awesome-repositories.com
ब्लॉग
MCP
awesome-repositories.com

AI-संचालित खोज के साथ बेहतरीन ओपन-सोर्स रिपॉजिटरी खोजें।

एक्सप्लोर करेंक्यूरेटेड खोजेंओपन-सोर्स विकल्पसेल्फ-होस्टेड सॉफ्टवेयरब्लॉगसाइटमैप
प्रोजेक्टहमारे बारे मेंहम रैंकिंग कैसे करते हैंप्रेसMCP सर्वर
कानूनीगोपनीयताशर्तें
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
NVIDIA avatar

NVIDIA/SkillSpector

0
View on GitHub↗
10,778 स्टार्स·873 फोर्क्स·Python·Apache-2.0·7 व्यूज़

SkillSpector

SkillSpector is a security scanner designed to detect vulnerabilities and malicious patterns in AI agent plugins and extensions before they are installed. It functions as a runtime guardrail that calculates numeric risk scores and assigns severity labels to provide installation recommendations or block risky external extensions.

The project distinguishes itself by using language models to perform semantic code analysis, evaluating code intent and context to reduce false positives. It also employs fingerprint-based issue suppression to track and ignore previously accepted risks across repeated scan cycles.

The tool covers software supply chain security through dependency scanning against public security databases and supports multi-source asset ingestion from local directories, remote URLs, and repositories. It provides vulnerability reporting in multiple machine-readable and human-readable formats for integration into CI/CD pipelines.

Features

  • AI Agent Vulnerability Scanners - Analyzes AI agent plugins and extensions to identify malicious patterns and security vulnerabilities before installation.
  • LLM-Based Analysis - Uses language models to perform semantic code analysis and evaluate intent to reduce false positives in vulnerability detection.
  • LLM-Powered Semantic Analyzers - Uses a language model to evaluate code semantics and reduce false positives during security analysis.
  • Security Intent Analysis - Uses large language models to evaluate code intent and context, reducing false positives in security detection.
  • CVE Dependency Scanners - Identifies known vulnerabilities in the skill dependency tree by querying public security databases.
  • Dependency Vulnerability Scanners - Identifies known vulnerabilities in third-party dependencies by querying public security databases.
  • Security Guardrails - Provides runtime guardrails that block the installation of risky AI skills based on security risk scores.
  • AI Agent Scanners - Serves as a specialized security scanner for detecting vulnerabilities and malicious patterns in AI agent skills.
  • Software Supply Chain Security - Secures the AI plugin supply chain by scanning external dependencies and remote repositories for known CVEs.
  • Asset Risk Scoring - Calculates numeric risk scores and severity levels for AI plugins to provide installation recommendations.
  • Vulnerability Dependency Mapping - Implements the process of mapping a plugin's dependency tree against public security databases to identify known vulnerabilities.
  • Static Code Analysis - Performs static analysis of plugin source code using LLMs to detect security risks without executing the code.
  • Fingerprint-Based Suppressions - Employs unique hashes to track and suppress previously accepted security risks across repeated scan cycles.
  • Multi-Source Asset Ingestion - Retrieves target code from local directories, remote URLs, or repositories for unified security processing.
  • File and URL Scans - Inspects files from remote URLs, repositories, and local directories to identify security risks in AI skills.
  • AI Application Security - Security scanner for detecting malicious patterns in AI agent skills.

स्टार हिस्ट्री

nvidia/skillspector के लिए स्टार हिस्ट्री चार्टnvidia/skillspector के लिए स्टार हिस्ट्री चार्ट

AI सर्च

और अधिक बेहतरीन रिपॉजिटरी खोजें

अपनी ज़रूरत को सरल भाषा में बताएं — AI हजारों क्यूरेटेड ओपन-सोर्स प्रोजेक्ट्स को प्रासंगिकता के आधार पर रैंक करता है।

Start searching with AI

SkillSpector के ओपन-सोर्स विकल्प

समान ओपन-सोर्स प्रोजेक्ट्स, जो SkillSpector के साथ साझा की गई सुविधाओं के आधार पर रैंक किए गए हैं।
  • snyk/snyksnyk का अवतार

    snyk/snyk

    5,586GitHub पर देखें↗

    Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source code, open-source dependencies, container images, and infrastructure-as-code configurations. It functions as a comprehensive security workflow automation tool, utilizing a static analysis engine and dependency graph mapping to detect security flaws and license compliance issues throughout the software development lifecycle. The platform distinguishes itself through agentic workflow orchestration and an automated remediation pipeline that generates and submits pull requests to patc

    TypeScript
    GitHub पर देखें↗5,586
  • snyk/clisnyk का अवतार

    snyk/cli

    5,428GitHub पर देखें↗

    The Snyk CLI is a command-line security scanner that detects known vulnerabilities across open-source dependencies, proprietary application code, container images, and infrastructure-as-code configuration files. It also serves as a platform management tool, allowing users to configure organizations, users, SSO, and reporting from the terminal rather than the web dashboard. The CLI integrates directly into development workflows, enabling scanning within IDEs, build pipelines, and version control systems. It implements static analysis with interfile data flow analysis to find complex security f

    TypeScriptmonitorsecuritysnyk
    GitHub पर देखें↗5,428
  • tencent/ai-infra-guardTencent का अवतार

    Tencent/AI-Infra-Guard

    2,971GitHub पर देखें↗

    AI-Infra-Guard is a security scanning platform designed to detect vulnerabilities across large language model deployments, AI agent skills, and the underlying infrastructure. It functions as a security toolset for auditing source code, evaluating model robustness, and identifying insecure network configurations. The project provides a red teaming framework that uses curated attack datasets to test for jailbreak vulnerabilities and prompt injections. It also includes an infrastructure auditor that employs network fingerprinting and asset discovery to match running components against known comm

    Pythonagentagent-scanagentskills
    GitHub पर देखें↗2,971
  • bridgecrewio/checkovbridgecrewio का अवतार

    bridgecrewio/checkov

    8,798GitHub पर देखें↗

    Checkov is a static analysis tool and security scanner designed to identify misconfigurations in infrastructure as code, container images, and Kubernetes configurations. It functions as a cloud security posture tool, an SCA vulnerability scanner, and a secret scanning utility to prevent security breaches and version control leaks. The project distinguishes itself through deep graph analysis and variable resolution, allowing it to map relationships between interconnected resources and evaluate the final state of infrastructure attributes. It provides extensibility for defining custom security

    Python
    GitHub पर देखें↗8,798
SkillSpector के सभी 30 विकल्प देखें→

अक्सर पूछे जाने वाले प्रश्न

nvidia/skillspector क्या करता है?

SkillSpector is a security scanner designed to detect vulnerabilities and malicious patterns in AI agent plugins and extensions before they are installed. It functions as a runtime guardrail that calculates numeric risk scores and assigns severity labels to provide installation recommendations or block risky external extensions.

nvidia/skillspector की मुख्य विशेषताएं क्या हैं?

nvidia/skillspector की मुख्य विशेषताएं हैं: AI Agent Vulnerability Scanners, LLM-Based Analysis, LLM-Powered Semantic Analyzers, Security Intent Analysis, CVE Dependency Scanners, Dependency Vulnerability Scanners, Security Guardrails, AI Agent Scanners।

nvidia/skillspector के कुछ ओपन-सोर्स विकल्प क्या हैं?

nvidia/skillspector के ओपन-सोर्स विकल्पों में शामिल हैं: snyk/snyk — Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source… snyk/cli — The Snyk CLI is a command-line security scanner that detects known vulnerabilities across open-source dependencies,… tencent/ai-infra-guard — AI-Infra-Guard is a security scanning platform designed to detect vulnerabilities across large language model… bridgecrewio/checkov — Checkov is a static analysis tool and security scanner designed to identify misconfigurations in infrastructure as… roave/securityadvisories — SecurityAdvisories is a software composition analysis tool and PHP security advisory database used to audit project… bodadotsh/npm-security-best-practices — This project provides a comprehensive guide for securing the software supply chain within Node.js and npm…