Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.
NVIDIA/SkillSpector is an MCP server distributed on github, maintained by NVIDIA, tracked here since August 2026. It has shipped 16 releases and exposes 1 tool. Tools include scan_skill. Its composite risk grade is C — an inferred review prompt computed from observed signals, not a verdict.
Reading the source raised 2 review prompts — dangerous code and toxic flow (lethal trifecta) — each a pattern worth a human look rather than a finding of fault.
full security breakdown →-
scan_skill
06-20 00:00 08-03 00:00 now
| version | date | src |
|---|---|---|
| v2.11.2 | 2026-09-09 | github |
| v2.11.1 | 2026-09-07 | github |
| v2.11.0 | 2026-08-28 | github |
| v2.10.0 | 2026-08-26 | github |
| v2.9.6 | 2026-08-18 | github |
| v2.9.5 | 2026-08-15 | github |
| v2.9.4 | 2026-08-13 | github |
| v2.9.3 | 2026-08-11 | github |
| v2.9.2 | 2026-08-11 | github |
| v2.9.1 | 2026-08-10 | github |