NVIDIA SkillSpector
Featuredby NVIDIA
Scan agent skills, plugins, and MCP servers before installing them — detects prompt injection, data exfiltration, malicious patterns, and supply-chain risk in Claude Code and Codex skills.
Skills
Skill Scanning
Analyzes an agent skill or plugin package for malicious instructions and risky capabilities before installation.
Injection Detection
Flags prompt-injection and instruction-override patterns embedded in skill files, docs, and tool descriptions.
Exfiltration Checks
Identifies network calls and file access paths that could move credentials or source code off the machine.
Supply Chain Audit
Inspects declared dependencies and install hooks for tampering and untrusted sources in the skill supply chain.
Related Agents
OpenSandbox
Runs AI-agent workloads in isolated Docker or Kubernetes sandboxes, exposing sandbox lifecycle, command, filesystem, an…
promptfoo
Tests and red-teams LLM apps, agents and RAG pipelines from declarative config, scanning for prompt injection, jailbrea…
IDA Pro MCP
Bridges IDA Pro to LLM clients over MCP, exposing decompilation, disassembly, cross-references, type and stack edits, m…
Snyk
Developer security platform with AI-powered vulnerability detection, fix suggestions, and automated security testing ac…