AI Guides › Workbench

Scan a Skill Before It Runs: A SkillSpector Kit

By Nigel Guy · 7 min read

Most people vet a skill by reading the first screen of its SKILL.md, seeing something sensible, and installing it. That feels like due diligence and isn't. A skill is instructions plus, often, scripts, and the folder runs with whatever access your agent has. The part that can hurt you is rarely on the first screen.

The rule: scan every skill you did not write before it goes into your skills folder, run the free static scan first, and treat the report as a list of places to look, not a verdict.

First, the statistic going round

The line doing the rounds is "NVIDIA checked over 42,000 skills and 1 in 20 were malicious". That is not quite what happened. The figures come from an academic paper, Agent Skills in the Wild (arXiv, January 2026), whose authors are not NVIDIA. They collected 42,447 skills from two marketplaces and analysed 31,132 of them. Of those, 26.1% contained at least one vulnerability and 5.2% showed high-severity patterns that "strongly suggest malicious intent". That is where "1 in 20" comes from, and it is a pattern-based estimate, not a count of confirmed malware. The paper reports 86.7% precision for its detector, so some of that 5.2% will be false alarms and some real problems will be missed.

NVIDIA's contribution is a separate, real tool: SkillSpector, an open-source scanner on GitHub, whose README cites the paper's dataset. The risk is real enough to scan for. It is not as clean a number as the headline.

The kit at a glance

Mode What it does Cost at time of writing Best for Catch
Static scan (--no-llm) Fast, deterministic checks: dangerous code patterns, suspicious strings, dependency lookups, declared-permission mismatches Free to run; check the licence on the repo Every skill, every time Pattern matching only, so it can miss intent and can be noisy
Static plus LLM Adds a model that compares what the skill says with what its code does The tool is free, but you pay your model provider for usage; the amount varies by skill size and provider, so check your provider's £ pricing Skills you are close to trusting, or that flagged something Sends skill content to the provider you configure
Batch scan Scans a whole folder of skills in parallel Same as above Auditing your existing library Lives in contrib/, so treat it as less polished

Run it: the Skills Folder Sweep

1. Install. NVIDIA's README gives two routes. With uv:

uv tool install git+https://github.com/NVIDIA/skillspector.git

Or without Python, build the Docker image from the repository's Dockerfile (docker build -t skillspector .). The README notes that installing pulls in third-party open-source packages, so read their licences if that matters to you.

2. Know where your skills live. In Claude Code, personal skills sit in ~/.claude/skills/<skill-name>/ and project skills in .claude/skills/<skill-name>/, each with a SKILL.md (Claude Code docs). Other agents use other folders; check yours.

3. Scan a single skill, static only.

skillspector scan ./my-skill/ --no-llm

It also accepts a single SKILL.md, a zip file, or a Git URL. Scanning a repo URL before you clone it into your skills folder is the best habit here.

4. Scan the whole library.

python -m contrib.batch_scan.batch_scan ./skills/ --no-llm

Run that from a clone of the repository. Add -f json -o report.json if you want a file. Using Docker instead, mount your current folder and scan inside it:

docker run --rm -v "$PWD:/scan" skillspector scan ./my-skill/ --no-llm

5. Save a readable report. --format markdown --output report.md is good for a review; JSON suits scripts; SARIF suits CI.

6. Optionally add the LLM stage. Set SKILLSPECTOR_PROVIDER and your provider's key (the README's Docker example uses anthropic with ANTHROPIC_API_KEY), and drop --no-llm. Do this only for skills you are willing to send to that provider.

7. Read the exit code. 0 means the risk score is 50 or below; 1 means it is above 50, or a strict gate you enabled fired; 2 means an error. By default a "caution" result still exits 0, so add --fail-on-findings if you want any active finding to block an install script.

Reading the report: the triage prompt

Reports are long and the findings are not equally serious. This prompt helps you sort one. Paste in the report plus the skill's own SKILL.md. Fill in the bracketed parts.

You are a careful application-security reviewer helping a non-specialist decide whether to install an AI agent skill.

Context: I scanned a skill with a static security scanner. The report is below, followed by the skill's SKILL.md. My agent is [AGENT_NAME]. It can access [WHAT_THE_AGENT_CAN_TOUCH, e.g. my home folder, API keys in environment variables, email].

Goal: tell me whether to install, fix, or reject, and exactly what to inspect by hand before I decide.

Steps:
1. Group the findings into: critical or high; plausible false alarms; needs a human look.
2. For each critical or high finding, quote the file and line from the report, explain in plain English what it could do on my machine, and say whether the skill's stated purpose would justify it.
3. Flag any mismatch between what SKILL.md says the skill does and what the findings suggest it does.
4. Give a verdict: install, install after specific changes, or reject, with two sentences of reasoning.

Output format: a short verdict first, then a table with columns Finding, Severity, Likely real or false alarm, What to check by hand.

Rules: use only the report and files I give you. If something you need is missing, ask for it rather than guessing. Do not claim a skill is safe; say what was and was not examined. Before answering, check that every claim cites a finding or a line from the files.

REPORT:
[PASTE_REPORT]

SKILL.MD:
[PASTE_SKILL_MD]

Fill in: your agent's name, what it can reach, the report and the SKILL.md. Be aware that the skill text is untrusted and could itself contain instructions aimed at a model; read the answer critically.

How to choose

What won't this do

It will not prove a skill is safe. A clean score means the checks found nothing, not that nothing is there. An independent research repository exists specifically to try to defeat SkillSpector, which tells you adversarial skills are an active area; I have not verified how well that attempt works. NVIDIA's own documentation says scanning is one release gate among others.

NVIDIA's pages also disagree on how many patterns it checks (the README, its hosted docs and a news write-up give different counts), so do not quote a number; it appears to grow with releases. The roughly 87% precision figure for the LLM stage comes from a trade-press write-up of the project, not an independently verified test.

What to skip

Guardrails

Sources

All 751 AI guides · JulieMango plans from £17/mo