Nvidia SkillSpector: security scanner for agent skills
AI agent skills (used by Claude Code, Codex CLI, Gemini CLI, etc.) execute with implicit trust and minimal vetting. Research shows that 26.1% of skills contain vulnerabilities and 5.2% show likely malicious intent.
SkillSpector helps you answer: “Is this skill safe to install?”
It gives a 0-100 safety score.
This is probably good to put into CI to monitor shared skills in your org.