Development Approach

Scanned Agent Skills vs Unvetted Skills (2026): Should You Vet Before You Install?

Scanning AI agent skills before install vs installing unvetted skills (2026): Snyk, Mondoo, NVIDIA SkillSpector data — plus why the CVE feed itself is now contaminated.

Reviewed by Michael Kerkhoff, as of

Definition
AI agent skills — the modular, shareable packages of instructions and code that extend what an agent can do — exploded in 2026, with public registries going from under fifty new skills a day to more than five hundred. That convenience came with a supply-chain problem. Security researchers have found malicious payloads, hidden prompt injection, credential theft and overbroad permissions tucked inside skills that look harmless in their description. The question every team now faces is whether to scan and vet each skill before installing it — using tooling like NVIDIA's open-source SkillSpector — or to keep installing skills directly and trust the registry to police itself. This comparison weighs the two approaches across supply-chain risk, setup friction, detection coverage, protection against novel threats, credential safety, ecosystem velocity, operational overhead and compliance, so you can decide how much vetting your agent stack actually needs.
Category
Development Approach
Options
Scanned Agent SkillsUnvetted Agent Skills

Detailed Comparison

A side-by-side analysis of key factors to help you make the right choice.

Scanned Agent Skills vs Unvetted Agent Skills
FactorScanned Agent SkillsUnvetted Agent Skills
Supply-chain risk reductionCatches malicious payloads, trojans and hidden prompt injection before the skill ever runs in your environment WinnerInherits whatever the registry missed — known campaigns have planted hundreds of malicious skills that passed casual curation
Setup speed & frictionAdds a scan step (seconds to minutes per skill) plus a review of flagged findings before installInstall instantly with one command — zero friction, which is exactly why most people skip the checks Winner
Malicious-pattern detection coverageTooling like SkillSpector checks 64 vulnerability patterns across 16 categories: prompt injection, credential theft, suspicious downloads, overbroad permissions WinnerNo systematic detection — relies entirely on a human noticing something off in the SKILL.md or code
Protection against novel / zero-day skillsStrong on known patterns, but researchers have shown scanners can be bypassed by sufficiently obfuscated payloadsCatches nothing proactively — but a careful manual reviewer can occasionally spot a brand-new trick a scanner has no signature for
Credential & secret-theft preventionFlags skills that read environment variables, exfiltrate tokens or reach for credentials they don't need WinnerCredential-stealing skills run with your agent's full access on first invocation, before you notice anything
Access to newest skills & ecosystem velocityScanning lags a registry adding 500+ skills a day; the very newest skills may not be scanned or signed yetImmediate access to anything published the moment it lands, no waiting on vetting pipelines Winner
Operational overhead & costRequires running a scanner in your install flow or CI, maintaining its rules and triaging findingsNo extra tooling, infrastructure or process to maintain — until an incident forces one Winner
Compliance & audit trailProduces a record of what was scanned, what was flagged and what was approved — useful for SOC 2 and client audits WinnerNo artifact proving due diligence; in a regulated or client environment that gap is a liability
Trustworthiness of the vulnerability feed the scanner readsOnly as good as its source — JFrog showed on 30 July 2026 that 54 of 55 CVEs from one GitHub account were AI-fabricated, and NVD plus CISA's ADP had already rated six of them Critical WinnerNo feed at all, so no false confidence either — but also no signal, and every genuine advisory is missed alongside the fabricated ones
Total Score · 1 ties5 / 93 / 9

Key Statistics

Real data from verified industry sources to support your decision.

  • Snyk's ToxicSkills study — billed as the first comprehensive security audit of the agent-skills supply chain — found prompt injection in 36% of audited skills and 1,467 malicious payloads across the ecosystem — Snyk ToxicSkills study (2026)
  • Mondoo's research found that more than one in four (over 25%) publicly available AI agent skills contain security vulnerabilities — Mondoo (2026)
  • NVIDIA SkillSpector is an open-source (Apache-2.0) security scanner that checks AI agent skills before installation for prompt injection, credential theft, supply-chain risk and malicious code, detecting 64 vulnerability patterns across 16 categories — NVIDIA SkillSpector / AI Native Landscape (2026)
  • The ClawHavoc campaign planted 341 malicious skills on a public agent-skill registry, distributing the Atomic macOS Stealer and bypassing curation using week-old GitHub accounts — Termdock (ClawHub incident postmortem) (2026)
  • CVE-2025-53773 showed that hidden prompt injection in pull-request descriptions enabled remote code execution via GitHub Copilot, carrying a critical CVSS score of 9.6 — Cycode (2026)
  • Trail of Bits researchers bypassed a public registry's malicious-skill detector, warning teams not to outsource trust to a scanner alone — evidence that scanning is necessary but not sufficient — Trail of Bits (2026)
  • JFrog Security Research reported on 30 July 2026 that 54 of 55 CVEs published from a single GitHub account were entirely AI-fabricated, including six SQLite advisories rated up to 9.8 Critical that referenced functions absent from the reported version and line numbers beyond the file's length. — JFrog Security Research — Afek Berger (2026)
  • The root cause JFrog names is structural: MITRE's CVE submission form has no identity verification, and NIST's manual NVD analysis — the safety net that used to catch this — has been paused since February 2024, leaving enrichment fragmented across CISA and other ADPs. — JFrog Security Research — Afek Berger (2026)

All statistics come from verified third-party sources. Source, year, and direct link are shown on each metric.

When to Choose Each Option

Clear guidance based on your specific situation and needs.

Our Recommendation

Scanning agent skills before you install them is the clear baseline — the data is not subtle. With Snyk finding prompt injection in 36% of audited skills and 1,467 malicious payloads across the supply chain, and Mondoo reporting that more than one in four public skills carry vulnerabilities, treating every third-party skill as untrusted code is simply table stakes in 2026. A scanner like NVIDIA's open-source SkillSpector — which checks 64 vulnerability patterns across 16 categories before installation — catches the obvious supply-chain traps that an unvetted install walks straight into. But don't mistake a clean scan for safety: Trail of Bits has already bypassed a public registry's malicious-skill detector, so scanning is necessary, not sufficient. The approach Context Studios takes, and the one we'd recommend, is layered: scan every skill before install, run it under least-privilege sandboxing, review its provenance and requested permissions, and never let an agent install skills autonomously. Skipping the scan only makes sense for skills you wrote yourself or that come from a source you fully control. For anything pulled from a public registry, scan first, sandbox always, and trust nothing by default. One update since this page was first written, and it cuts at the layer beneath the scanner. On 30 July 2026 JFrog demonstrated that 54 of 55 CVEs published from a single GitHub account were AI-fabricated — six SQLite advisories rated as high as 9.8 Critical referenced functions that did not exist in the targeted version, cited line numbers past the end of the file, and claimed patches that a diff shows never happened. NVD flagged them critical and CISA's ADP concurred. The cause is structural: MITRE's submission form verifies no identity, and NIST's manual NVD analysis has been paused since February 2024. So the argument for scanning still holds, but the claim it supports is narrower than it looks — a scanner is only as trustworthy as the feed it reads, and that feed is now demonstrably contaminated. Scan, sandbox, least-privilege, and verify any finding that would trigger real work against the upstream project's own advisory page.

Choose Scanned Agent Skills when...
  • You install skills from public registries where you don't control the authors
  • Your agents handle credentials, customer data or anything connected to real money
  • You operate in a regulated or client environment that requires an audit trail
  • You run multi-agent or autonomous workflows where one bad skill can spread fast
Choose Unvetted Agent Skills when...
  • The skill is one you wrote yourself or comes from a source you fully control
  • You're prototyping in a throwaway sandbox with no secrets and no network access to anything sensitive
  • You need a brand-new skill the moment it ships and accept the risk consciously
  • You have other strong controls (strict sandboxing, no credential access) that contain a bad skill anyway

Common questions about this comparison answered.

Frequently Asked Questions

(01)Are AI agent skills really a security risk?
Yes. In 2026, Snyk's ToxicSkills audit found prompt injection in 36% of audited agent skills and 1,467 malicious payloads across the supply chain, while Mondoo reported that more than one in four public skills contain security vulnerabilities. Real campaigns like ClawHavoc planted hundreds of malicious skills on public registries distributing credential-stealing malware. Because a skill can carry hidden instructions, overbroad permissions or executable code that does more than its description admits, treating skills as untrusted third-party code is now standard practice.
(02)What does a tool like NVIDIA SkillSpector actually check?
SkillSpector is an open-source (Apache-2.0) scanner that inspects an agent skill before you install it. It looks for prompt injection, credential theft, suspicious downloads, overbroad permissions and malicious code, covering 64 vulnerability patterns across 16 categories. The point is to answer a simple question — does this skill do more than its description says? — before the skill ever runs with your agent's access.
(03)If I scan every skill, am I safe?
Scanning makes you much safer, but it is not a guarantee. Trail of Bits researchers have already bypassed a public registry's malicious-skill detector with obfuscated payloads, which is why a clean scan should be treated as necessary, not sufficient. The robust approach is layered: scan before install, then run skills under least-privilege sandboxing, review provenance and requested permissions, and avoid letting agents install skills autonomously.
(04)When is it acceptable to install an unvetted skill?
Skipping the scan is reasonable for skills you wrote yourself or that come from a source you fully control, or when you're prototyping in a disposable sandbox with no secrets and no sensitive network access. For anything pulled from a public registry — especially when your agent touches credentials, customer data or money — scan first, sandbox always and trust nothing by default.
(05)If the CVE database itself contains AI-generated junk, is scanning still worth it?
Yes, but calibrate what a clean scan buys you. JFrog's 30 July 2026 analysis found 54 of 55 CVEs from one account fabricated — six SQLite advisories rated as high as 9.8 Critical cited functions that did not exist in the version they targeted, and one cited line numbers past the end of a 2,706-line file. NVD and CISA's ADP had already passed them through. The lesson is not to stop scanning; it is that a scanner inherits the trust level of its feed. Treat severity scores as a prioritisation hint, not a verdict, and confirm anything that would trigger real work against the upstream project's own advisory page.

Need help deciding?

Book a free 30-minute consultation and we'll help you determine the best approach for your specific project.

Free consultation · No obligation · Personal reply