NVIDIA Releases SkillSpector Security Scanner for AI Agent Skills
Installing a new skill into Claude Code or Codex gives your agent instant superpowers. It also opens the door to anything that skill was built to do — including leaking your data or running a prompt injection.
What Happened
NVIDIA released SkillSpector, a security scanner for AI agent skills. It checks a skill before you install it into Claude Code or Codex and flags risks in seconds: prompt injections, malicious instructions, data exfiltration vectors, and supply-chain or third-party dependencies. The tool is open source and lives on GitHub: https://github.com/NVIDIA/SkillSpector
Why It Matters
The question used to be "is this skill cool?" Now it can be "is this skill safe?" If you have ever pulled an agent skill from a random repo without reading the code first, SkillSpector is the sanity check you were missing.
Comments
Join the conversation — sign in to comment.
No comments yet — start the conversation!