
One in Twenty Agent Skills Are Malicious. NVIDIA Built a Scanner.
SkillSpector is an open-source security scanner that treats AI agent skills—markdown files with embedded code that agents install and run with implicit trust—as a software supply chain artifact riddled with prompt injection, data exfiltration, and privilege escalation risks.
