100100 Ideas AI
Submit Tool

SkillSpector

MCPOpen source

NVIDIA security scanner that detects vulnerabilities, prompt injection, and supply-chain risks in AI agent skills before

18kApache-2.0

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.

Pros

  • +71 vulnerability patterns across 17 categories including prompt injection, data exfiltration, and MCP tool poisoning
  • +Two-stage analysis combining fast static checks with optional LLM semantic evaluation
  • +Multiple output formats (terminal, JSON, Markdown, SARIF) with 0-100 risk scoring and baseline suppression
  • +Backed by NVIDIA's Verified Skills pipeline with live OSV.dev CVE lookups

Cons

  • −Requires Python 3.12+ or Docker and a virtual environment for setup
  • −LLM-based semantic analysis needs external API credentials and adds cost
  • −Security findings may require tuning baselines to suppress false positives

Target audience: Developers and security engineers who install or publish AI agent skills for Claude Code, Codex, or MCP and need to vet them for safety.

Related tools

Other open-source tools that share tags with SkillSpector.

headroom

MCPApache-2.0

Open-source context compression layer for AI agents, cutting tokens 60-95% for JSON and 15-20% for coding.

67k·LLM Ops·Open source