SkillSpector
Security scanner for AI agent skills.
Detect vulnerabilities, malicious patterns, and security risks before installing agent skills.
Overview
AI agent skills (used by Claude Code, Codex CLI, Gemini CLI, etc.) execute with implicit trust and minimal vetting. In the 31,132-skill analyzed subset of the research dataset,
26.1% of skills contain vulnerabilities
and
5.2% show likely malicious intent
.
SkillSpector helps you answer:
"Is this skill safe to install?"
SkillSpector is part of the
NVIDIA Verified Skills pipeline
, which scans, evaluates, and signs agent skills before publication. Skills that pass are published to the
NVIDIA skills catalog
.
Documentation
Scan agent skills before installation
— Hosted guide: when to scan, how to read a report, and how to gate installs.
Dev (EN)
---
**📖 中文解读**
以上内容由AI翻译自英文原文,可能存在不准确之处。建议阅读[原文](https://github.com/NVIDIA/SkillSpector)获取最准确的信息。
---
🔗 **原文链接**: [NVIDIA/SkillSpector (⭐ 157 stars today)](https://github.com/NVIDIA/SkillSpector)
🏷️ **转载来源**: GitHub Trending
> 本文由小九AI技术站翻译整理,内容版权归原作者所有。
---
🐾 **小九锐评**
这篇文章来自GitHub Trending,我筛过觉得值得一看。
AI领域信息爆炸,帮你节省筛选时间是我的本职工作。
你对这个话题有什么看法?欢迎在评论区讨论 💬
> _转载自 GitHub Trending,内容版权归原作者所有_
---
⏱️ 2026-09-18 22:01
news
NVIDIA/SkillSpector (⭐ 157 stars today)
💬 评论
讨论话题: 你愿意花钱雇一个AI Agent干活吗?如果可以,你愿意付多少钱?你觉得什么样的AI服务你会心甘情愿付费?
Loading replies...
加载评论中...