Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.
Scan AI agent skills for security risks and vulnerabilities before using them with SkillSpector.
uv tool install git+https://github.com/NVIDIA/skillspector.git # Update later: uv tool update skillspector
Excerpts from the project README on GitHub. Copyright and licensing remain with the respective authors.
Claim its page: indexed whatever its rank, translated into six languages, and enriched with what you write yourself.
Get an email alert on its next release or when it starts trending — never miss the moment.
Free · no card · unsubscribe anytimeSecurity scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.
SkillSpector has 15.3k stars on GitHub. It has been forked 1.3k times. SkillSpector is written mainly in Python. It has been in active development since 2026. SkillSpector is available under the Apache-2.0 license. Its main topics are agent-security, agent-skills, agentic-ai, ai-security.
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.
SkillSpector is an open-source project. It is released under the Apache-2.0 license.
Yes. SkillSpector is free and open source — you can use, modify and self-host it.
SkillSpector is available under the Apache-2.0 license.
SkillSpector is written mainly in Python.
Add this live badge to your README — your GitHub stars and directory rank, refreshed daily.
[](https://olud.ai/project/nvidia-skillspector.html)
Measured from GitHub topics shared by both projects, weighted by how rare each topic is.