SkillSpector
View on GitHubSecurity scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.
SkillSpector is an NVIDIA Apache-2.0 Python CLI that scans AI agent skills (Claude Code, Codex, MCP) for prompt injection, data exfiltration, supply-chain and tool-poisoning risks. It combines 71 static/YARA/AST patterns with optional LLM semantic analysis and outputs terminal, JSON, Markdown or SARIF reports with 0-10
Use Cases
Built With
- Language
- Python
- Frameworks
- LangGraph · LangChain · Pydantic · Typer · Rich · OpenAI SDK · boto3 · YARA · MCP SDK · LangSmith · hatchling · httpx
Tags
agent-security · security-scanner · prompt-injection · supply-chain-security · agent-skills · mcp · static-analysis · yara · sarif · vulnerability-scanner · claude-code · codex · data-exfiltration · llm-security · ci-cd · cli