# NVIDIA Releases SkillSpector: Open-Source Security Scanner for AI Agent Skills

> NVIDIA released SkillSpector, an Apache-2.0 open-source scanner that statically and semantically analyzes AI agent "skills" (SKILL.md instructions plus accompanying Python scripts) for 68 vulnerability/malice patterns before installation. It responds to peer-reviewed research showing skills shipping executable scripts are 2.12x more likely to be vulnerable, and to a growing wave of real-world agent-skill supply-chain attacks (AgentBaiting/SmartLoader, Snyk's ToxicSkills audit) that exploit agents' default trust-on-load behavior.

- **Published:** 2026-08-03T00:00:00Z
- **Last reviewed:** 2026-08-03T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1828
- **ID:** TL-2026-1828
- **Severity:** LOW
- **Category:** THREAT_INTEL
- **Status:** TRACKING
- **Detections:** 9 · **IOCs:** 27 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2025-59536, CVE-2026-21852

## Description

NVIDIA published SkillSpector (github.com/NVIDIA/SkillSpector, Apache-2.0), an open-source security scanner purpose-built for the AI agent "skill" ecosystem — Markdown instruction files (SKILL.md) often bundled with Python helper scripts that give agents like Claude Code, Codex CLI, Gemini CLI, and generic MCP-capable agents new capabilities. Skills are typically loaded on trust alone, with no code-signing or registry moderation equivalent to traditional package ecosystems, and unlike installed packages they can also carry natural-language instructions that an LLM will interpret and act on directly.

The release operationalizes findings from Liu et al.'s "Agent Skills in the Wild: An Empirical Study of Security Vulnerabilities at Scale" (arXiv:2601.10338, Jan 2026), which scanned 42,447 skills and found 26.1% contained vulnerabilities, 5.2% showed likely malicious intent, and skills bundling an executable script were 2.12x more likely to be vulnerable than prose-only skills. SkillSpector runs a two-stage pipeline: a fast static pass (regex analyzers for prompt injection/credential access/memory poisoning/typosquatting/persistence; Python AST walking for exec/eval/subprocess/dynamic-import/getattr sinks; taint tracking from environment variables and file reads to network sinks; YARA matching for malware/webshells/cryptominers/hack-tools; and live OSV.dev dependency-CVE lookups with an offline fallback) and an optional LLM semantic pass (~87% precision, context-aware false-positive reduction) using hosted (OpenAI, Anthropic, Bedrock, NVIDIA build.nvidia.com), CLI, or fully local/self-hosted (Ollama, vLLM) providers. It also inspects skill metadata for homoglyphs, right-to-left Unicode overrides, zero-width characters, and HTML comments used to hide directives from human reviewers. Findings accumulate into a 0-100 risk score (executable content applies a 1.3x multiplier); scores above 50 are flagged DO NOT INSTALL and the CLI exits non-zero for CI gating. It can also run as an MCP server exposing a single scan_skill tool to gate installations at runtime, and emits terminal, JSON, Markdown, or SARIF output.

The release lands against a documented, active threat pattern rather than a hypothetical one. Snyk's February 2026 "ToxicSkills" audit of 3,984 skills from the ClawHub and skills.sh registries found 36.82% had at least one security flaw, 13.4% a critical-level issue, and confirmed 76 malicious payloads (8 still live at publication), including 40+ programmatically generated malicious skills from a single ClawHub account and a maintainer repository (NET_NiNjA.v1.2) shipping pre-deployment malware; 91% of confirmed-malicious skills combined traditional malicious code with prompt-injection techniques. In July 2026, the AgentBaiting campaign was reported distributing SmartLoader malware through roughly 7,600 fraudulent GitHub repositories (over 800 posing as AI Skills or MCP servers impersonating Claude Skills, Databricks MCP, Jenkins MCP, Docker MCP gateway, and Alibaba Cloud Skills), using obfuscated Lua stagers, scheduled-task persistence, and a StealC-derived injector to harvest browser sessions, credentials, OAuth tokens, and SSH keys — with DragonForce and Akira ransomware observed as secondary payloads against retail targets downstream of the infostealer precursor. Separately, the Cloud Security Alliance's May 2026 "SKILL.md Agent Context Poisoning" brief documented natural-language instruction injection (e.g., directives to append API-key environment variables to outbound URLs) and Unicode Tag-character (U+E0000-U+E007F) injection that renders invisibly to human reviewers but is parsed as semantic content by the LLM, and tied the risk class to two disclosed Claude Code vulnerabilities: CVE-2025-59536 (trust-dialog bypass allowing code execution before a user accepts a project's startup trust prompt, fixed in 1.0.111) and CVE-2026-21852 (project-load flow allowing malicious repository configuration to exfiltrate Anthropic API keys before trust confirmation, fixed in 2.0.65).

SkillSpector does not execute or sandbox scanned skills — it is a pre-installation static/semantic gate, not a runtime control — and its offline mode relies on a bundled, necessarily incomplete OSV.dev fallback list. There is no CVE, active exploitation, or PoC tied to SkillSpector itself; it is tracked here as THREAT_INTEL because it directly documents and tools against a live, actively-exploited supply-chain risk pattern in the AI agent ecosystem.

## MITRE ATT&CK

- T1585 Establish Accounts
- T1608 Stage Capabilities
- T1195 Supply Chain Compromise
- T1059 Command and Scripting Interpreter
- T1204 User Execution
- T1053 Scheduled Task/Job
- T1078 Valid Accounts
- T1036 Masquerading
- T1684.001 Impersonation
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1620 Reflective Code Loading
- T1552 Unsecured Credentials
- T1528 Steal Application Access Token
- T1539 Steal Web Session Cookie
- T1105 Ingress Tool Transfer
- T1102 Web Service
- T1041 Exfiltration Over C2 Channel
- T1567 Exfiltration Over Web Service
- T1486 Data Encrypted for Impact

## Sources

- [SkillSpector: Open-source agent skill security scanner](https://www.helpnetsecurity.com/2026/08/03/skillspector-open-source-agent-skill-security-scanner/)
- [NVIDIA/SkillSpector GitHub repository](https://github.com/NVIDIA/SkillSpector)
- [Agent Skills in the Wild: An Empirical Study of Security Vulnerabilities at Scale (Liu et al.)](https://arxiv.org/pdf/2601.10338)
- [New AgentBaiting Campaign Delivers SmartLoader Via Fake AI Skills and MCP Servers](https://rhisac.org/threat-intelligence/new-agentbaiting-campaign-delivers-smartloader-via-fake-ai-skills-and-mcp-servers/)
- [ToxicSkills: Malicious AI Agent Skills on ClawHub](https://snyk.io/blog/toxicskills-malicious-ai-agent-skills-clawhub/)
- [CISO Briefing: Agent Context Poisoning — SKILL.md and the New AI Supply Chain Attack Surface](https://labs.cloudsecurityalliance.org/research/briefing-csa-research-note-skill-md-agent-context-poisoning/)
- [NVD - CVE-2025-59536](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2025-59536)
- [NVD - CVE-2026-21852](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-21852)
- [Supply Chain Attacks 2024-2026: The Acceleration Report](https://phoenix.security/open-source-supply-chain-attacks-2024-2026/)
- [Under the Hood of SKILL.md: Semantic Supply-chain Attacks on AI Agent Skill Registry (Saha, Faghih, Feizi)](https://arxiv.org/abs/2605.11418)
- [Malicious ClawHub Skills Target OpenClaw Users ("Clawdbot skills ganked your crypto")](https://opensourcemalware.com/blog/clawdbot-skills-ganked-your-crypto)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1828
