NVIDIA has released SkillSpector, a security scanner designed to detect vulnerabilities and malicious patterns in AI agent skills before installation. The tool identifies security risks including prompt injection, data exfiltration, and supply-chain threats across Claude Code, Codex, and MCP skills. This open-source utility helps developers evaluate the security posture of AI agent extensions and integrations.

Read original