10 open-source projects for securing AI agent skills, plus what they all miss

bibryam · x · 2026-09-10

bibryam shares a curated list of 10 open-source projects for securing AI agent skills — from pre-install scanning and supply-chain controls to sandboxing and runtime governance: NVIDIA SkillSpector, Cisco AI Defense Skill Scanner, SkillWard, Agent Audit, AgentShield, Microsoft Agent Package Manager, NVIDIA Verified Agent Skills, NVIDIA OpenShell, Kubernetes Agent Sandbox, and Microsoft Agent Governance Toolkit.

Quoting itayglick's critique: none of these tools publishes measured efficacy — what they catch beyond what the model already refuses on its own. Also, most only scan before install, while only the last few enforce at runtime; you need both layers, since a skill can turn malicious after installation.

Original post →

More from coding & agent

coding & agent channel →