SkillSpector
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.
SkillSpector is a security scanning agent skill from NVIDIA that analyzes AI agent skills, MCP servers, and plugins for vulnerabilities before installation. It detects 71 vulnerability patterns across 17 categories including prompt injection, data exfiltration, privilege escalation, and supply-chain risks. The tool combines fast static analysis with optional LLM-powered semantic evaluation to provide risk scores and installation recommendations. It can scan Git repositories, directories, zip files, or individual skill files, and runs as a CLI tool, Docker container, or MCP server.
Key Features
Use Cases
- 01Scanning third-party agent skills from marketplaces before installation to detect malicious code or vulnerabilities
- 02CI/CD pipeline integration to block deployment of skills with high-severity security issues using SARIF output
- 03Runtime install gates by running as an MCP server that agents call before approving skill installations
- 04Batch security audits of entire skill directories to identify vulnerable or abandoned dependencies
- 05Compliance verification for enterprise agent deployments requiring vetted, signed skills
- 06Developer workflow integration via IDE tooling using SARIF format for inline security warnings
Related Skills
View moresuperpowers
An agentic skills framework & software development methodology that works.
skills
Skills for Real Engineers. Straight from my .agents directory.
skills
Public repository for Agent Skills
ponytail
Makes your AI agent think like the laziest senior dev in the room. The best code is the code you never wrote.
SkillSpector — FAQ
What is SkillSpector?+
SkillSpector is a security scanner for AI agent skills, MCP servers, and plugins that detects 71 vulnerability patterns including prompt injection, data exfiltration, and supply-chain risks before you install them. It provides risk scores and installation recommendations based on static analysis and optional LLM evaluation.
How do I install SkillSpector?+
Install via uv with 'uv tool install git+https://github.com/NVIDIA/skillspector.git' for CLI-only use, or add '[mcp]' extra for MCP server mode. Alternatively, use 'make install' from source after cloning the repo, or run via Docker without installing Python.
Which AI clients work with SkillSpector?+
SkillSpector runs as a standalone CLI tool to scan any skill file or repo. In MCP server mode, it integrates with Claude Code, Codex CLI, Gemini CLI, and other MCP-capable agents to gate skill installations at runtime.
Do I need an API key to use SkillSpector?+
No API key is required for static-only analysis (--no-llm flag). For optional LLM semantic analysis, you need credentials for one of the supported providers: OpenAI, Anthropic, AWS Bedrock, NVIDIA build.nvidia.com, Ollama, Azure OpenAI, or local Claude/Codex/Gemini CLI sessions.
Is SkillSpector free to use?+
Yes, SkillSpector is open source under Apache 2.0 license and free to use. Static analysis requires no external services. LLM analysis incurs costs from your chosen provider (e.g., OpenAI, Anthropic), but local/CLI providers like Ollama or Claude CLI have no additional charge.
What are the system requirements?+
SkillSpector requires Python 3.12+ for local installation, or Docker for containerized use. For LLM analysis, you need network access to your chosen provider API or a local model server like Ollama. Live SC4 vulnerability checks require outbound HTTPS to api.osv.dev.
How do I install SkillSpector?+
Open the source repository on GitHub and follow its README. SkillSpector is a skill — MCP Agents Market links you directly to the official repo.
Is SkillSpector free?+
SkillSpector is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.