SkillSpector

Vet an agent skill before you install it, with a 0-100 risk score and line-level findings

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.

No video published yet. The write-up below covers what the tool does and how to try it.

Category
Security & privacy
Audience
Developers
Language
Python
Licence
Apache-2.0

Published Updated

SkillSpector is a security scanner for AI agent skills — the bundles of instructions and helper scripts that coding agents such as Claude Code, Codex CLI and Gemini CLI load and run on your machine. It is written for developers and teams who install those skills from GitHub repositories, zip files and links passed around in chat, and who have no realistic way to read every file in every bundle first. NVIDIA publishes it in Python under Apache-2.0; the repository has gathered roughly 18,900 stars and 1,650 forks since it appeared in March 2026.

What it does

The project starts from a measurement rather than a worry. In the 31,132-skill analyzed subset of the research dataset behind the tool, 26.1% of skills contained vulnerabilities and 5.2% showed likely malicious intent. Agent skills, as the README puts it, execute with implicit trust and minimal vetting, so SkillSpector is aimed at one question: is this skill safe to install?

To answer it, the scanner checks a skill bundle against 71 vulnerability patterns grouped into 17 categories. The categories the materials name include:

  • prompt injection, where hidden text in a skill redirects the agent that loads it
  • data exfiltration, where a skill ships your files, keys or conversation somewhere else
  • privilege escalation
  • supply-chain risk in whatever the skill pulls in

The result is a risk score from 0 to 100 plus a list of findings, and each finding points at the exact line that caused it. That last detail is what makes a report usable: you can argue with a specific line, while you can only shrug at a score.

How it works

Input is deliberately loose. You can scan a Git repository, a URL, a zip file, a directory or a single file, which matches how skills actually travel between people. From there the bundle goes through an analyzer pipeline whose architecture and package layout are documented in the project's development guide, and which is meant to be extended with new analyzers.

One design decision is worth calling out because it is unusual in a scanner of this kind. The repository ships a document on analysis resource bounds covering fail-closed ceilings for bundles, parsers, nested artifacts, the ledger and the findings list. A skill under inspection is hostile input: deeply nested archives or pathological files are a plausible way to make a scanner give up. Fail-closed means hitting a limit produces a refusal rather than a quiet pass.

SkillSpector is also not a standalone experiment. It is the scanning stage of the NVIDIA Verified Skills pipeline, which scans, evaluates and signs agent skills before publication, with skills that pass going into the NVIDIA skills catalog. So the same rules the tool applies on your laptop are the ones being applied to a published catalog.

Getting started

The badge in the README asks for Python 3.12 or newer. The fastest useful run is the one from the video: point the scanner at a GitHub repository or a zip file of the skill you were about to install, and read the score and the findings before you copy anything into your agent's skills directory.

NVIDIA hosts a guide on scanning agent skills before installation that covers when to scan, how to read a report and how to gate installs — the last of those matters most if you want this in a team workflow rather than as an occasional manual check. Two more documents cover running the scanner from inside an agent session instead of beside it: a Pi extension that installs SkillSpector as a Pi tool, and an OpenCode extension that adds it as an OpenCode tool with a /skillspector command. Either way, the agent can check a skill while you are still deciding about it.

When to use it / when not

Reach for it when a skill comes from somewhere you do not control, when you are about to add a skill to a shared repository that other people's agents will load, or when you want an install gate in CI rather than a habit you have to remember.

It is less useful in a few situations. This is pattern analysis, so a clean report means none of the 71 patterns matched, not that the skill is safe — a novel or carefully disguised attack can still pass. The findings are about security, not quality; nothing here tells you whether a skill does its job well. And the scope is skill bundles, so your model choice, your agent's own permissions and the rest of your setup remain your problem.

Anyone who installs agent skills casually — which, given how skills are shared, is most people using Claude Code, Codex or MCP tooling — should treat this repository as the missing step in that workflow. The numbers in its README are the argument: a quarter of the skills in a large sample carried vulnerabilities, and installing one is handing a stranger's instructions to a program that can read your files and run commands. A scan that takes seconds and names the offending line is a cheap way to stop doing that blind, and the fail-closed resource bounds and the signing pipeline behind it suggest the authors understand that the thing being scanned may be trying to win.

More in Security & privacy

All of Security & privacy →