NVIDIA SkillSpector: Security Scanner for AI Agent Skills
Shared by The Startup Ideas Podcast on LinkedIn (2026-06, ~2.9k followers)
Summary
SkillSpector (github.com/NVIDIA/SkillSpector, Apache 2.0) is NVIDIA’s security scanner for AI agent skills. People now pull skills, MCP servers, plugins, and agent tools straight from GitHub — and those files can carry instructions, scripts, dependencies, and tool access. SkillSpector flags prompt injection, data exfiltration, supply-chain risk, hidden instructions, and MCP-related risks before you install them. Covers 68 vulnerability patterns across 17 categories; works on Claude Code, Codex CLI, Gemini CLI, and MCP skills.
The Post (full text)
NVIDIA shipped a repo called SkillSpector, and it’s a no-brainer install.
People are pulling skills, MCP servers, plugins, and agent tools straight from GitHub.
Those files can carry instructions, scripts, dependencies, and tool access. Some of them touch files, call tools, and connect to services.
SkillSpector flags prompt injection, data exfiltration, supply chain risk, and hidden instructions.
Here’s the whole setup:
- Install with uv:
uv tool install git+[repo link]- Scan a local skill folder:
skillspector scan ./my-skill- Or scan a GitHub repo directly:
skillspector scan [link]- Add
--no-llmfor a static scan that doesn’t send file contents to an LLM provider.- Use the Docker option if you’d rather not install Python locally.
- Then install the skill.
Step 6 goes last. Once a skill is in your setup, it has already had its shot at your files.
Builders and founders are stacking a coding agent, a research skill, a design skill, a browser tool, a video workflow. 5 installs in, that’s the operating system you work inside every day, and no security team is checking it for you.
The easy fix is to run the tool through SkillSpector, then hand it to your agent.
Podcast Transcript (key points)
So the 4th repo is NVIDIA’s, and it’s called SkillSpector. This is a no-brainer one to install, because people are starting to install skills and MCP servers and plugins and agent tools straight from GitHub — which is exciting because it gives your AI new abilities. But it creates a problem: a skill isn’t just a block of text. It can include instructions and scripts and dependencies, tool access — behavior that changes how your agent works. And in some cases it can actually touch files, call tools, and connect to services.
So before you install random capabilities from GitHub, you should probably ask whether it’s safe. SkillSpector scans AI agent skills for security issues — prompt injection, data exfiltration, supply-chain risk, hidden instructions, malicious patterns, and MCP-related risks.
The way I think about it: before you hand your AI a new tool, scan the tool. This matters a lot more now because AI workflows are getting more modular. Most people use one chatbot today, but builders are already assembling their own AI work environments — a coding agent, a research skill, a design skill, a browser tool, a video workflow. At some point your setup starts to look like a little operating system for your work. Once that happens, security stops being an enterprise-only problem and becomes a normal builder/founder problem.
Install:
uv tool install git+[GitHub link], then scan a skill directory withskillspector scan ./my-skill, or scan a GitHub repo directly. Add--no-llmfor a faster static scan that doesn’t send file contents to an LLM provider — matters if you’re scanning sensitive or private files. There’s also a Docker option if you’d rather not install Python locally.If teams are going to install AI skills and MCP servers, someone’s going to need to help them decide what’s safe — that could be a trusted marketplace, a security scanner and install gate for companies, or a feature inside every agent platform. Glad NVIDIA is attached to this one — it gives the whole category credibility and admits that a lot of these skills and plugins could be malicious, so you have to be careful.
Quick Start
# install
uv tool install git+https://github.com/NVIDIA/SkillSpector
# scan a local skill folder
skillspector scan ./my-skill
# scan a GitHub repo directly
skillspector scan https://github.com/org/repo
# static-only scan (no file contents sent to an LLM provider)
skillspector scan ./my-skill --no-llmKey Takeaways
- Scan before you install — once a skill is in your setup, it has already had its shot at your files (step 6 goes last).
- Detects: prompt injection, data exfiltration, supply-chain risk, hidden instructions, MCP-related risks.
- 68 vulnerability patterns across 17 categories (Claude Code, Codex, Gemini CLI, MCP skills).
--no-llmfor private/sensitive files (no contents sent to LLM providers); Docker option available.- Repo: https://github.com/NVIDIA/SkillSpector (Apache 2.0)