
Inside the original README — Document outline
- SkillSpector
- Overview
- Documentation
- Features
- Quick Start
- Installation
- Docker (no Python required)
- Basic Usage
- Size limits
- Output Formats
- Batch Scanning
- Suppressing False Positives (baseline)
Headings are captured from the source. Links open the publisher’s document, not a locally hosted copy.
Links from the README
References supplied by the publisher, not independently verified endorsements. Check the destination before downloading files or entering credentials.
Documentation belongs to its respective authors. Reported project/model license: Apache-2.0. A listing is not a grant of reuse or training rights. Confirm the document’s own terms at the source.
What this repository does
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.
Repository facts
- Owner
- NVIDIA
- Primary language
- Python
- Stars
- 18,564
- Forks
- 1,620
- Open issues + pull requests
- 139
- License
- Apache-2.0
- Archived
- No
- Default branch
- main
- Created
- 2026-03-21T00:28:43.000Z
- Last push
- 2026-09-28T21:33:38.000Z
Topics and intended use
Owner-supplied topics: agent-security, agent-skills, agentic-ai, ai-security, claude-code, mcp, prompt-injection, security-scanner, security-tools, security-workflow, supply-chain-security
Review the README for scope, installation, examples and limitations. We do not run repository code or certify it.
Evaluate before installing
Review licensing and dependencies, inspect recent commits and unresolved issues, and test in an isolated environment before production use. Stars and forks alone cannot answer these questions.
Source and freshness
Source: GitHub. Metadata observed 2026-09-29T12:04:09.244Z. Daily imports are snapshots, not real-time monitoring.
Popularity and source listings do not establish security, suitability, licensing rights or benchmark performance.
Related repositories
EbookFoundation/free-programming-books
donnemartin/system-design-primer