S

SkillSpector

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in

18.8k
Stars
+1565
Stars/month
356
Commits (90d)
10
Releases (6m)

Star Growth

+4.7k (33.3%)estimated from velocity
13.8k16.5k19.2kJul 2Sep 30

Overview

SkillSpector scans AI agent skills (used by Claude Code, Codex CLI, Gemini CLI, etc.) for security risks before installation. It detects 71 vulnerability patterns across 17 categories including prompt injection, data exfiltration, and supply chain risks. The tool provides risk scoring, multiple output formats, and integrates with NVIDIA's Verified Skills pipeline.

Deep Analysis

Key Differentiator

Specialized security scanner focused exclusively on AI agent skills with 71 vulnerability patterns across 17 risk categories.

⚡ Capabilities

  • • Static analysis of agent skills
  • • LLM semantic evaluation
  • • 71 vulnerability pattern detection
  • • Risk scoring (0-100)
  • • Multiple output formats (JSON, Markdown, SARIF)
  • • Live CVE lookups via OSV.dev
  • • False-positive suppression

🔗 Integrations

Claude Code skillsCodex CLI skillsGemini CLI skillsMCP skillsNVIDIA Verified Skills pipelinePi tool extensionOpenCode extension

✓ Best For

  • ✓ Security teams vetting agent skills
  • ✓ Developers installing third-party agent skills
  • ✓ Organizations implementing agent skill governance
  • ✓ Preventing malicious skill installation

✗ Not Ideal For

  • ✗ End-user AI applications
  • ✗ General-purpose security scanning
  • ✗ Non-agent-related code analysis

⚠ Known Limitations

  • ⚠ Specifically for AI agent skills only
  • ⚠ Requires Python 3.12+
  • ⚠ Research dataset shows 26.1% vulnerability rate in analyzed skills

Alternatives

See all 8 SkillSpector alternatives →

Compare SkillSpector

Maintain SkillSpector?

Show your live rank in your README, or put SkillSpector in front of every visitor to AgentoolRank.