releases.shpreview

SkillSpector scans AI agent configs for security risks

1 featureThis release1 featureNew capabilitiesAI-tallied from the release notes

SkillSpector

CodeRabbit now runs Nvidia's SkillSpector to detect security risks in AI agent skills and MCP configuration files during pull request reviews. CodeRabbit runs SkillSpector against changed files including SKILL.md, mcp.json, mcp-config.json, claude_desktop_config.json, .cursorrules, and codex.yaml.

SkillSpector is enabled by default. To disable it, set reviews.tools.skillspector.enabled: false in your .coderabbit.yaml or from Reviews → Tools → SkillSpector in the settings page.

See the SkillSpector tool guide for details.

Fetched June 16, 2026