8 Best SkillSpector Alternatives in 2026 (Open Source)
SkillSpector — Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in. Specialized security scanner focused exclusively on AI agent skills with 71 vulnerability patterns across 17 risk categories.
These 8 open-source tools do the same job. They are ordered by how closely they match SkillSpector, with live GitHub data so you can see which projects are actively maintained.
| Tool | GitHub stars | Stars / 30d | Last commit |
|---|---|---|---|
| SkillSpector(original) | 18.8k | +1,565 | 2026-09-30 |
| agentic-radar | 1.1k | +20 | 2025-11-27 |
| garak | 9.4k | +783 | 2026-09-16 |
| Promptfoo | 25.6k | +1,117 | 2026-09-30 |
| LLM Guard | 3.2k | +76 | 2026-07-08 |
| LangKit | 997 | +3 | 2024-11-22 |
| UpTrain | 2.4k | +4 | 2024-07-29 |
| Superagent | 6.8k | +42 | 2026-08-25 |
| HexStrike AI MCP Agents | 12.3k | +1,022 | 2026-08-03 |
1. agentic-radar
A security scanner for your LLM agentic workflows
What sets it apart: The first dedicated security scanner specifically designed for agentic AI workflows, combining static analysis with runtime adversarial testing and automatic prompt hardening — no other tool maps agent vulnerabilities to OWASP AI security frameworks
Best for: Security teams auditing agentic AI systems before production deployment; DevOps teams integrating AI security scanning into CI/CD pipelines
2. garak
the LLM vulnerability scanner
What sets it apart: Specialized security-focused evaluation framework that treats LLM assessment like traditional vulnerability scanning with nmap/Metasploit methodologies.
Best for: Security testing of LLM-based agents; Evaluating agent robustness before deployment; Red-teaming AI agent vulnerabilities
3. Promptfoo
Test your prompts, agents, and RAGs. Red teaming/pentesting/vulnerability scanning for AI. Compare performance of GPT, Claude, Gemini, Llama, and more. Simple declarative configs with command line and
What sets it apart: Unlike LangSmith (production observability) or Langfuse (logging), promptfoo is the only open-source tool combining eval + red teaming + CI/CD code scanning — now backed by OpenAI while remaining fully MIT-licensed
Best for: Teams hardening LLM apps against prompt injection and jailbreaks with automated red teaming; Engineering teams adding LLM eval regression tests to CI/CD pipelines
4. LLM Guard
The Security Toolkit for LLM Interactions
Best for: Enterprise teams deploying LLMs in production needing security guardrails; Organizations with strict data leakage prevention requirements; Applications handling sensitive user data through LLM interfaces
5. LangKit
🔍 LangKit: An open-source toolkit for monitoring Large Language Models (LLMs). 📚 Extracts signals from prompts & responses, ensuring safety & security. 🛡️ Features include text quality, relevance m
What sets it apart: Open-source text metrics toolkit for LLM monitoring with built-in security detection (jailbreaks, prompt injection), quality scoring, and whylogs integration
Best for: llm-output-monitoring; detecting-prompt-injection; text-quality-observability
6. UpTrain
UpTrain is an open-source unified platform to evaluate and improve Generative AI applications. We provide grades for 20+ preconfigured checks (covering language, code, embedding use-cases), perform ro
What sets it apart: vs generic eval tools: 20+ preconfigured evaluations with customizable prompts, few-shot examples, and scenario descriptions — all running locally for data privacy with root cause analysis on failures
Best for: RAG system evaluation and quality assurance; LLM application testing before production deployment; Safety and security testing for prompt injection vulnerabilities
7. Superagent
Superagent protects your AI applications against prompt injections, data leaks, and harmful outputs. Embed safety directly into your app and prove compliance to your customers.
What sets it apart: YC-backed AI safety SDK that pivoted from general agent building to focused safety tooling — provides guard, redact, and scan capabilities with open-weight models for self-hosting, filling the gap between building agents and securing them
Best for: Teams adding safety layers to production AI agents; Enterprises requiring PII redaction and prompt injection protection; Security-focused AI deployments with compliance requirements
8. HexStrike AI MCP Agents
HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pente
What sets it apart: Specialized MCP server focused exclusively on cybersecurity tool integration for AI agents.
Best for: AI-powered penetration testing; bug bounty automation; security research automation
FAQ
- What are the best alternatives to SkillSpector?
- The closest open-source alternatives to SkillSpector are agentic-radar, garak and Promptfoo, followed by LLM Guard, LangKit and UpTrain. They are ranked by how closely they match what SkillSpector does.
- Which SkillSpector alternative is the most popular?
- Promptfoo has the most GitHub stars among SkillSpector alternatives, with 25,597 stars.
- Which SkillSpector alternative is the most actively maintained?
- By recent activity, Promptfoo (895 commits in the last 90 days) is the most actively developed alternative.