When you download or install a skill — a set of instructions that tells your AI agent how to behave and what tools to use — you are adding instructions that run inside your AI system, with access to everything that system can access. Your files. Your credentials. Your conversations. Your organisation's data.
According to NVIDIA's research across 42,447 real-world skills, 26.1% contain vulnerabilities and 5.2% show likely malicious intent.
One in four is broken. One in twenty is actively trying to cause harm.
What a malicious skill can do
A skill is a set of natural-language instructions. The AI reads them and follows them. Vulnerability patterns include prompt injection, data exfiltration, privilege escalation, supply-chain attacks, memory poisoning, rogue self-modifying agents, and MCP tool poisoning.
In plain language: a skill can be written to steal credentials, persist instructions across conversations, override safety constraints, or modify its behaviour at runtime in ways you never authorised.
The tool: NVIDIA SkillSpector
NVIDIA SkillSpector is an open-source security scanner for AI agent skills. It detects vulnerabilities, malicious patterns, and security risks before installation in Claude Code, Codex CLI, Gemini CLI, or other agent platforms. It uses static analysis, YARA signatures, CVE lookups, and optional LLM evaluation, with terminal, JSON, Markdown, and SARIF output.
It scans 65 vulnerability patterns across 16 categories. Pattern-only checks run in seconds with the --no-llm flag.
Why this belongs in any article about skill safety
A skill with good values, installed alongside a malicious skill, is compromised. Memory poisoning can corrupt the context that a well-built skill is operating in. Security is not separate from quality. It is a precondition for it.
The practical habit
Before installing any third-party skill, scan it. SkillSpector is free, open-source, runs locally, and takes seconds. If you build skills, scan your own skills before sharing them. Vulnerabilities can be unintentional.
You would not install unknown software on a work machine without checking it first. A skill is software. It runs inside your AI system, with your access, on your data. Check it first.
This is part of the Parenting Your AI series, a practitioner's guide to building AI skills that are safe, effective, and worth trusting. Written from inside enterprise AI systems by someone who has spent years diagnosing what goes wrong when AI meets real work at scale.
Read the full series at KnowledgeManagement.ie