SkillSpector is an open-source security scanner for AI agent skills, developed by NVIDIA. It scans Git repositories, URLs, ZIP archives, directories, and individual skill files before installation, looking for prompt injection, data exfiltration, privilege escalation, supply-chain issues, dangerous code, MCP permission problems, tool poisoning, and other malicious patterns.
Its two-stage pipeline combines static analysis—including regex, Python AST, taint tracking, YARA signatures, and OSV.dev dependency lookups—with optional LLM-based semantic evaluation. It produces terminal, JSON, Markdown, or SARIF reports containing findings, severity labels, a 0–100 risk score, and installation recommendations. Baselines can suppress accepted findings, and the CLI can be used in CI or install gates through exit codes and machine-readable output.
SkillSpector can also run as an MCP server callable by compatible agents. It does not execute scanned skills or sandbox them; optional LLM analysis sends eligible file contents to the configured provider, while dependency checks query OSV.dev. The project is distributed under the Apache License 2.0 and is part of NVIDIA's Verified Skills pipeline.