NVIDIA/SkillSpector

Source
GitHub
First trending
Category
Security
GitHub stars
17,491
Main language
Python
Website
docs.nvidia.com/skills/scanning-agent-skills (opens in a new tab)

This page introduces an external open-source repository. It is not an HDATF product.

NVIDIA/SkillSpector

What it does

SkillSpector scans AI agent skills for Claude Code, Codex and MCP before installation. It looks for vulnerabilities, malicious patterns, prompt injection, data exfiltration and supply-chain risks in Git repos, URLs, zip files or directories.

How it helps ATF

A reference for checking outside skills before Harness or the ATF Works AI assistant runs them. Since the assistant works inside each person's permissions, a scan for prompt injection and data exfiltration is worth comparing.

License

Apache-2.0 Permissive, with a patent grant. Commercial use is allowed; keep the notices and state your changes.

More in this category

  • simplex-chat/simplex-chat
    SimpleX Chat is a messaging network with apps for iOS, Android and desktop that works without user identifiers of any kind, aiming to keep communication private by design.
  • anthropics/defending-code-reference-harness
    A reference implementation for finding and fixing code vulnerabilities with Claude, with Claude Code skills for threat modeling, scanning, triage and patching plus an autonomous scanning harness. The repository is not maintained.
  • astrid-runtime/book
    The canonical reference book for Astrid, built with mdBook, covering the kernel, the capsule model, the host ABI, the bus and the security model. Appendices such as the capability catalog are generated from the Astrid source.
  • mukul975/Anthropic-Cybersecurity-Skills
    A community library of cybersecurity skills for AI agents, not affiliated with Anthropic, mapped to frameworks such as MITRE ATT&CK and NIST CSF 2.0. It includes offensive and dual-use techniques for authorized penetration testing, security research, defense and education.
  • astrid-runtime/astrid
    A portable runtime, heading toward a standalone operating system, that runs WebAssembly capsules in a sandbox on macOS and Linux. Capsules talk through typed interfaces, and file, network, process and IPC access is checked at runtime boundaries.

Only repositories in the ranked Trendshift lists are included, and the lists are used only to find candidates. We do not copy their ranks. Descriptions, licenses and star counts come from each GitHub repository. The notes are our own reading. We have not tested these projects, and a place on a trending list does not prove quality.

View on GitHub (opens in a new tab)