SkillSpector

Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install

CLIEditors’ pick

Medium risk

We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.

Why this level

  • Clones repositories and unpacks archives to disk for analysis
  • Reaches the network: OSV.dev for CVE data and, optionally, an LLM provider
All reasons and checks

nvidia/skillspector

Install

Manual install

uv tool install git+https://github.com/NVIDIA/skillspector.git

CLI-only install. Update with uv tool update skillspector. Source install via make install and a Docker run without Python are also available.

This is third-party code. Review the repository files before installing.

What it does

SkillSpector vets skills and MCP servers before you install them. Input can be a git repo, a URL, a zip archive, a directory or a single SKILL.md file. Static analysis matches content against 71 vulnerability patterns across 17 categories: prompt injection, data exfiltration, privilege escalation, supply chain, dangerous code via AST parsing, MCP tool poisoning and others. An optional LLM stage adds semantic evaluation, and rule SC4 checks dependencies against live OSV.dev CVE data with an automatic offline fallback. The output is a 0 to 100 risk score with a severity label and a clear recommendation, plus reports in terminal, JSON, Markdown or SARIF for CI. It also runs as an MCP server so an agent can gate installs on the scan result.

Who it is for. For developers and security engineers who install third-party skills, MCP servers and plugins and want to vet them first.

Good fit when

  • Before installing a skill, plugin or MCP server from an unfamiliar source
  • To add a skill scan gate to CI over a repository or a directory
  • To run scanning from inside an agent session via the MCP server or the OpenCode and Pi extensions

Not a fit when

  • You need a review of ordinary application code rather than agent skills
  • You need a safety guarantee rather than a risk signal: heuristics produce both false positives and misses

Example request

Check this skill for safety before I install it: https://github.com/user/some-skill

Limitations

Analysis is heuristic, so both false positives and misses are possible; accepted findings are suppressed via a baseline. The LLM stage is optional and needs an OpenAI-compatible endpoint with its own key or a local model; without it only static analysis runs. It requires Python 3.12+ or Docker. Input size is capped: 100 MiB per source, 10000 zip members, 1 MB per analyzed file. The MCP server's HTTP transport ships without authentication and should only be exposed behind a reverse proxy. Some LLM providers such as OpenAI and Anthropic are unreachable from Russia without a VPN, but the static mode and local models work offline.

How to disable. Uninstall the tool: uv tool uninstall skillspector, or remove the virtual environment or pip package. If you registered it as an MCP server, remove it: claude mcp remove skillspector.

Security check

  • Clones repositories and unpacks archives to disk for analysis
  • Reaches the network: OSV.dev for CVE data and, optionally, an LLM provider

README in short

The README presents SkillSpector as a security scanner for agent skills and MCP servers, which are usually installed with implicit trust. It scans repositories, URLs, archives, directories and single files, using static analysis with 71 vulnerability patterns and an optional LLM evaluation. It installs via uv, pip or source, or runs in Docker with no Python setup, and reports to terminal, JSON, Markdown and SARIF. The MCP server mode and the OpenCode and Pi extensions let you gate installs from inside an agent. SkillSpector is part of the NVIDIA Verified Skills pipeline. Apache 2.0 licensed.

FAQ

Do I need an LLM key?

No. Static analysis runs without a key, and the --no-llm flag turns off the semantic stage. It is optional and needs an OpenAI-compatible endpoint or a local model.

Can it run in CI?

Yes. The SARIF format targets CI/CD and IDE tooling, JSON and Markdown are also available, and batch scanning walks a skill directory in parallel.

Editors’ pick

A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor

SkillMedium riskNo VPN needed22.6KRepository stars
Editors’ pick

NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference

CLIHigh risk22.6KRepository stars
Official

Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents

CLIMedium risk16.8KRepository stars

Trail of Bits skills

Trail of Bits Skills Marketplace

Editors’ pick

Trail of Bits plugin marketplace for security work: smart contracts, C/C++ and Rust review, Semgrep, CodeQL and fuzzing

PluginMedium risk7.3KRepository stars
Foxx AISkillSpector

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.