Vibe Coding Discover

AI Tools

SkillSpector

View on GitHub

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.

★ 18K1,573 forksPythonApache-2.0NVIDIA

SkillSpector is an NVIDIA Apache-2.0 Python CLI that scans AI agent skills (Claude Code, Codex, MCP) for prompt injection, data exfiltration, supply-chain and tool-poisoning risks. It combines 71 static/YARA/AST patterns with optional LLM semantic analysis and outputs terminal, JSON, Markdown or SARIF reports with 0-10

Use Cases

Vet an AI agent skill before installing itGate skill installs in CI/CD with SARIF outputBatch-scan a large catalog of Claude Code or Codex skillsDetect prompt injection and anti-refusal patternsDetect data exfiltration and credential theft in skillsCheck MCP servers for tool poisoning and least privilegeLook up live CVEs for skill dependencies via OSV.devSuppress accepted findings with a baseline for re-scansRun security scans from inside an agent session via the Pi or OpenCode extensionProduce JSON/Markdown risk reports with 0-100 scoring

Built With

Language
Python
Frameworks
LangGraph · LangChain · Pydantic · Typer · Rich · OpenAI SDK · boto3 · YARA · MCP SDK · LangSmith · hatchling · httpx

Tags

agent-security · security-scanner · prompt-injection · supply-chain-security · agent-skills · mcp · static-analysis · yara · sarif · vulnerability-scanner · claude-code · codex · data-exfiltration · llm-security · ci-cd · cli