NVIDIA open-sources SkillSpector, a scanner for risky AI agent skills
dr_cintas · x · 2026-07-23
NVIDIA has open-sourced SkillSpector, a security scanner for AI agent skills used by tools like Claude Code, Codex CLI, and Gemini CLI.
- It can scan a skill from a folder, single file, GitHub link, or zip archive.
- The tool runs a fast static pass to flag credential harvesting, data leaks, and known CVEs in dependencies.
- An optional LLM pass then checks intent to reduce false positives.
- Output is a single risk score from 0 to 100 with a plain verdict: safe, caution, or do not install.
- The README says it is free and includes support for multi-format input, multiple output formats, and checks for patterns like prompt injection, data exfiltration, privilege escalation, and MCP tool poisoning.
Related event: NVIDIA Open-Sources SkillSpector for AI Agent Security(3 posts)→
More from coding & agent
- HeyGen’s HyperFrames adds a storyboard-first workflow for AI video generation — HeyGen · 2026-07-23
- W&B adds stronger agent tracing, harness integrations and automated evals in Weave — _ScottCondron · 2026-07-23
- Claude Managed Agents adds effort levels, sub-agent streaming and session seeding — EricBuess · 2026-07-23
- AI Autopilot Drives Open-Source Maintenance: Running Hourly to Triage PRs — jiayuan_jy · 2026-07-23
- Embodied Agent Eval: Two Scenes Hit 100% Zero-Shot Success Rate — wandb · 2026-07-23
- A high-school builder’s “Taste Skill” for AI frontend design hits 67,000 stars — soumitrashukla9 · 2026-07-23