Back to Compare
addyosmani/agent-skills vs NVIDIA/SkillSpector
A side-by-side comparison of pricing, ratings, features, pros and cons.
| Overview | |||
| Description | A curated library of 20+ engineering workflow skills for AI coding assistants. Standardizes the software development lifecycle from requirements through shipping, with 7 built-in commands: /spec, /plan, /build, /test, /ship, etc. Built by Google Gemini team lead Addy Osmani. Compatible with Claude Code, Gemini CLI, Codex, and Cursor. | Open-source security scanner for AI agent skills from NVIDIA. Scans skills (from Git repos, URLs, zip files, or directories) for risky patterns including prompt injection, data exfiltration, privilege escalation, malicious code, supply-chain issues, and MCP tool poisoning. Uses static analysis plus optional LLM-based semantic review and can be used in CI/CD or as an MCP server. | |
| Category | |||
| Developer | addyosmani | NVIDIA | |
| Verified Status | No | No | |
| Last Updated | Sep 2026 | Sep 2026 | |
| Pricing | |||
| Pricing Model | Free | Free | |
| Free Plan | Yes | Yes | |
| Open Source | No | No | |
| Capabilities | |||
| Features | • 24 production-grade engineering skills mapped to 8 lifecycle commands: /spec, /plan, /build, /test, /review, /webperf, /code-simplify, /ship • Skills activate automatically based on context (e.g. API work triggers the API-design skill) • /build auto generates a plan and implements every task in one pass, still test-driven and individually committed • Installs via a CLI supporting 70+ agents, including Claude Code, Cursor, Codex, and GitHub Copilot • Native plugin marketplace install for Claude Code • Individual skills installable one at a time, not just as a full bundle | • Scans AI agent skills for 68 vulnerability patterns across 17 categories (prompt injection, data exfiltration, supply chain, etc.) • Two-stage analysis: fast static analysis plus optional LLM semantic evaluation • Cross-references OSV.dev for real-time CVE data with offline fallback • 0-100 risk score with severity labels and clear recommendations • Scans Git repos, URLs, zip files, directories, or single files • Baseline/suppression system so re-scans surface only new findings • Reports in terminal, JSON, Markdown, or SARIF format | |
| Tags | builtgeminiaddyosmanicuratedagent-skills | nvidiaskillsskillspectorsecurityopen-source | |
| Trust and Engagement | |||
| Review Count | 0 | 0 | |
| Saves | 0 | 0 | |
| Views | 90 | 87 | |
| Quality Score | 62/100 | 62/100 | |
| Website Status | Online | Online | |
| Availability | |||
| Website | github.com | github.com | |
| Social Links | 1 linked | 1 linked | |
| Screenshots | No | No | |
| Reviews | |||
| Pros | • Free to use | • Free to use | |
Who Should Choose Each Tool?
Ready to Try These Tools?
Alternatives to Consider
Frequently Asked Questions
Both tools are closely matched on rating — the better fit depends on your specific needs. See the full feature and pricing comparison above.
You can compare up to 4 tools — use "Add Tool" in the table above.
Disclosure: AlverHub may earn a commission if you sign up for a tool through a link on this page, at no additional cost to you. This never affects which tools we list or how we describe them — our recommendations are based on real, documented data and our published scoring methodology.





