SkillSpector: Security Scanner for AI Agent Skills
What SkillSpector is
SkillSpector is a security scanner for AI agent skills, published by NVIDIA under the Apache-2.0 license. Agent skills are the packaged instructions, scripts, and dependencies that coding agents such as Claude Code, Codex CLI, and Gemini CLI load to extend what they can do. The README points out that these skills execute with implicit trust and minimal vetting, and cites research to make the point: in a 31,132-skill analyzed subset of a dataset from the paper "Agent Skills in the Wild: An Empirical Study of Security Vulnerabilities at Scale" (Liu et al., 2026), 26.1% of skills contained at least one vulnerability and 5.2% showed likely malicious intent. The same research reports that skills with executable scripts are 2.12 times more likely to be vulnerable.
The question SkillSpector is built to answer is short: is this skill safe to install? It takes a skill from a Git repository, URL, zip file, directory, or single SKILL.md file, analyzes it, and returns a 0-100 risk score with a severity label and a recommendation. It is also part of NVIDIA's Verified Skills pipeline, which scans, evaluates, and signs skills before they are published to the NVIDIA skills catalog.
It is aimed at developers who install third-party skills, platform teams who want to gate skill installation in CI or inside agent sessions, and anyone running a skill marketplace.
How it works
SkillSpector uses a two-stage detection pipeline, orchestrated as a LangGraph workflow.
Stage 1: static analysis
The first stage runs regex-based pattern matching across 11 static analyzers, AST-based behavioral analysis that looks for dangerous calls such as exec, eval, and subprocess, taint tracking from sources to sinks, YARA signature matching, and live vulnerability lookups against OSV.dev for declared dependencies. The README describes this stage as high recall with moderate precision, meaning it catches most issues but produces some false positives.
Stage 2: LLM semantic analysis (optional)
The second stage sends file contents to a configured LLM to evaluate context and intent, filter false positives, and write human-readable explanations. The README claims this improves precision to around 87%, and says the prompt includes anti-jailbreak protections so a malicious skill cannot talk the analyzer out of flagging it. Pass --no-llm to skip this stage.
Risk scoring
Each finding adds to the score: 50 points for critical, 25 for high, 10 for medium, and 5 for low, with a 1.3x multiplier when the skill contains executable scripts. Scores of 0-20 map to LOW and SAFE, 21-50 to MEDIUM and CAUTION, and anything above 50 to HIGH or CRITICAL with a DO NOT INSTALL recommendation.
Key features
- 71 vulnerability patterns in 17 categories: prompt injection, data exfiltration, privilege escalation, supply chain, excessive agency, output handling, system prompt leakage, memory poisoning, tool misuse, rogue agent, anti-refusal, trigger abuse, dangerous code via AST, taint tracking, YARA signatures, MCP least privilege, and MCP tool poisoning.
- Agent-specific checks: patterns such as overly broad triggers, triggers that shadow built-in commands, instructions to never refuse, and hidden directives in MCP tool metadata using zero-width characters or homoglyphs.
- Supply chain checks: unpinned and abandoned dependencies, typosquatting,
curl | bashstyle fetching, shipped Python bytecode, and dependency source redirection. - Multiple output formats: terminal, JSON, Markdown, and SARIF 2.1.0 for CI and IDE tooling.
- Baselines: accept known findings via glob rules or exact fingerprints so later scans report only new issues.
- Many LLM providers: OpenAI, Anthropic, AWS Bedrock, Azure OpenAI, NVIDIA build.nvidia.com, Ollama, any OpenAI-compatible endpoint, and local Claude, Codex, Gemini, or OpenCode CLIs that reuse their own login sessions.
- MCP server mode: exposes a single
scan_skilltool so an agent can check a skill and gate its own installs on the result. - Stable integration contract: documented exit codes and JSON shape, plus a Python API.
- Fail-closed ingest limits: a 100 MiB per-ingest cap and a 10,000-member zip cap guard against oversized downloads and zip bombs.
Getting started
The quickest path is a CLI-only install with uv:
uv tool install git+https://github.com/NVIDIA/skillspector.git
# Update later: uv tool update skillspectorIf you want MCP server mode, install the extra:
uv tool install 'skillspector[mcp] @ git+https://github.com/NVIDIA/skillspector.git'Basic scans:
# Scan a local skill directory
skillspector scan ./my-skill/
# Scan a single SKILL.md file
skillspector scan ./SKILL.md
# Scan a Git repository
skillspector scan https://github.com/user/my-skill
# Scan a zip file
skillspector scan ./my-skill.zipFor CI, emit SARIF, and to keep scans fully local, skip the LLM stage:
skillspector scan ./my-skill/ --format sarif --output report.sarif
skillspector scan ./my-skill/ --no-llmA Dockerfile based on python:3.12-slim-bookworm is included if you would rather not install Python:
docker build -t skillspector .
docker run --rm -v "$PWD:/scan" skillspector scan ./my-skill/ --no-llmTo register it as an MCP tool in Claude Code:
claude mcp add skillspector -- skillspector mcpUse cases
- Vetting a skill before install: run a scan on a skill's Git URL before adding it to your agent and read the explanations for any HIGH findings.
- CI gating for a skills repository: use exit codes (0 for score 50 or below, 1 for above 50 or a strict gate firing, 2 for errors) with
--fail-on-findingsor--fail-on-incompletefor stricter policies, and upload SARIF to code scanning. - Runtime guardrail inside an agent: run
skillspector mcpso the agent itself callsscan_skilland refuses installs that come backsafe_to_install: false. - Marketplace or catalog review: the batch scanner in
contrib/batch_scan/scans whole directories of skills in parallel and supports zh, ja, and ko detection. - Tracking regressions: commit a baseline file and only new findings affect the score on later scans.
How it compares
The README does not compare SkillSpector against named alternatives. In practical terms it sits between general static analysis tools and secret scanners on one side and agent runtime sandboxes on the other. Its distinguishing scope is that it understands agent-specific attack surfaces, such as prompt injection inside SKILL.md, trigger abuse, and MCP tool poisoning, alongside conventional code and dependency checks. It is a pre-install check rather than an isolation layer, so it complements rather than replaces sandboxing.
Things to know before adopting
- Data egress: LLM analysis is on by default and sends analyzer-eligible file contents to the configured provider. The default provider is
nv_build. Use--no-llmto keep content local. - OSV.dev lookups always run: the SC4 dependency check sends package names and versions to OSV.dev even with
--no-llm, falling back to a small bundled list when offline. - Not a sandbox: SkillSpector never executes the skill, and it does not contain a skill you decide to install anyway.
- Stated limitations: it may miss patterns in non-English content, cannot read text inside images, cannot analyze compiled or encrypted code, and does not observe runtime behavior.
- HTTP MCP transport has no authentication: put it behind an authenticating reverse proxy before exposing it. Local paths and
file://URLs are rejected over HTTP. - Version pinning quirks: the
opencode_cliprovider fails closed unless OpenCode 1.18.32 is installed, and the README notes a known initialize hang on the stdio MCP transport. - Python 3.12+ is required for non-Docker installs.
Project activity
As of October 2026 the repository has roughly 19,000 stars. It was created on March 21, 2026, is written in Python, and is licensed under Apache-2.0. Source code is at github.com/NVIDIA/SkillSpector, and the hosted guide to scanning skills before installation is at docs.nvidia.com/skills/scanning-agent-skills. The repository also includes a development guide, suppression documentation, and extensions for running SkillSpector from inside Pi and OpenCode sessions.
Enjoying this project?
Discover more amazing open-source projects on TechLogHub. We curate the best developer tools and projects.
Repository:https://github.com/NVIDIA/SkillSpector
GitHub - NVIDIA/SkillSpector: SkillSpector: Security Scanner for AI Agent Skills
SkillSpector is NVIDIA's open-source security scanner for AI agent skills. It combines static analysis, AST and taint checks, YARA rules, and optional LLM revie...
github - nvidia/skillspector
Related Projects
Scrapling: Adaptive Web Scraping Framework for Python
Python scraping framework with an adaptive parser, HTTP and browser fetchers, and Scrapy-style spiders.
Docling: Document Parsing for Generative AI
Python toolkit that converts PDFs, Office docs, HTML, audio and more into structured Markdown or JSON for AI pipelines.
Hindsight: Agent Memory That Learns Over Time
Open-source agent memory server with retain, recall and reflect APIs, multi-strategy retrieval and 60+ integrations.

