TESIGN
SAVED

EN · KO

Auto-generated — not yet edited · only the numbers are verified

  1. TESIGN / RADAR
  2. REPOSITORY CARD
  3. nvidia/skillspector

nvidia/skillspector

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.

★ 17.1k▲ +38 / 7dDaily star increases over 14 days. Hollow bars mean no data. The last day may be partial.2026-09-03 +22026-09-04 +842026-09-05 +482026-09-06 +412026-09-07 +62026-09-08 no data2026-09-09 no data2026-09-10 +62026-09-11 +112026-09-12 +22026-09-13 +42026-09-14 +32026-09-15 +102026-09-16 +2largest one-day increase in the 14 days+84last 14 days · stars per dayhollow = no data

RANKS Rising 30d #94

AT A GLANCE

LANGUAGE
Python
LICENSE
Apache-2.0
USAGE
Commercial use, redistribution OK. Keep notices; mark changes.
ACTIVITY
last commit 4 days ago ()
TOPICS
  • agent-security
  • agent-skills
  • agentic-ai
  • ai-security
  • claude-code
  • mcp
  • prompt-injection
  • security-scanner
  • security-tools
  • security-workflow
  • supply-chain-security
HOMEPAGE
https://docs.nvidia.com/skills/scanning-agent-skills
REPOSITORY
GitHub ↗
CATEGORY
AI

A summary, not legal advice.

README EXCERPT

SkillSpector Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, and security risks before installing agent skills. Overview AI agent skills (used by Claude Code, Codex CLI, Gemini CLI, etc.) execute with implicit trust and minimal vetting. Research shows that 26.1% of skills contain vulnerabilities and 5.2% show likely malicious intent . SkillSpector helps you answer: "Is this skill safe to install?" SkillSpector is part of the NVIDIA Verified Skills pipeline, which scans, evaluates, and signs agent skills before publication. Skills that pass are published to the NVIDIA skills catalog. Documentation - Scan agent skills before installation — Hosted guide: when to scan, how to read a report, and how to gate installs. - Development guide — Architecture, package layout, and how to extend the analyzer pipeline. - Analysis resource bounds — Fail-closed bundle, parser, nested-artifact, ledger, and finding ceilings. - Pi extension — Install SkillSpector as a Pi tool for scanning skills from inside agent sessions. Features - Multi-format input : Scan Git repos, URLs, zip files, directories, or single files - 71 vulnerability patterns across 17 categories: prom…

The opening of the GitHub README as stored, at most 1,200 characters. Markdown is not rendered.

TIMELINE

  1. Repository created
  2. Last push
  3. FIRST SEEN BY TESIGN ◌ BACK CATALOG

AI chooses the lists under the owner’s delegation. No human review is running in September 2026. Total stars, increases, cross-source signals, last updates and licences are shown as evidence. How ranks work →

If this repository gets editorial text (why, build, who, start, caveat) it becomes an edited entry. Until then the page shows only stored GitHub metadata and numbers.