AI एजेंट स्किल्स के लिए सुरक्षा स्कैनर। इन्हें इंस्टॉल करने से पहले Claude Code, Codex और MCP स्किल्स में कमजोरियाँ, दुर्भावनापूर्ण पैटर्न, सुरक्षा जोखिम, प्रॉम्प्ट इंजेक्शन, डेटा एक्सफिल्ट्रेशन और सप्लाई-चेन जोखिम का पता लगाएँ।
AI एजेंट स्किल्स के लिए सुरक्षा स्कैनर। एजेंट स्किल्स इंस्टॉल करने से पहले कमज़ोरियों, दुर्भावनापूर्ण पैटर्न और सुरक्षा जोखिमों का पता लगाएं।
AI एजेंट स्किल्स (जो Claude Code, Codex CLI, Gemini CLI, आदि द्वारा उपयोग की जाती हैं) अंतर्निहित विश्वास और न्यूनतम जाँच के साथ निष्पादित होती हैं। शोध डेटासेट के 31,132-स्किल विश्लेषित सबसेट में, 26.1% स्किल्स में कमज़ोरियाँ हैं और 5.2% संभावित दुर्भावनापूर्ण इरादा दर्शाती हैं।
SkillSpector आपको इसका उत्तर देने में मदद करता है: "क्या यह स्किल इंस्टॉल करने के लिए सुरक्षित है?"
SkillSpector NVIDIA Verified Skills पाइपलाइन का हिस्सा है, जो प्रकाशन से पहले एजेंट स्किल्स को स्कैन, मूल्यांकन और हस्ताक्षरित करती है। पास होने वाली स्किल्स NVIDIA skills कैटलॉग में प्रकाशित की जाती हैं।
/skillspector कमांड के रूप में इंस्टॉल करें।ओपन-सोर्स सॉफ़्टवेयर सूचना: यह प्रोजेक्ट अतिरिक्त तृतीय-पक्ष ओपन सोर्स सॉफ़्टवेयर प्रोजेक्ट्स को डाउनलोड और इंस्टॉल करेगा। उपयोग से पहले इन ओपन सोर्स प्रोजेक्ट्स की लाइसेंस शर्तों की समीक्षा करें।
पहले एक वर्चुअल एनवायरनमेंट बनाएं और सक्रिय करें (सभी make टार्गेट मानते हैं कि venv सक्रिय है)। uv या pip का उपयोग करें; Makefile uv का उपयोग करता है यदि उपलब्ध हो, अन्यथा pip।
uv के साथ त्वरित इंस्टॉल (केवल CLI):```bash uv tool install git+https://github.com/NVIDIA/skillspector.git
यदि आप `skillspector mcp` चलाने की योजना बना रहे हैं, तो इंस्टॉल के समय MCP extra इंस्टॉल करें:```bash
uv tool install 'skillspector[mcp] @ git+https://github.com/NVIDIA/skillspector.git'
स्रोत से:```bash
git clone https://github.com/NVIDIA/skillspector.git cd skillspector
uv venv .venv && source .venv/bin/activate
make install
make install-dev
### Docker (Python की आवश्यकता नहीं)
शामिल [Dockerfile](https://github.com/nvidia/skillspector/blob/main/Dockerfile) से इसे स्थानीय रूप से बनाकर Python इंस्टॉल किए बिना SkillSpector चलाएँ। यह इमेज Docker Official Python `3.12-slim-bookworm` इमेज पर आधारित है।
**इमेज बनाएँ:**```bash
make docker-build
# or: docker build -t skillspector .
किसी स्थानीय निर्देशिका को स्कैन करें अपनी वर्तमान निर्देशिका को /scan में माउंट करके, जो कंटेनर की कार्यशील निर्देशिका है:```bash
docker run --rm -v "$PWD:/scan" skillspector scan ./my-skill/ --no-llm
**LLM विश्लेषण के साथ स्कैन करें** एक स्थानीय `.env` फ़ाइल के साथ क्रेडेंशियल्स पास करके:```bash
cat > .env <<'EOF'
SKILLSPECTOR_PROVIDER=anthropic
ANTHROPIC_API_KEY=sk-ant-...
EOF
| -s | --server | Server URL (default: http://localhost:8080) |
| -t | --token | API token for authentication |
| -o | --output | Output file path |
| -f | --format | Output format: json, csv, table |
| -v | --verbose | Enable verbose output |
| -q | --quiet | Suppress non-essential output |
| --no-color | | Disable colored output |
| --timeout | | Request timeout in seconds (default: 30) |
# Scan a single target
scanner scan --target example.com
# Scan multiple targets from a file
scanner scan --file targets.txt --output results.json
# Use a custom configuration
scanner scan --config custom-config.yaml --verbose
# Check scan status
scanner status --scan-id abc123
# List all scans
scanner list --format table
The tool reads configuration from ~/.scanner/config.yaml by default. A sample configuration file is provided in the examples/ directory.
# ~/.scanner/config.yaml
server:
url: "http://localhost:8080"
timeout: 30
auth:
token: "your-api-token-here"
scan:
default_profile: "full"
max_concurrent: 10
rate_limit: 100
output:
format: "json"
directory: "./results"
verbose: false
The scanner exposes a REST API for programmatic access:
# Start a new scan
curl -X POST http://localhost:8080/api/v1/scans \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"target": "example.com", "profile": "full"}'
# Get scan results
curl -X GET http://localhost:8080/api/v1/scans/abc123 \
-H "Authorization: Bearer $TOKEN"
The scanner is built with a modular architecture:
Contributions are welcome! Please follow these guidelines:
git checkout -b feature/amazing-feature)git commit -m 'Add amazing feature')git push origin feature/amazing-feature)Please ensure your code follows the existing style and includes appropriate tests.
This project is licensed under the MIT License - see the LICENSE file for details.