Agentic Research

NVIDIA SkillSpector: An AI Agent Skill Security Scanner

2026/06/2012 min readUltraClaw閱讀中文原文
TopicsGitHub TrendingAgent Skills

One-Sentence Summary

An AI Agent Skill security scanner open-sourced by NVIDIA. Scan before installing a Skill to detect 64 vulnerability patterns × 16 risk categories, covering prompt injection, data exfiltration, privilege escalation, supply chain attacks, and more.


Why Is SkillSpector Needed?

In the AI Agent ecosystem, anyone can publish a Skill. These Skills run on implicit trust, with almost no review mechanism.

NVIDIA's research shows:

  • 26.1% of Skills contain vulnerabilities
  • 5.2% show possible malicious intent

You have 200+ installed Skills, and you have never run a security scan.


Feature Highlights

FeatureDescription
Multi-format inputGit repos, URLs, zip files, local directories, single files
64 vulnerability patterns16 risk categories, from prompt injection to supply chain attacks
Two-stage analysisFast static analysis + optional LLM semantic assessment
Real-time CVE lookupConnects to OSV.dev for live vulnerability data
Multiple output formatsTerminal / JSON / Markdown / SARIF
Risk scoringA 0-100 score + severity level + concrete recommendations

16 Risk Categories × 64 Detection Patterns

🔴 High-Risk Categories

CategoryPatternsTypical Detection
Prompt Injection5Instruction override, hidden instructions, data exfiltration commands
Data Exfiltration4External transmission, environment variable harvesting, context leakage
Dangerous Code (AST)6eval() / exec() / subprocess / os.system()
Supply Chain4Unverified dependencies, URL download and execute, pip install injection

🟡 Medium-Risk Categories

CategoryPatternsTypical Detection
Privilege Escalation3Excessive permission requests, sudo/root execution
Excessive Agency4Autonomous behavior beyond the declared function
Output Handling3Unfiltered output, sensitive information leakage
System Prompt Leakage3System prompt extraction
Memory Poisoning4Memory contamination, long-dormant instructions
Tool Misuse4Tool abuse, unauthorized operations

🟢 Low-Risk but Important

CategoryPatternsTypical Detection
Rogue Agent3Self-replication, unauthorized spawn
Trigger Abuse3Timed triggers, hidden activation conditions
Taint Tracking5User input taint tracking
YARA Signatures4Known malicious pattern matching
MCP Least Privilege3MCP tool least-privilege checks
MCP Tool Poisoning3MCP tool poisoning detection

Usage

Pre-Installation Scan (the most important)

# Scan GitHub Repositories (Before Installation)
skillspector scan https://github.com/someone/some-skill

# Scan Local Directory
skillspector scan ./my-skill/

# Static analysis only (fast)
skillspector scan ./my-skill/ --no-llm

LLM Semantic Analysis

export SKILLSPECTOR_PROVIDER=openai
export OPENAI_API_KEY=sk-...
skillspector scan ./my-skill/

Supports OpenAI / Anthropic / NVIDIA NIM / a local Ollama.

CI/CD Integration

The SARIF output format integrates directly with GitHub Code Scanning:

skillspector scan ./my-skill/ --format sarif --output report.sarif

Docker (no Python installation needed)

docker run --rm -v "$PWD:/scan" skillspector scan ./my-skill/ --no-llm

Value to Us

We have 200+ Skills and zero security scanning.

ActionPriority
Run a one-time batch scan of all installed Skills🔴 P0
Mandatory scan before installing a new Skill🔴 P0
Integrate into CI/CD to scan automatically on every Skill update🟡 P1
Establish a Skill security allowlist/blocklist🟢 P2

Tech stack: Python 3.12+ · LangGraph · SARIF 2.1.0 License: Apache 2.0 | Repo: NVIDIA/SkillSpector