NVIDIA open-sources SkillSpector, a scanner for risky AI agent skills
dr_cintas · x · 2026-07-23
NVIDIA has open-sourced SkillSpector, a security scanner for AI agent skills used by tools like Claude Code, Codex CLI, and Gemini CLI.
- It can scan a skill from a folder, single file, GitHub link, or zip archive.
- The tool runs a fast static pass to flag credential harvesting, data leaks, and known CVEs in dependencies.
- An optional LLM pass then checks intent to reduce false positives.
- Output is a single risk score from 0 to 100 with a plain verdict: safe, caution, or do not install.
- The README says it is free and includes support for multi-format input, multiple output formats, and checks for patterns like prompt injection, data exfiltration, privilege escalation, and MCP tool poisoning.
Related event: NVIDIA Open-Sources SkillSpector for AI Agent Security(3 posts)→
More from coding & agent
- GPT-6 Astra beats Factorio with enemies in 44 in-game hours at ~$4,500 API cost — liminal_bardo · 2026-09-11
- Investment Analyst Asks How to Build a Claude-Based Diligence Agent Stack — Careless_Tie2286 · 2026-09-11
- How Do You Catch Behavioral Regressions in LLM Agents Between Releases? — Beautiful_Belt_601 · 2026-09-11
- Treating agents like 50 First Dates: a 3-layer context system so every conversation doesn't start from zero — evielync · 2026-09-11
- Running the Firefox MCP on Android via Termux, ngrok, and mcp-proxy — Nervous-Strain7544 · 2026-09-11
- Run Firefox MCP on Android: Termux + ngrok tunnel tutorial — Nervous-Strain7544 · 2026-09-11