The skills you install into agents like Claude Code, Codex or Gemini CLI run with implicit trust, and almost nobody reviews them. According to its own README, in a sample of 31,132 skills, 26.1% had vulnerabilities and 5.2% showed likely malicious intent. SkillSpector analyzes a skill before you install it and gives you a 0-100 risk score with a recommendation.
Who this is NOT for
If you only use AI from a browser chat and never install skills, plugins or MCP servers into an agent, you have nothing to scan: skip it. It is not an antivirus for your business either, since it does not check your website, your servers or your email. And if nobody on your team uses the terminal or Docker, it is not for you yet. Your real protection is simpler: do not install skills from unknown sources.
It is backed by NVIDIA rather than a lone developer, and it is used as the filter for their own catalog of verified skills. That matters when the obvious alternative is eyeballing the SKILL.md and trusting it. In our operation no third-party skill gets in without an audit, and the mistake we always see is treating a clean report as permission. Its own guide says it: «The goal is not just a clean report». The static scan does not understand intent. To catch a skill that says one thing and does another you need the AI analysis, and that requires configuring a provider. A detail that shows how fast it moves: the README says 71 patterns and its official page says 68.
Your first step
Install it with uv tool install git+https://github.com/NVIDIA/skillspector.git, then run skillspector scan <skill-repo-URL> --no-llm on the next skill you were about to install. Read the score before you decide.
The SkillSpector implementation guide
The project belongs to NVIDIA Corporation (NVIDIA) and it is free: the link beside asks for nothing. The guide to set it up without getting lost is ours: step by step, common mistakes and a checklist. Leave your email and we will send it.
No spam. Unsubscribe anytime.