अपडेट पर वापस जाएँ
New releaseAug 5, 2026

SkillSpector v2.5.3

AI एजेंट स्किल्स के लिए सुरक्षा स्कैनर। इन्हें इंस्टॉल करने से पहले Claude Code, Codex और MCP स्किल्स में कमज़ोरियों, दुर्भावनापूर्ण पैटर्न, सुरक्षा जोखिम, प्रॉम्प्ट इंजेक्शन, डेटा एक्सफ़िल्ट्रेशन और सप्लाई-चेन जोखिम का पता लगाएँ।

साझा करें

SkillSpector

AI एजेंट स्किल्स के लिए सुरक्षा स्कैनर। एजेंट स्किल्स इंस्टॉल करने से पहले कमज़ोरियों, दुर्भावनापूर्ण पैटर्न और सुरक्षा जोखिमों का पता लगाएं।

Python 3.12+ License: Apache 2.0

अवलोकन

AI एजेंट स्किल्स (जो Claude Code, Codex CLI, Gemini CLI, आदि द्वारा उपयोग की जाती हैं) अंतर्निहित विश्वास और न्यूनतम जाँच के साथ निष्पादित होती हैं। शोध डेटासेट के 31,132-स्किल विश्लेषित सबसेट में, 26.1% स्किल्स में कमज़ोरियाँ हैं और 5.2% संभावित दुर्भावनापूर्ण इरादा दर्शाती हैं।

SkillSpector आपको इसका उत्तर देने में मदद करता है: "क्या यह स्किल इंस्टॉल करने के लिए सुरक्षित है?"

SkillSpector NVIDIA Verified Skills पाइपलाइन का हिस्सा है, जो प्रकाशन से पहले एजेंट स्किल्स को स्कैन, मूल्यांकन और हस्ताक्षरित करती है। पास होने वाली स्किल्स NVIDIA skills कैटलॉग में प्रकाशित की जाती हैं।

दस्तावेज़ीकरण

विशेषताएँ

  • मल्टी-फॉर्मेट इनपुट: Git रेपो, URL, zip फ़ाइलें, डायरेक्टरी, या एकल फ़ाइलें स्कैन करें
  • 17 श्रेणियों में 71 कमज़ोरी पैटर्न: प्रॉम्प्ट इंजेक्शन, डेटा एक्सफ़िल्ट्रेशन, प्रिविलेज एस्केलेशन, सप्लाई चेन, अत्यधिक एजेंसी, आउटपुट हैंडलिंग, सिस्टम प्रॉम्प्ट लीकेज, मेमोरी पॉइज़निंग, टूल का दुरुपयोग, रोग एजेंट, एंटी-रिफ्यूज़ल, ट्रिगर एब्यूज़, खतरनाक कोड (AST), टेंट ट्रैकिंग, YARA सिग्नेचर, MCP लीस्ट प्रिविलेज, और MCP टूल पॉइज़निंग
  • दो-चरणीय विश्लेषण: तेज़ स्टैटिक विश्लेषण + वैकल्पिक LLM सिमेंटिक मूल्यांकन
  • लाइव कमज़ोरी लुकअप: SC4 वास्तविक समय CVE डेटा के लिए OSV.dev को क्वेरी करता है, स्वचालित ऑफ़लाइन फ़ॉलबैक के साथ
  • एकाधिक आउटपुट फॉर्मेट: टर्मिनल, JSON, Markdown, और SARIF रिपोर्ट
  • जोखिम स्कोरिंग: गंभीरता लेबल और स्पष्ट सिफ़ारिशों के साथ 0-100 स्कोर
  • बेसलाइन / फ़ॉल्स-पॉज़िटिव सप्रेशन: ग्लोब-रूल या फ़िंगरप्रिंट बेसलाइन के माध्यम से ज्ञात फाइंडिंग्स स्वीकार करें ताकि पुनः-स्कैन केवल नई समस्याएँ सामने लाएँ (docs)

त्वरित शुरुआत

इंस्टॉलेशन

ओपन-सोर्स सॉफ़्टवेयर सूचना: यह प्रोजेक्ट अतिरिक्त तृतीय-पक्ष ओपन सोर्स सॉफ़्टवेयर प्रोजेक्ट्स को डाउनलोड और इंस्टॉल करेगा। उपयोग से पहले इन ओपन सोर्स प्रोजेक्ट्स की लाइसेंस शर्तों की समीक्षा करें।

पहले एक वर्चुअल एनवायरनमेंट बनाएं और सक्रिय करें (सभी make टार्गेट मानते हैं कि venv सक्रिय है)। uv या pip का उपयोग करें; Makefile uv का उपयोग करता है यदि उपलब्ध हो, अन्यथा pip।

uv के साथ त्वरित इंस्टॉल (केवल CLI):```bash uv tool install git+https://github.com/NVIDIA/skillspector.git

Update later: uv tool update skillspector

यदि आप `skillspector mcp` चलाने की योजना बना रहे हैं, तो इंस्टॉल के समय MCP extra इंस्टॉल करें:```bash
uv tool install 'skillspector[mcp] @ git+https://github.com/NVIDIA/skillspector.git'

स्रोत से:```bash

Clone the repository

git clone https://github.com/NVIDIA/skillspector.git cd skillspector

Create and activate virtual environment

uv venv .venv && source .venv/bin/activate

or: python3 -m venv .venv && source .venv/bin/activate

Install for production use

make install

Or install with development dependencies

make install-dev

### Docker (Python की आवश्यकता नहीं)

शामिल [Dockerfile](https://github.com/nvidia/skillspector/blob/main/Dockerfile) से इसे स्थानीय रूप से बनाकर Python इंस्टॉल किए बिना SkillSpector चलाएँ। यह इमेज Docker Official Python `3.12-slim-bookworm` इमेज पर आधारित है।

**इमेज बनाएँ:**```bash
make docker-build
# or: docker build -t skillspector .

किसी स्थानीय निर्देशिका को स्कैन करें अपनी वर्तमान निर्देशिका को /scan में माउंट करके, जो कंटेनर की कार्यशील निर्देशिका है:```bash docker run --rm -v "$PWD:/scan" skillspector scan ./my-skill/ --no-llm

**LLM विश्लेषण के साथ स्कैन करें** एक स्थानीय `.env` फ़ाइल के साथ क्रेडेंशियल्स पास करके:```bash
cat > .env <<'EOF'
SKILLSPECTOR_PROVIDER=anthropic
ANTHROPIC_API_KEY=sk-ant-...
EOF

| -s | --server | Server URL (default: http://localhost:8080) | | -t | --token | API token for authentication | | -o | --output | Output file path | | -f | --format | Output format: json, csv, table | | -v | --verbose | Enable verbose output | | -q | --quiet | Suppress non-essential output | | --no-color | | Disable colored output | | --timeout | | Request timeout in seconds (default: 30) |

उदाहरण

# Scan a single target
scanner scan --target example.com

# Scan multiple targets from a file
scanner scan --file targets.txt --output results.json

# Use a custom configuration
scanner scan --config custom-config.yaml --verbose

# Check scan status
scanner status --scan-id abc123

# List all scans
scanner list --format table

कॉन्फ़िगरेशन

The tool reads configuration from ~/.scanner/config.yaml by default. A sample configuration file is provided in the examples/ directory.

# ~/.scanner/config.yaml
server:
  url: "http://localhost:8080"
  timeout: 30

auth:
  token: "your-api-token-here"

scan:
  default_profile: "full"
  max_concurrent: 10
  rate_limit: 100

output:
  format: "json"
  directory: "./results"
  verbose: false

API उपयोग

The scanner exposes a REST API for programmatic access:

# Start a new scan
curl -X POST http://localhost:8080/api/v1/scans \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"target": "example.com", "profile": "full"}'

# Get scan results
curl -X GET http://localhost:8080/api/v1/scans/abc123 \
  -H "Authorization: Bearer $TOKEN"

आर्किटेक्चर

The scanner is built with a modular architecture:

  • Core Engine: Orchestrates scan execution and manages plugins
  • Plugin System: Extensible modules for different scan types
  • API Server: REST API for remote control and integration
  • Storage Layer: Persists scan results and configuration
  • CLI Interface: Command-line interface for direct interaction

योगदान

Contributions are welcome! Please follow these guidelines:

  1. Fork the repository
  2. Create a feature branch (git checkout -b feature/amazing-feature)
  3. Commit your changes (git commit -m 'Add amazing feature')
  4. Push to the branch (git push origin feature/amazing-feature)
  5. Open a Pull Request

Please ensure your code follows the existing style and includes appropriate tests.

लाइसेंस

This project is licensed under the MIT License - see the LICENSE file for details.

आभार

  • ProjectDiscovery for inspiration and tools
  • All contributors who have helped improve this project

संपर्क

श्रेणियाँ