{"repo":"NVIDIA/SkillSpector","free":true,"listed":false,"github":"https://github.com/NVIDIA/SkillSpector","clone":"git clone https://github.com/NVIDIA/SkillSpector.git","description":"Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.","language":"Python","stars":14724,"topics":["agent-security","agent-skills","agentic-ai","ai-security","claude-code","mcp","prompt-injection","security-scanner","security-tools","security-workflow"],"license":"Apache-2.0","category":"mcp-servers","readme_excerpt":"SkillSpector Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, and security risks before installing agent skills. Overview AI agent skills (used by Claude Code, Codex CLI, Gemini CLI, etc.) execute with implicit trust and minimal vetting. Research shows that 26.1% of skills contain vulnerabilities and 5.2% show likely malicious intent . SkillSpector helps you answer: \"Is this skill safe to install?\" SkillSpector is part of the NVIDIA Verified Skills pipeline, which scans, evaluates, and signs agent skills before publication. Skills that pass are published to the NVIDIA skills catalog. Documentation - Scan agent skills before installation — Hosted guide: when to scan, how to read a report, and how to gate installs. - Development guide — Architecture, package layout, and how to extend the analyzer pipeline. - Pi extension — Install SkillSpector as a Pi tool for scanning skills from inside agent sessions. Features - Multi-format input : Scan Git repos, URLs, zip files, directories, or single files - 69 vulnerability patterns across 17 categories: prompt injection, data exfiltration, privilege escalation, supply chain, excessive agency, output handling, system prompt leakage, memory poisoning, tool misuse, rogue agent, anti-refusal, trigger abuse, dangerous code (AST), taint tracking, YARA signatures, MCP least privilege, and MCP tool poisoning - Two-stage analysis : Fast static analysis + optional LLM semantic evaluation - Live vulnerability looku","default_branch":null,"files":null,"tree":[],"storefront":"/r/NVIDIA","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/NVIDIA/SkillSpector/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}