-
Notifications
You must be signed in to change notification settings - Fork 460
Pull requests: NVIDIA/SkillSpector
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
feat(analyzer): detect skills snooping on the agent ecosystem (other skills, MCP config, agent memory)
#77
opened Jun 15, 2026 by
CharmingGroot
Loading…
feat: implement dynamic analyzer discovery and risk score validation
#74
opened Jun 15, 2026 by
umran666
Loading…
Add pre-commit hook, GitHub Actions workflow, and community templates
#73
opened Jun 15, 2026 by
ckdash-git
Loading…
2 of 5 tasks
fix(analyzer): parse structured output from text so OpenAI-compatible endpoints don't crash LLM analysis
#71
opened Jun 15, 2026 by
bmd1905
Loading…
fix(meta-analyzer): keep LLM-confirmed findings when model returns end_line
#70
opened Jun 15, 2026 by
JiayingHuang
Loading…
feat(analyzer): detect anti-refusal statements (jailbreak preamble)
#65
opened Jun 15, 2026 by
ankushchadha
Loading…
feat(analyzer): detect SSRF (cloud metadata / internal-network / dynamic-host requests)
#63
opened Jun 15, 2026 by
CharmingGroot
Loading…
security(meta_analyzer): preserve high-severity static findings from LLM suppression
#54
opened Jun 14, 2026 by
AbhiramDwivedi
Loading…
ci: add GitHub Actions workflow (lint, unit tests, DCO)
#53
opened Jun 14, 2026 by
AbhiramDwivedi
Loading…
feat(providers): add claude_cli and codex_cli agent-CLI providers
#52
opened Jun 14, 2026 by
AbhiramDwivedi
Loading…
docs: document the integration contract and trust model
#51
opened Jun 14, 2026 by
AbhiramDwivedi
Loading…
docs: correct stale analyzer status and dangling references
#50
opened Jun 14, 2026 by
AbhiramDwivedi
Loading…
fix: ignore structural markdown comments in static engine
#49
opened Jun 14, 2026 by
Rachitrajvaishkiyar
Loading…
Trojan Source (CVE-2021-42574) bidirectional control characters in file contents were undetected
#40
opened Jun 13, 2026 by
asadbekXodjayev
Loading…
feat(mcp): expose SkillSpector as an MCP server with a scan_skill tool
#36
opened Jun 13, 2026 by
CharmingGroot
Loading…
fix(llm): isolate Stage 2 batch failures and keep unanalysed findings
#32
opened Jun 12, 2026 by
nyxst4ck
Loading…
Fix(llm): retry transient failures and make concurrency configurable
#29
opened Jun 12, 2026 by
jhamze7
Loading…
fix(supply-chain): exclude pyproject metadata keys from dependency extraction
#28
opened Jun 12, 2026 by
CharmingGroot
Loading…
fix(mcp): treat allowed-tools as a permission declaration for LP3
#27
opened Jun 12, 2026 by
CharmingGroot
Loading…
Detect whitespace padding used to hide prompt-injection instructions (P9)
#24
opened Jun 11, 2026 by
korjavin
Loading…
Previous Next
ProTip!
Follow long discussions with comments:>50.