NVIDIA's security scanner for agent skills that finds vulnerabilities, prompt injection and malicious patterns before you install a skill.
SkillSpector scans Claude Code, Codex and MCP skills for vulnerabilities, prompt injection, data exfiltration and supply-chain risks before they reach your machine.
Run it with Docker or as an MCP server, as shown in the README.
Trail of Bits · Plugin
Security research, vulnerability detection and audit skills for Claude Code from the security firm Trail of Bits.
Microsoft · Tool / CLI
Microsoft's policy enforcement, identity, sandboxing and audit logging for autonomous AI agents.
Strix · Agent
Open-source AI penetration testers that run your app, find vulnerabilities and prove each one with a working exploit.