free field guide quality-control
Scan an AI Skill Before You Install It
Install NVIDIA SkillSpector, scan one skill or repository, read the risk report, and understand what the score cannot prove.
Scan an AI Skill Before You Install It
NVIDIA SkillSpector is an open-source scanner for agent skills. It checks about 70 patterns across 17 risk categories and produces a score from 0 to 100.
What this helps you do
Inspect a skill, repository, archive, or folder for suspicious instructions before giving it access to your files, terminal, credentials, or network.
Before you start
You need Git, uv, a terminal, and the exact skill path or repository URL. Test unknown skills in a disposable folder with no secrets. Read the current SkillSpector README before installing because commands can change.
Terms to know
- Static scan: examines files without proving how they behave at runtime.
- Risk score: a triage signal from 0 to 100, not a safety guarantee.
- Environment variable: a setting that can hold API keys or credentials.
- Persistence: a way for code to keep running later, such as a scheduled job.
Step-by-step
- Install SkillSpector from NVIDIA's repository.
- Scan the exact skill before installing it.
- Read every flagged file and line.
- Check install scripts, downloaded code, credential access, hooks, and scheduled tasks yourself.
- If the report is unclear, do not install the skill in a sensitive environment.
Copy this
Copy this
uv tool install git+https://github.com/NVIDIA/SkillSpector.git
# Replace the path below with one skill, repository, zip file, or folder.
skillspector scan /FULL/PATH/TO/SKILLTo expose the scanner as an MCP tool, use the current MCP installation section in NVIDIA's README. Review what the server can access before connecting it to an agent.
Things to know
A low score does not prove a skill is safe. New attacks may not match existing patterns, model-based judgments can vary, and false positives are possible. A scan also cannot tell you whether a trusted dependency changes after installation. Keep credentials out of the test folder and review the source plus the report.
If something goes wrong
- If
uvis missing, install it from the official uv documentation and reopen the terminal. - If
skillspectoris not found, runuv tool listand add uv's tool directory to your shell path. - If a remote repository cannot be fetched, clone it yourself, inspect it, then scan the local path.
- If a result changes between scans, save both reports and review the flagged source manually.
Final check
You pass only when the exact publisher and repository are verified, the scan finishes, every high-risk finding is explained, install scripts are reviewed, and the first test contains no secrets.