Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.
git clone https://github.com/NVIDIA/SkillSpector && cp SkillSpector/*.md ~/.claude/agents/Subagents overview
# SkillSpector **Security scanner for AI agent skills.** Detect vulnerabilities, malicious patterns, and security risks before installing agent skills. [](https://www.python.org/downloads/) [](https://www.apache.org/licenses/LICENSE-2.0) ## Overview AI agent skills (used by Claude Code, Codex CLI, Gemini CLI, etc.) execute with implicit trust and minimal vetting. Research shows that **26.1% of skills contain vulnerabilities** and **5.2% show likely malicious intent**. SkillSpector helps you answer: **"Is this skill safe to install?"** SkillSpector is part of the [NVIDIA Verified Skills pipeline](https://docs.nvidia.com/skills/), which scans, evaluates, and signs agent skills before publication. Skills that pass are published to the [NVIDIA skills catalog](https://github.com/NVIDIA/skills). ## Documentation - **[Scan agent skills before installation](https://docs.nvidia.com/skills/scanning-agent-skills)** — Hosted guide: when to scan, how to read a report, and how to gate installs. - **[Development guide](docs/DEVELOPMENT.md)** — Architecture, package layout, and how to extend the analyzer pipeline. - **[Pi extension](docs/PI_EXTENSION.md)** — Install SkillSpector as a Pi tool for scanning skills from inside agent sessions. ## Features - **Multi-format input**: Scan Git repos, URLs, zip files, directories, or single files - **68 vulnerability patterns** across 17 categories: prompt injection, data exfiltration, privilege escalation, supply chain, excessive agency, output handling, system prompt leakage, memory poisoning, tool misuse, rogue agent, anti-refusal, trigger abuse, dangerous code (AST), taint tracking, YARA signatures, MCP least privilege, and MCP tool poisoning - **Two-stage analysis**: Fast static analysis + optional LLM semantic evaluation - **Live vulnerability lookups**: SC4 queries [OSV.dev](https://osv.dev) for real-time CVE data with automatic offline fallback - **Multiple output formats**: Terminal, JSON, Markdown, and SARIF reports - **Risk scoring**: 0-100 score with severity labels and clear recommendations - **Baseline / false-positive suppression**: Accept known findings via a glob-rule or fingerprint baseline so re-scans surface only *new* issues ([docs](docs/SUPPRESSION.md)) ## Quick Start ### Installation > **Open-source software notice:** This project will download and install additional third-party open source software projects. Review the license terms of these open source projects before use. Create and activate a virtual environment first (all `make` targets assume the venv is active). Use **uv** or **pip**; the Makefile uses `uv` if available, otherwise `pip`. **Quick install with uv (CLI-only):** ```bash uv tool install git+https://github.com/NVIDIA/skillspector.git # Update later: uv tool update skillspector ``` If you plan to run `skillspector mcp`, install the MCP extra at install time: ```bash uv tool install 'skillspector[mcp] @ git+https://github.com/NVIDIA/skillspector.git' ``` **From source:** ```bash # Clone the repository git clone https://github.com/NVIDIA/skillspector.git cd skillspector # Create and activate virtual environment uv venv .venv && source .venv/bin/activate # or: python3 -m venv .venv && source .venv/bin/activate # Install for production use make install # Or install with development dependencies make install-dev ``` ### Docker (no Python required) Run SkillSpector without installing Python by building it locally from the included [Dockerfile](Dockerfile). The image is based on the Docker Official Python `3.12-slim-bookworm` image. **Build the image:** ```bash make docker-build # or: docker build -t skillspector . ``` **Scan a local directory** by mounting your current directory into `/scan`, the container's working directory: ```bash docker run --rm -v "$PWD:/scan" skillspector scan ./my-skill/ --no-llm ``` **Scan with LLM analysis** by passing credentials with a local `.env` file: ```bash cat > .env <<'EOF' SKILLSPECTOR_PROVIDER=anthropic ANTHROPIC_API_KEY=sk-ant-... EOF ``` ```bash docker run --rm \ -v "$PWD:/scan" \ --env-file .env \ skillspector scan ./my-skill/ ``` Or pass credentials directly from your shell environment: ```bash docker run --rm \ -v "$PWD:/scan" \ -e SKILLSPECTOR_PROVIDER=anthropic \ -e ANTHROPIC_API_KEY="$ANTHROPIC_API_KEY" \ skillspector scan ./my-skill/ ``` **Write a report to the host filesystem** by writing to the mounted directory: ```bash docker run --rm \ -v "$PWD:/scan" \ skillspector scan ./my-skill/ --no-llm --format json --output report.json ``` **Optional alias** for repeated static scans: ```bash alias skillspector-docker='docker run --rm -v "$PWD:/scan" skillspector' skillspector-docker scan ./my-skill/ --no-llm ``` ### Basic Usage ```bash # Scan a local skill directory skillspector scan ./my-skill/ # Scan a single SKILL.md file skillspector scan ./SKILL.md # Scan a Git repository skillspector scan https://github.com/user/my-skill # Scan a zip file skillspector scan ./my-skill.zip ``` #### Size limits SkillSpector enforces two independent caps on remote and archive inputs to bound the impact of oversized downloads and zip bombs: - **Per-ingest cap**: `INGEST_MAX_BYTES` (100 MiB) — applied to streamed URL downloads, total uncompressed size of zip archives, and post-clone disk usage of Git repos. - **Zip member cap**: `INGEST_MAX_ZIP_MEMBERS` (10,000) — caps the number of entries in a single zip. Note that the per-file 1 MB analysis cap (`MAX_FILE_BYTES`) is a separate, downstream limit: it bounds what individual analyzers will read out of an already-ingested directory. The ingest caps above bound how much content can land on disk in the first place. A breach of either ingest cap fails closed with an `IngestLimitExceededError`. ### Output Formats ```bash # Terminal output (default) - pretty formatted skillspector scan ./my-skill/ # JSON output - machine readable skillspector scan ./my-skill/ --format json --output report.json # Markdown output - for documentation skillspector scan ./my-skill/ --format markdown --output report.md # SARIF output - for CI/CD integration and IDE tooling skillspector scan ./my-skill/ --format sarif --output report.sarif ``` ### Batch Scanning Scan entire directories of skills in parallel from `contrib/batch_scan/`: ```bash python -m contrib.batch_scan.batch_scan ./my-skills/ --no-llm python -m contrib.batch_scan.batch_scan ./my-skills/ --workers 20 -f json -o report.json python -m contrib.batch_scan.batch_scan ./tests/fixtures/ -f terminal --workers 20 ``` Supports multilingual detection (zh/ja/ko) and terminal/JSON/Markdown output. For LLM scans with higher concurrency, configure multiple API keys following [`.env.example`](contrib/batch_scan/.env.example) — the pool improves throughput and resilience, provided the keys don't share an account-level rate limit. See the [contrib guide](contrib/batch_scan/docs/) for details. > **Note on LLM support:** The default configuration targets DeepSeek as the > cheapest public option. DeepSeek-Chat is > [expected to sunset](https://api-docs.deepseek.com/), and the contributor > does not have hardware to test against local models. The batch scanner was > originally tested with OpenAI-compatible endpoints — DeepSeek's lack of > structured-output support required manual JSON-parsing patches. If you can > contribute a more universal backend (Ollama, vLLM, or a different provider), > PRs are very welcome. ### Suppressing False Positives (baseline) Suppress known/accepted findings so the risk score reflects only un-triaged issues and re-scans surface only *new* findings. See the [suppression guide](docs/SUPPRESSION.md) for the full reference. ```bash # Accept all current findings into a baseline (run once), then commit it. skillspector baseline ./my-skill/ -o .skillspector-baseline.yaml # Scan against the baseline — only NEW findings are reported and scored. skillspector scan ./my-skill/ --baseline .skillspector-baseline.yaml # Review what was suppressed (still excluded from the score). skillspector scan ./my-skill/ --baseline .skillspector-baseline.yaml --show-suppressed ``` A baseline can also use drift-tolerant glob rules (by rule id, file path, or message) — see [`.skillspector-baseline.example.yaml`](.skillspector-baseline.example.yaml). Exact fingerprint baselines are evidence-bound: changing the scanned source or SkillSpector version keeps the finding active until it is reviewed again. ### LLM Analysis For the best results, configure an OpenAI-compatible LLM endpoint for semantic analysis. Pick a provider with `SKILLSPECTOR_PROVIDER`; hosted providers ship bundled default models, while CLI providers fall back to the local runtime's default model unless `SKILLSPECTOR_MODEL` is set. SkillSpector also works against local OpenAI-compatible servers (Ollama, vLLM, llama.cpp) and managed inference gateways. | Provider (`SKILLSPECTOR_PROVIDER`) | Credential env var | Endpoint | Default model | | ---------- | ---- | ---- | ---- | | `openai` | `OPENAI_API_KEY` (+ optional `OPENAI_BASE_URL`) | api.openai.com (or any OpenAI-compatible URL) | `gpt-5.4` | | `anthropic` | `ANTHROPIC_API_KEY` | api.anthropic.com | `claude-opus-4-6` | | `anthropic_proxy` | `ANTHROPIC_PROXY_API_KEY` + `ANTHROPIC_PROXY_ENDPOINT_URL` | Any Vertex-style raw-predict proxy | `claude-sonnet-4-6` | | `bedrock` | `AWS_PROFILE` (optional) + `AWS_REGION` — SigV4 via boto3 | AWS Bedrock Runtime | `us.anthropic.claude-sonnet-4-6-20250915-v1:0` | | `nv_build` | `NVIDIA_INFERENCE_KEY` | build.nvidia.com | `deepseek-ai/deepseek-v4-flash` | | `claude_cli` | _(none — uses local CLI auth)_ | local `claude` binary | local Claude runtime fallback, or `SKILLSPECTOR_MODEL` | | `codex_cli` | _(none — uses local CLI auth)_ | local `codex` binary | local Codex runtime fallba
What people ask about SkillSpector
What is NVIDIA/SkillSpector?
+
NVIDIA/SkillSpector is subagents for the Claude AI ecosystem. Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them. It has 14.2k GitHub stars and was last updated today.
How do I install SkillSpector?
+
You can install SkillSpector by cloning the repository (https://github.com/NVIDIA/SkillSpector) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.
Is NVIDIA/SkillSpector safe to use?
+
NVIDIA/SkillSpector has not been audited yet by our security agent. Review the original repository on GitHub before using it in production.
Who maintains NVIDIA/SkillSpector?
+
NVIDIA/SkillSpector is maintained by NVIDIA. The last recorded GitHub activity is from today, with 96 open issues.
Are there alternatives to SkillSpector?
+
Yes. On ClaudeWave you can browse similar subagents at /categories/agents, sorted by popularity or recent activity.
Deploy SkillSpector to your cloud
Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.
Maintain this repo? Add a badge to your README
Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.
[](https://claudewave.com/repo/nvidia-skillspector)<a href="https://claudewave.com/repo/nvidia-skillspector"><img src="https://claudewave.com/api/badge/nvidia-skillspector" alt="Featured on ClaudeWave: NVIDIA/SkillSpector" width="320" height="64" /></a>More Subagents
The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.
The agent that grows with you
Java 面试 & 后端通用面试指南,覆盖计算机基础、数据库、分布式、高并发、系统设计与 AI 应用开发
Build Agentic workflows, RAG pipelines, with rich AI model and tool support on one collaborative workspace. Deploy on cloud, VPC, or self-hosted, so teams move from prototype to production without rebuilding the stack.
The agent engineering platform.
Turn any codebase, with its docs, SQL schemas, configs, and PDFs, into a queryable knowledge graph. A /graphify skill for Claude Code, Cursor, Codex, and Gemini CLI: local deterministic AST parsing, every edge explained, no vector store.