NVIDIA's SkillSpector scanner hits v2.8.2 with a 42,447-skill study: 26.1% carry a vulnerability, 5.2% look outright malicious
NVIDIA's open-source SkillSpector (Apache-2.0, 14,403 stars) shipped v2.8.1 on August 7 and v2.8.2 on August 8, scanning agent skills for Claude Code, Codex CLI and Gemini CLI across 68 vulnerability patterns in 17 categories — prompt injection, data exfiltration, memory poisoning, rogue agent, MCP tool poisoning, taint tracking, YARA signatures — with live OSV.dev CVE lookups and SARIF output. Its own dataset of 42,447 marketplace skills found 26.1% containing at least one vulnerability and 5.2% showing likely malicious intent, with skills that bundle executable scripts 2.12x more likely to be vulnerable. That last ratio is the actionable one: the script payload, not the SKILL.md prose, is where the risk concentrates.
↳ Follow the thread