AI Skills Registry with Security Scanning
A private, scanned catalog of agent skills that runs inside the client’s cloud, so no skill reaches an agent without passing a security gate.
- Industries
- Biotech, Healthcare, Defense
- Author
- Solvren AI Engineering
- Published
- Last updated
Solvren AI is an AI forward deployment company: our engineers embed with the client’s team and build inside the client’s own cloud.
Problem
Agent skills are installable folders of instructions and code. A skill can hide data exfiltration, prompt injection, or permissions far broader than its job needs, and without a review step an agent will load it anyway.
Teams adopting agents need one vetted source for skills, with a security check that runs before any agent installs one and again every time a skill changes.
What we deployed
- A private registry built on the open SKILL.md convention: each skill is a folder with YAML front matter and a Markdown procedure, plus optional scripts and references.
- A JSON catalog that agents and a search UI both query, so engineers can browse approved skills and agents can only resolve skills that passed review.
- A scanning gate in CI that blocks release of any skill with critical or high findings.
- Everything runs in the client’s own cloud account. Skills, scan results, and logs stay there.
How it works
-
1Author submits skill
A SKILL.md folder is pushed to the registry repository.
-
2Scanner runs
SkillSpector static checks, plus optional LLM semantic checks; output as SARIF.
-
3Triage policy decides
Findings mapped to OWASP Agentic Skills Top 10; critical or high blocks release.
-
4Registry publishes
The approved version is added to the JSON catalog.
-
5Agent installs
Agents resolve skills only from the approved catalog.
Scan on submit and on every new version
Every skill is scanned before it is published and again on each new version, using NVIDIA SkillSpector. SkillSpector runs fast static checks by default and can add an LLM semantic pass for issues that need intent comparison, such as a description that does not match what the code does.
Findings as SARIF
Scan results are emitted as SARIF, the standard static-analysis format, so they show up in the same code-scanning views and CI checks the client’s security team already reviews.
Governance mapping
Each finding is mapped to an OWASP Agentic Skills Top 10 category (for example malicious skills, supply chain compromise, over-privileged skills, update drift). The release policy is written against those categories, so auditors read one familiar taxonomy.
Controls
- No skill is installable until it passes the scanning gate.
- Re-scan on every new version, so an approved skill cannot drift into an unapproved one.
- Critical and high findings block release in CI; lower findings go to a human triage queue.
- Registry, scanner, and logs run in the client’s cloud account.
- Scan reports kept as SARIF for audit.
Results
| Measure | Result |
|---|---|
| Skills scanned | Being measured |
| Skills blocked by policy | Being measured |
| Submission to approval | Being measured |
We publish only numbers we measured.
Why it fits regulated teams
Everything runs in the client’s environment, which is the data-sovereignty requirement that biotech, healthcare, defense, legal, and fintech buyers start from.
Related industries: Biotech, Healthcare, Defense
FAQ
What is an AI skills registry?
A skills registry is a private catalog of the instruction-and-code packages (skills) that AI agents can load. It gives a team one approved source, versioning, and a security check before any agent installs a skill.
How are agent skills scanned for security issues?
We scan each skill with NVIDIA SkillSpector before publish and on every new version. It combines static pattern checks with an optional LLM semantic pass, and writes findings as SARIF so they appear in existing code-scanning tools.
Which framework do the release rules follow?
Findings are mapped to the OWASP Agentic Skills Top 10. Critical or high findings block release in CI; everything else goes to human triage.
Does the registry send skills or data outside our cloud?
No. The registry, scanner, and logs are deployed inside your cloud account. If the optional LLM semantic check is used, it calls a model endpoint you have already approved.