SkillSpector is a security scanner for AI agent skills, detecting vulnerabilities, malicious patterns, and risks before installation. Research shows that 26.1% of skills contain vulnerabilities and 5.2% show likely malicious intent.
It scans Git repos, URLs, zip files, directories, or single files for 64 vulnerability patterns across 16 categories, including prompt injection, data exfiltration, privilege escalation, supply chain, and more. Two-stage analysis: fast static analysis plus optional LLM evaluation.
SkillSpector provides risk scoring (0-100), severity labels, and multiple output formats: terminal, JSON, Markdown, and SARIF. It can be used with local or cloud LLMs for deeper semantic analysis.
GitHub ★ 2,254

0 комментариев