Metal Mantra / AGENT INTELLIGENCEPublic evidence reportAUTOMATED SIGNAL. NOT CERTIFICATION.
PUBLIC REPORT / AGENT SIGNAL v0.2

skillspector.

Scanned repository says: Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, and security risks before installing agent skills.

Inspect GitHub source

19.8k starsApache-2.0pushed today

0community interest

Votes show community interest, not safety. They never change this score.

AUTOMATED SIGNAL77/100BBBNot security certification
START HERE

Critical findings need attention.

Critical finding · details withheld for 30 days

Inspect the findings
WHAT THIS DOES NOT ESTABLISH

Runtime safety, real-world agent capability, fitness for your use case or independent certification.

Scan scope80 / 124Partial eligible-file selection · not the entire repository
Recorded findings7Heuristic matches requiring human review
SnapshotOct 9, 2026UTC · engine 0.2.0
DNS at scan timeUnverifiedDomain control is not security certification
01 / KNOW THE REPOSITORY

What the source
actually tells us.

Structured, cited information from the scanned archive. Repository-authored claims are labeled and never treated as verified capabilities.

INSPECTED SOURCE80 / 124Partial selection
READMEReadRepository-authored information
MANIFESTS3LICENSE, package.json, pyproject.toml

Who it is for

  • Stated purpose · repository says · unreviewed

    Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, and security risks before installing agent skills.

    README.md:3
  • Stated purpose · repository says · unreviewed

    License: Apache 2.0

    README.md:6
  • Stated purpose · repository says · unreviewed

    SkillSpector helps you answer: "Is this skill safe to install?"

    README.md:12

What it can do

  • Stated capability · repository says · unreviewed

    Multi-format input: Scan Git repos, URLs, zip files, directories, or single files

    README.md:26
  • Stated capability · repository says · unreviewed

    Two-stage analysis: Fast static analysis + optional LLM semantic evaluation

    README.md:28
  • Stated capability · repository says · unreviewed

    Live vulnerability lookups: SC4 queries OSV.dev for real-time CVE data with automatic offline fallback

    README.md:29

What adoption takes

  • Stated deployment · repository says · unreviewed

    Open-source software notice: This project will download and install additional third-party open source software projects. Review the license terms of these open source projects before use.

    README.md:38
  • Stated prerequisite · manifest declares · unreviewed

    Manifest declares Python >=3.12,<3.15 as a requirement.

    pyproject.toml:11
  • Declared dependency · manifest declares · unreviewed

    Declares a dependency on typer.

    pyproject.toml:34
  • Stated deployment · repository says · unreviewed

    All make targets assume a virtual environment is already created and activated. The Makefile uses uv if available, else pip.

    README.md:883
  • Declared dependency · manifest declares · unreviewed

    Declares a dependency on rich.

    pyproject.toml:35
  • Declared dependency · manifest declares · unreviewed

    Declares a dependency on httpx.

    pyproject.toml:36
  • Declared dependency · manifest declares · unreviewed

    Declares a dependency on pywhatwgurl.

    pyproject.toml:37
  • Declared dependency · manifest declares · unreviewed

    Declares a dependency on regex.

    pyproject.toml:38
  • Declared dependency · manifest declares · unreviewed

    Declares a dependency on packaging.

    pyproject.toml:39

Limits and terms

  • Stated limitation · repository says · unreviewed

    Non-English content: May miss patterns in other languages

    README.md:959
  • Declared license · manifest declares · unreviewed

    A license or copying file is present; its terms have not been reviewed.

    LICENSE:1
  • Stated limitation · repository says · unreviewed

    Image-based attacks: Cannot analyze text in images

    README.md:960
  • Stated limitation · repository says · unreviewed

    Encrypted/binary code: Cannot analyze compiled or encrypted content

    README.md:961

Observed technical context

Python · 80 selected filesAgent orchestration reference · static onlyTool-calling reference · static only

These are references in selected source files, not proof that a feature works at runtime.

Observed in the scanned archive at Oct 9, 2026, 8:20 AM UTC. Archive digest sha256:cf5dff912b7b43a0…. Source links open current GitHub HEAD and may differ from the scan. Repository statements are unreviewed and do not affect the score.

02 / FINDINGS FIRST

What needs
a closer look.

Critical details are withheld publicly for the first 30 days after a scan. A matched pattern is a lead for investigation, not a confirmed vulnerability.

7 findings
CRITICAL

Critical finding · details withheld for 30 days

SEC002 · Security & privacy

Details are withheld from public view for 30 days after the scan. The owner can see them in full.

SUGGESTED ACTION

Review the private assessment and address the finding.

[location embargoed] · location unavailable
CRITICAL

Critical finding · details withheld for 30 days

SEC002 · Security & privacy

Details are withheld from public view for 30 days after the scan. The owner can see them in full.

SUGGESTED ACTION

Review the private assessment and address the finding.

[location embargoed] · location unavailable
MAJOR

Domain ownership not verified

TRUST001 · Entity trust

Metal Mantra could not confirm that the owner controls the stated domain. The domain may belong to someone else.

SUGGESTED ACTION

Verify the domain using the Metal Mantra DNS TXT challenge.

nvidia.com · location unavailable
MINOR

Raw model text returned

SCH002 · Schema & tooling

The code returns the model's raw text. Output that was never parsed or validated can pass mistakes straight to users or other systems.

SUGGESTED ACTION

Parse and validate the result before returning it.

skillspector/llm_utils.py:695
MINOR

Raw model text returned

SCH002 · Schema & tooling

The code returns the model's raw text. Output that was never parsed or validated can pass mistakes straight to users or other systems.

SUGGESTED ACTION

Parse and validate the result before returning it.

skillspector/llm_utils.py:696
MINOR

Privacy Policy link not confirmed

TRUST003 · Entity trust

No privacy policy link was found on the stated homepage. Buyers cannot see how the vendor handles their data.

SUGGESTED ACTION

Expose a clear Privacy Policy link on the official homepage.

nvidia.com · location unavailable
MINOR

Terms link not confirmed

TRUST004 · Entity trust

No terms link was found on the stated homepage. Buyers cannot see the conditions that apply to using the service.

SUGGESTED ACTION

Expose a clear Terms link on the official homepage.

nvidia.com · location unavailable
03 / EVIDENCE & LIMITS

The boundary
is part of the result.

What was scanned
80 of 124 eligible files · Partial selection.
Supported static source patterns and domain checks; no runtime execution.
What remains unknown
Unscanned files, external dependencies, production configuration, actual agent behavior and evidence beyond the configured checks.
Source location
Links open the current repository HEAD. Source may have changed since this snapshot.
Something looks wrong?
Tell us if a finding, scope or claim on this report needs a correction. Report a problem with this report
Entity trust · 15% of v0.2
Includes DNS ownership, HTTPS and policy evidence. Verification is domain control, not a security certificate.
DNS: unverifiedHTTPS: availablePrivacy: not confirmedTerms: not confirmed
04 / THE METHOD BEHIND THE NUMBER

Open the
calculation.

Each pillar starts at 100. Rule deductions reduce its score; weights determine the overall contribution.

01

Security & privacy

2 findings · 25% weight
64/10016.0 pts
02

Guardrails & loop control

0 findings · 25% weight
100/10025.0 pts
03

Schema & tooling

2 findings · 20% weight
84/10016.8 pts
04

Token & cost efficiency

0 findings · 15% weight
100/10015.0 pts
05

Entity trust

3 findings · 15% weight
25/1003.8 pts
Inspect the current standard
USER REPORTS

Did skillspector work for people?

No user reports yet.

Each report is one signed-in GitHub account saying what happened. We do not verify that the account ran the agent, and reports never change the automated score or grade. For a security problem, use the disclosure page instead of a public note.

Sign in with GitHub to add a report

SHARE THE EVIDENCE

A signal.
Not a seal.

Share the full report so its scope and limits travel with the score.

Metal Mantra automated signal 77/100, not certified