S
SkillSpector
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in
open-sourceobservability-evaluation
18.8k
Stars
+1565
Stars/month
356
Commits (90d)
10
Releases (6m)
Star Growth
+4.7k (33.3%)estimated from velocity
Overview
SkillSpector scans AI agent skills (used by Claude Code, Codex CLI, Gemini CLI, etc.) for security risks before installation. It detects 71 vulnerability patterns across 17 categories including prompt injection, data exfiltration, and supply chain risks. The tool provides risk scoring, multiple output formats, and integrates with NVIDIA's Verified Skills pipeline.
Deep Analysis
Key Differentiator
Specialized security scanner focused exclusively on AI agent skills with 71 vulnerability patterns across 17 risk categories.
⚡ Capabilities
- • Static analysis of agent skills
- • LLM semantic evaluation
- • 71 vulnerability pattern detection
- • Risk scoring (0-100)
- • Multiple output formats (JSON, Markdown, SARIF)
- • Live CVE lookups via OSV.dev
- • False-positive suppression
🔗 Integrations
Claude Code skillsCodex CLI skillsGemini CLI skillsMCP skillsNVIDIA Verified Skills pipelinePi tool extensionOpenCode extension
✓ Best For
- ✓ Security teams vetting agent skills
- ✓ Developers installing third-party agent skills
- ✓ Organizations implementing agent skill governance
- ✓ Preventing malicious skill installation
✗ Not Ideal For
- ✗ End-user AI applications
- ✗ General-purpose security scanning
- ✗ Non-agent-related code analysis
⚠ Known Limitations
- ⚠ Specifically for AI agent skills only
- ⚠ Requires Python 3.12+
- ⚠ Research dataset shows 26.1% vulnerability rate in analyzed skills
Alternatives
a
agentic-radar
A security scanner for your LLM agentic workflows
g
garak
the LLM vulnerability scanner
P
Promptfoo
Test your prompts, agents, and RAGs. Red teaming/pentesting/vulnerability scanning for AI. Compare performance of GPT, Claude, Gemini, Llama, and more. Simple declarative configs with command line and
L
LLM Guard
The Security Toolkit for LLM Interactions
Compare SkillSpector
Maintain SkillSpector?
Show your live rank in your README, or put SkillSpector in front of every visitor to AgentoolRank.