OSSCisco Skill Scanner: Enterprise Agent Skill SecurityGitHub·high signalXBlueskyLinkedInCopy linkYARA rules + LLM-as-judge + SARIF output for agent skill scanningSourceSource pageGitHub↳ Follow the threadStack layer / Threat patterngoogle/skills Is Google Publishing Official Agent Skills for Ads, Analytics, and Cloud — 16,460 StarsGitHubStack layer / Threat patternNVIDIA's SkillSpector scanner hits v2.8.2 with a 42,447-skill study: 26.1% carry a vulnerability, 5.2% look outright maliciousGitHub (nvidia/skillspector)Stack layer / Threat patterncaveman Hits 97,000 Stars for a Token-Cutting Skill — and Its README Publishes the JetBrains Test That Drops the Claim From 65% to 8.5%GitHubStack layer / Threat patternopen-kritt Open-Sources Agent-Orchestrated Vulnerability Hunting on the Premise That Whole-Repo Scanning FailsGitHubStack layer / Threat patternECC v2.1 Adds a Browser-Based Plan Canvas and a Native Kimi Code Install PathGitHubStack layer / Threat patternMicrosoft's Foundry Local CLI 0.10.3 Fixes Non-CPU Models Silently Not AppearingGitHubStack layer / Threat patternvllm.cpp Is a 1:1 C++ Port of vLLM in a 66 MiB Binary — 140x Smaller Install, 6.1x Faster Cold Start, Token-Exact Outputmudler/vllm.cpp (GitHub)Stack layer / Threat patternBoundary-Bench: turn on the security controls your enterprise already runs and coding agents lose up to 18.3 pointsGitHub (boundary-bench)