Vulnerabilities
Known-risky calls, unsafe file and network access buried in a skill's code.
Security scanner · agent skills
SkillSpector inspects AI agent skills for vulnerabilities, malicious patterns, and security risks, so an untrusted SKILL file never executes unchecked.
# inspect a skill before install $ skillspector scan ./suspicious-skill
Known-risky calls, unsafe file and network access buried in a skill's code.
Exfiltration, destructive shell, and obfuscation signatures flagged before they run.
Hidden instruction overrides and injection bait inside skill text.