SkillSpector
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.
AI代理技能安全扫描器。在安装之前,检测Claude Code、Codex和MCP技能中的漏洞、恶意模式、安全风险、提示注入、数据外泄和供应链风险。
How to install
git clone https://github.com/NVIDIA/SkillSpector ~/.claude/skills/SkillSpector About
SkillSpector **Security scanner for AI agent skills.** Detect vulnerabilities, malicious patterns, and security risks before installing agent skills. Overview AI agent skills (used by Claude Code, Codex CLI, Gemini CLI, etc.) execute with implicit trust and minimal vetting. Research shows that **26.1% of skills contain vulnerabilities** and **5.2% show likely malicious intent**. SkillSpector helps you answer: **"Is this skill safe to install?"** SkillSpector is part of the NVIDIA Verified Skills pipeline, which scans, evaluates, and signs agent skills before publication. Skills that pass are p…
Recommendation signals
Meta
- License
- Apache-2.0
- Language
- Python
- GitHub stars
- 18.2K
- mo. downloads
- –
- Last push
- 2026-09-24
- Created
- 2026-03-21
Links
Basic safety check
- Findings
- curated 收录但无 npm 包/安装命令
- Sources
- curated:hesreallyhim/awesome-claude-code
- Topics
- agent-security, agent-skills, agentic-ai, ai-security, claude-code, mcp, prompt-injection, security-scanner, security-tools, security-workflow, supply-chain-security
Related plugins
superpowers
obra/superpowers
An agentic skills framework & software development methodology that works.
dev-browser
SawyerHood/dev-browser
A Claude Skill to give your agent the ability to use a web browser
ruflo
ruvnet/claude-flow
🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated