S
SkillSpector
Scans AI agent skills for prompt injection, data exfiltration, supply-chain risks, and vulnerabilities
open-sourceobservability-evaluation
19.0k
Stars
+3795
Stars/month
352
Commits (90d)
10
Releases (6m)
Star Growth
+253 (1.3%)
Overview
SkillSpector scans AI agent skills (used by Claude Code, Codex CLI, Gemini CLI, etc.) for security risks before installation. It detects 71 vulnerability patterns across 17 categories including prompt injection, data exfiltration, and supply chain risks. The tool provides risk scoring, multiple output formats, and integrates with NVIDIA's Verified Skills pipeline.
Deep Analysis
Key Differentiator
Specialized security scanner focused exclusively on AI agent skills with 71 vulnerability patterns across 17 risk categories.
⚡ Capabilities
- • Static analysis of agent skills
- • LLM semantic evaluation
- • 71 vulnerability pattern detection
- • Risk scoring (0-100)
- • Multiple output formats (JSON, Markdown, SARIF)
- • Live CVE lookups via OSV.dev
- • False-positive suppression
🔗 Integrations
Claude Code skillsCodex CLI skillsGemini CLI skillsMCP skillsNVIDIA Verified Skills pipelinePi tool extensionOpenCode extension
✓ Best For
- ✓ Security teams vetting agent skills
- ✓ Developers installing third-party agent skills
- ✓ Organizations implementing agent skill governance
- ✓ Preventing malicious skill installation
✗ Not Ideal For
- ✗ End-user AI applications
- ✗ General-purpose security scanning
- ✗ Non-agent-related code analysis
⚠ Known Limitations
- ⚠ Specifically for AI agent skills only
- ⚠ Requires Python 3.12+
- ⚠ Research dataset shows 26.1% vulnerability rate in analyzed skills
Alternatives
a
agentic-radar
A security scanner for your LLM agentic workflows
g
garak
the LLM vulnerability scanner
P
Promptfoo
Open-source CLI and library for evaluating and red-teaming prompts, agents, RAG systems, and LLM apps
L
LLM Guard
The Security Toolkit for LLM Interactions
Compare SkillSpector
Maintain SkillSpector?
Show your live rank in your README, or put SkillSpector in front of every visitor to AgentoolRank.