Get the Safe-Skill Checklist
AI agent skills for Claude Code, Codex and the Gemini CLI run with full trust — they can read your files, run your shell, and reach the internet, with no app store and no review. NVIDIA's research found 26.1% are vulnerable and 5.2% are likely malicious. This one-page field guide is the 30-second habit that catches a poisoned skill before it ever touches your agent, powered by NVIDIA's free, open-source SkillSpector. Inside: the 3 install rules, the exact scan commands (plus Docker, no Python needed), the 8 red flags to spot by eye in any SKILL.md or script, the 16 threat categories SkillSpector checks, and how to wire it into CI so an unsafe skill fails the build. Full credit to NVIDIA's security team for building and open-sourcing SkillSpector.
Free. No spam. Unsubscribe anytime.