Your Agent Is Quietly Wrecking Things
A coding agent will happily install a skill you've never read, announce "done" on a feature that returns a 500, pad every answer with filler, build a UI that looks like every other AI app, and wave through code it should have rejected. None of that is malicious. It just has no guardrails. Five free repos add them.
Scan Before You Install β SkillSpector
NVIDIA's security scanner for agent skills. Point it at a skill folder, a SKILL.md, a GitHub URL or a zip before installing, and it flags credential access, prompt injection, data exfiltration and dangerous or obfuscated code β the things that turn a helpful skill into a way to lose your SSH keys.
Prove It Works β Reticle
When the agent says it's finished, Reticle opens your real running app, tests it, and catches the failures the UI was hiding β live 500s, broken flows β then hands the agent the exact fix. Works with Claude Code, Cursor and any MCP agent.
Trim the Fluff β Chisle
Stops the agent rambling and building things nobody asked for: YAGNI-first code, terse replies, trimmed tool output. The project documents one change dropping from roughly 1,500 tokens to about 600 β its own test, so treat it as indicative.
Give It Taste β UI Skills
The playbook design engineers actually use, packaged as skills: spacing and rhythm, motion and easing, accessibility. So the app stops looking generically AI-built.
Reject the Slop β Anti-Slop
Rules that automatically reject the lazy patterns AI produces β generic UI, filler copy, throwaway comments β before they land in your codebase.
One Sensible Habit
SkillSpector is NVIDIA's; the other four are community open-source projects. The guide's own advice is the right one: run the other four through SkillSpector before you install them.
What's in the Guide
What each repo does, where it fits in the loop, and links to all five.
The full field guide is in the PDF.
Get the Guide
Drop your email below and we'll send it straight to your inbox.