
SkillSpector v2.5.3
AI एजेंट स्किल्स के लिए सुरक्षा स्कैनर। इन्हें इंस्टॉल करने से पहले Claude Code, Codex और MCP स्किल्स में कमज़ोरियों, दुर्भावनापूर्ण पैटर्न, सुरक्षा जोखिम, प्रॉम्प्ट इंजेक्शन, डेटा एक्सफ़िल्ट्रेशन और सप्लाई-चेन जोखिम का पता लगाएँ।
SkillSpector
AI एजेंट स्किल्स के लिए सुरक्षा स्कैनर। एजेंट स्किल्स इंस्टॉल करने से पहले कमज़ोरियों, दुर्भावनापूर्ण पैटर्न और सुरक्षा जोखिमों का पता लगाएं।
अवलोकन
AI एजेंट स्किल्स (जो Claude Code, Codex CLI, Gemini CLI, आदि द्वारा उपयोग की जाती हैं) अंतर्निहित विश्वास और न्यूनतम जाँच के साथ निष्पादित होती हैं। शोध डेटासेट के 31,132-स्किल विश्लेषित सबसेट में, 26.1% स्किल्स में कमज़ोरियाँ हैं और 5.2% संभावित दुर्भावनापूर्ण इरादा दर्शाती हैं।
SkillSpector आपको इसका उत्तर देने में मदद करता है: "क्या यह स्किल इंस्टॉल करने के लिए सुरक्षित है?"
SkillSpector NVIDIA Verified Skills पाइपलाइन का हिस्सा है, जो प्रकाशन से पहले एजेंट स्किल्स को स्कैन, मूल्यांकन और हस्ताक्षरित करती है। पास होने वाली स्किल्स NVIDIA skills कैटलॉग में प्रकाशित की जाती हैं।
दस्तावेज़ीकरण
- इंस्टॉलेशन से पहले एजेंट स्किल्स स्कैन करें — होस्टेड गाइड: कब स्कैन करें, रिपोर्ट कैसे पढ़ें, और इंस्टॉल को कैसे गेट करें।
- विकास गाइड — आर्किटेक्चर, पैकेज लेआउट, और एनालाइज़र पाइपलाइन को कैसे बढ़ाएं।
- विश्लेषण संसाधन सीमाएँ — फेल-क्लोज़्ड बंडल, पार्सर, नेस्टेड-आर्टिफैक्ट, लेजर, और फाइंडिंग सीलिंग।
- Pi एक्सटेंशन — एजेंट सत्रों के अंदर से स्किल्स स्कैन करने के लिए SkillSpector को Pi टूल के रूप में इंस्टॉल करें।
- OpenCode एक्सटेंशन — एजेंट सत्रों के अंदर से स्किल्स स्कैन करने के लिए SkillSpector को OpenCode टूल और
/skillspectorकमांड के रूप में इंस्टॉल करें।
विशेषताएँ
- मल्टी-फॉर्मेट इनपुट: Git रेपो, URL, zip फ़ाइलें, डायरेक्टरी, या एकल फ़ाइलें स्कैन करें
- 17 श्रेणियों में 71 कमज़ोरी पैटर्न: प्रॉम्प्ट इंजेक्शन, डेटा एक्सफ़िल्ट्रेशन, प्रिविलेज एस्केलेशन, सप्लाई चेन, अत्यधिक एजेंसी, आउटपुट हैंडलिंग, सिस्टम प्रॉम्प्ट लीकेज, मेमोरी पॉइज़निंग, टूल का दुरुपयोग, रोग एजेंट, एंटी-रिफ्यूज़ल, ट्रिगर एब्यूज़, खतरनाक कोड (AST), टेंट ट्रैकिंग, YARA सिग्नेचर, MCP लीस्ट प्रिविलेज, और MCP टूल पॉइज़निंग
- दो-चरणीय विश्लेषण: तेज़ स्टैटिक विश्लेषण + वैकल्पिक LLM सिमेंटिक मूल्यांकन
- लाइव कमज़ोरी लुकअप: SC4 वास्तविक समय CVE डेटा के लिए OSV.dev को क्वेरी करता है, स्वचालित ऑफ़लाइन फ़ॉलबैक के साथ
- एकाधिक आउटपुट फॉर्मेट: टर्मिनल, JSON, Markdown, और SARIF रिपोर्ट
- जोखिम स्कोरिंग: गंभीरता लेबल और स्पष्ट सिफ़ारिशों के साथ 0-100 स्कोर
- बेसलाइन / फ़ॉल्स-पॉज़िटिव सप्रेशन: ग्लोब-रूल या फ़िंगरप्रिंट बेसलाइन के माध्यम से ज्ञात फाइंडिंग्स स्वीकार करें ताकि पुनः-स्कैन केवल नई समस्याएँ सामने लाएँ (docs)
त्वरित शुरुआत
इंस्टॉलेशन
ओपन-सोर्स सॉफ़्टवेयर सूचना: यह प्रोजेक्ट अतिरिक्त तृतीय-पक्ष ओपन सोर्स सॉफ़्टवेयर प्रोजेक्ट्स को डाउनलोड और इंस्टॉल करेगा। उपयोग से पहले इन ओपन सोर्स प्रोजेक्ट्स की लाइसेंस शर्तों की समीक्षा करें।
पहले एक वर्चुअल एनवायरनमेंट बनाएं और सक्रिय करें (सभी make टार्गेट मानते हैं कि venv सक्रिय है)। uv या pip का उपयोग करें; Makefile uv का उपयोग करता है यदि उपलब्ध हो, अन्यथा pip।
uv के साथ त्वरित इंस्टॉल (केवल CLI):```bash uv tool install git+https://github.com/NVIDIA/skillspector.git
Update later: uv tool update skillspector
यदि आप `skillspector mcp` चलाने की योजना बना रहे हैं, तो इंस्टॉल के समय MCP extra इंस्टॉल करें:```bash
uv tool install 'skillspector[mcp] @ git+https://github.com/NVIDIA/skillspector.git'
स्रोत से:```bash
Clone the repository
git clone https://github.com/NVIDIA/skillspector.git cd skillspector
Create and activate virtual environment
uv venv .venv && source .venv/bin/activate
or: python3 -m venv .venv && source .venv/bin/activate
Install for production use
make install
Or install with development dependencies
make install-dev
### Docker (Python की आवश्यकता नहीं)
शामिल [Dockerfile](https://github.com/nvidia/skillspector/blob/main/Dockerfile) से इसे स्थानीय रूप से बनाकर Python इंस्टॉल किए बिना SkillSpector चलाएँ। यह इमेज Docker Official Python `3.12-slim-bookworm` इमेज पर आधारित है।
**इमेज बनाएँ:**```bash
make docker-build
# or: docker build -t skillspector .
किसी स्थानीय निर्देशिका को स्कैन करें अपनी वर्तमान निर्देशिका को /scan में माउंट करके, जो कंटेनर की कार्यशील निर्देशिका है:```bash
docker run --rm -v "$PWD:/scan" skillspector scan ./my-skill/ --no-llm
**LLM विश्लेषण के साथ स्कैन करें** एक स्थानीय `.env` फ़ाइल के साथ क्रेडेंशियल्स पास करके:```bash
cat > .env <<'EOF'
SKILLSPECTOR_PROVIDER=anthropic
ANTHROPIC_API_KEY=sk-ant-...
EOF
| -s | --server | Server URL (default: http://localhost:8080) |
| -t | --token | API token for authentication |
| -o | --output | Output file path |
| -f | --format | Output format: json, csv, table |
| -v | --verbose | Enable verbose output |
| -q | --quiet | Suppress non-essential output |
| --no-color | | Disable colored output |
| --timeout | | Request timeout in seconds (default: 30) |
उदाहरण
# Scan a single target
scanner scan --target example.com
# Scan multiple targets from a file
scanner scan --file targets.txt --output results.json
# Use a custom configuration
scanner scan --config custom-config.yaml --verbose
# Check scan status
scanner status --scan-id abc123
# List all scans
scanner list --format table
कॉन्फ़िगरेशन
The tool reads configuration from ~/.scanner/config.yaml by default. A sample configuration file is provided in the examples/ directory.
# ~/.scanner/config.yaml
server:
url: "http://localhost:8080"
timeout: 30
auth:
token: "your-api-token-here"
scan:
default_profile: "full"
max_concurrent: 10
rate_limit: 100
output:
format: "json"
directory: "./results"
verbose: false
API उपयोग
The scanner exposes a REST API for programmatic access:
# Start a new scan
curl -X POST http://localhost:8080/api/v1/scans \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"target": "example.com", "profile": "full"}'
# Get scan results
curl -X GET http://localhost:8080/api/v1/scans/abc123 \
-H "Authorization: Bearer $TOKEN"
आर्किटेक्चर
The scanner is built with a modular architecture:
- Core Engine: Orchestrates scan execution and manages plugins
- Plugin System: Extensible modules for different scan types
- API Server: REST API for remote control and integration
- Storage Layer: Persists scan results and configuration
- CLI Interface: Command-line interface for direct interaction
योगदान
Contributions are welcome! Please follow these guidelines:
- Fork the repository
- Create a feature branch (
git checkout -b feature/amazing-feature) - Commit your changes (
git commit -m 'Add amazing feature') - Push to the branch (
git push origin feature/amazing-feature) - Open a Pull Request
Please ensure your code follows the existing style and includes appropriate tests.
लाइसेंस
This project is licensed under the MIT License - see the LICENSE file for details.
आभार
- ProjectDiscovery for inspiration and tools
- All contributors who have helped improve this project