Scanners-Box 每日 AI 工具推荐 Scanners-Box Daily AI Tool Picks
Agent Skills 安全审计 Security Auditing for Agent Skills
共 1 个工具 · 专栏每天 14:00(北京)更新一期 1 tools · one new issue daily at 14:00 GMT+8
回答「这个 skill 装了安全吗」:71 个漏洞模式 × 17 类别,静态 + 可选 LLM 语义两阶段,SARIF 直接进 CI Answers "is this skill safe to install?": 71 vulnerability patterns across 17 categories, static plus optional LLM semantic analysis, SARIF straight into CI
背后那条研究数据是重点:分析的 31,132 个 skill 里 26.1% 含漏洞、5.2% 疑似恶意。短板:静态规则对语义级后门覆盖有限、LLM 阶段引入成本与不确定性、生态绑定 NVIDIA 工具链。
The research behind it is the point: of 31,132 skills analyzed, 26.1% contain vulnerabilities and 5.2% show likely malicious intent. Caveats: static rules cover semantic-level backdoors only so far, the LLM stage adds cost and nondeterminism, and the tooling ties into the NVIDIA ecosystem.
https://github.com/NVIDIA/SkillSpector