Skip to main content
SkillSpector is a security scanner for AI agent skills and MCP configuration files. CodeRabbit runs SkillSpector version 2.9.5 to detect vulnerabilities, malicious patterns, and security risks in changed agent configuration files.

Files

SkillSpector will run on changed files with the following names:
  • SKILL.md
  • mcp.json
  • mcp-config.json
  • claude_desktop_config.json
  • .cursorrules
  • codex.yaml

Configuration

SkillSpector is enabled by default.

Security policy and restrictions

CodeRabbit runs SkillSpector inside the sandbox with LLM analysis disabled. It uses static analysis and does not make LLM or network calls. When multiple supported files change in the same directory, CodeRabbit may scan that directory once and attribute findings only to changed files.

When we skip SkillSpector

CodeRabbit will skip running SkillSpector when:
  • SkillSpector is disabled in CodeRabbit settings or .coderabbit.yaml.
  • No changed files match the supported file names.
  • A candidate path is absolute or contains .., |, a newline, or a null byte.

Profile behavior

SkillSpector uses the same rules in Chill and Assertive modes.

What’s next

Tool catalog

Browse all linters, security analyzers, and CI/CD integrations by category and technology.

Tools reference

Explore detailed specifications and configuration options for CodeRabbit tools.