10 open-source projects for securing AI agent skills, plus what they all miss
bibryam · x · 2026-09-10
bibryam shares a curated list of 10 open-source projects for securing AI agent skills — from pre-install scanning and supply-chain controls to sandboxing and runtime governance: NVIDIA SkillSpector, Cisco AI Defense Skill Scanner, SkillWard, Agent Audit, AgentShield, Microsoft Agent Package Manager, NVIDIA Verified Agent Skills, NVIDIA OpenShell, Kubernetes Agent Sandbox, and Microsoft Agent Governance Toolkit.
Quoting itayglick's critique: none of these tools publishes measured efficacy — what they catch beyond what the model already refuses on its own. Also, most only scan before install, while only the last few enforce at runtime; you need both layers, since a skill can turn malicious after installation.
More from coding & agent
- Open-source TIDAL MCP server ships 112 tools for music discovery via Claude and Cursor — Fickle_Guitar7417 · 2026-09-10
- CommerceAgentBench hits 1,000 GitHub stars with 107 tasks to vet e-commerce agents — VibeMarketer_ · 2026-09-10
- 8 AI tools gaining tons of GitHub stars this week: Skills, Archify, MiniMind and more — Shruti_0810 · 2026-09-10
- mcp-x: 42 X API tools designed so the model can't burn your money — GoldBroccoli7073 · 2026-09-10
- Replace RPA with Doubao's browser record-and-replay: automate link submissions — lxfater · 2026-09-10
- DeepSeek's new open model beats GLM 5.3 and Kimi K3 at 4-10x lower price — deedydas · 2026-09-10