Ross ROSS = Recommend OSS · open-source software intelligence for agents

NVIDIA/SkillSpector

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them. observed · 2026-08-28

github.com/NVIDIA/SkillSpector · homepage · Python · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

81/100

  • Activity 99
  • Release rhythm 99
  • Longevity 11

Flags: young

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 1.5
  • age_days: 166
  • days_rel: 7
  • days_push: 7
  • n_releases_24m: 13

Full methodology

Adoption not part of the score

15011 stars · 1257 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

SkillSpector is a security scanner for AI agent skills used by Claude Code, Codex CLI, Gemini CLI, and MCP-based agents. It detects vulnerabilities, malicious patterns, prompt injection, data exfiltration, and supply-chain risks before a skill is installed, using static analysis plus optional LLM semantic evaluation.

Use cases

  • scan an agent skill for prompt injection before installing it
  • check if a Claude Code skill is safe to install
  • detect data exfiltration patterns in MCP skills
  • audit agent skills for supply-chain risks
  • generate SARIF reports for skill security findings
  • gate skill installation in CI with a risk score
  • suppress known false positives in skill re-scans

When to choose

  • you install third-party agent skills and want to vet them first
  • you publish agent skills and need a security tier in your release pipeline
  • you need SARIF/JSON security reports for agent skill bundles
  • you want CVE lookups via OSV.dev plus static and semantic analysis in one tool

When to avoid

  • you need general-purpose SAST for ordinary application code
  • you need runtime sandboxing or enforcement rather than pre-install scanning
  • you need a GUI-based security dashboard

Facets

cli-tool · maturity active

security vulnerability-scanning linter developer-tools dependency-audit security developer-tools large-language-models python cli cross-platform agent-skills prompt-injection mcp claude-code supply-chain-security sarif llm-analysis yara ai-agents

9 sources

Member repositories

RepositoryRoleHealth v2
NVIDIA/SkillSpectormain81

For agents

markdown · JSON · MCP: product_card(name="NVIDIA/SkillSpector")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem