Skip to content

Security

Secure Claude Skills start with security scanning

Skills Directory runs automated security analysis on Claude skills and agent skills before discovery. We scan for prompt injection, credential theft, data exfiltration, unsafe commands, malware, and more.

The threat landscape is real

Recent research shows that agent skills are a growing attack vector.

Real-world attacks

These aren't theoretical risks. They're documented incidents.

  • Snyk ToxicSkills study

    February 2026

    The largest audit of agent skills to date. Snyk scanned 3,984 skills and found 1,467 with malicious payloads: credential theft, backdoors, data exfiltration. 13.4% had critical issues that simple pattern matching missed.

    Read the full report
  • ClawHavoc campaign

    January 2026

    A coordinated supply chain attack on ClawHub. 341 malicious skills delivered Atomic macOS Stealer through fake prerequisite instructions. A single actor uploaded 354 packages. Bitdefender found ~20% of all ClawHub packages were malicious.

    Read the full report
  • Cato CTRL MedusaLocker

    December 2025

    Researchers weaponized a Claude Skill to deploy live ransomware. A hidden helper script ran silently alongside an approved main script: the “consent gap” between what users approve and what actually executes.

    Read the full report

How we scan skills

Every skill goes through static analysis with 120 detection patterns across 11 threat categories.

  • Execution

    eval(), child_process, shell pipes, dynamic code execution

  • Network

    Hardcoded IPs, HTTP requests, WebSocket, DNS lookups

  • File system

    Path traversal, sensitive directories, destructive operations

  • Obfuscation

    Base64 encoding, character codes, hex-encoded strings

  • Credentials

    SSH keys, API key patterns, keychain access, env harvesting

  • Persistence

    Cron jobs, startup scripts, systemctl, launchctl

  • Prompt injection

    Instruction override, developer mode, system impersonation, unicode smuggling

  • Data exfiltration

    Credential exfil via curl, environment variables sent to URLs

  • Hidden helpers

    External code downloads, password-protected archives, file encryption

  • Supply chain

    Remote exec pipes, runtime npm install, postinstall hooks

Rules are weighted by confidence level. Findings inside markdown code fences receive reduced penalties to minimize false positives.

Scoring and grading

Each skill starts with a score of 100. Points are deducted based on finding severity.

Severity penalties

SeverityPenalty
Critical-25 points
High-15 points
Medium-8 points
Low-3 points
Info0 points

Low-confidence findings receive a 50% penalty reduction.

Grade scale

GradeScoreMeaning
A90–100No significant issues found
B75–89Minor concerns, generally safe
C60–74Some issues, review recommended
D40–59Significant concerns
F0–39Critical security issues detected

Skills Directory by the numbers

Live data from our security scanning pipeline.

Skills scanned
592,677
Grade A skills
570,014
Pass rate (A)
96%
Detection patterns
120

Grade distribution

  • A570,014 (96%)
  • B14,482 (2%)
  • C5,017 (1%)
  • D1,951 (0%)
  • F1,213 (0%)

Questions

How does Skills Directory scan agent skills for security issues?
Every skill goes through automated static analysis with 120 detection patterns (36 rules) across 11 threat categories including prompt injection, credential theft, data exfiltration, code execution, network access, file system access, obfuscation, persistence, hidden helpers, and supply chain attacks.
What is a security grade for agent skills?
Each skill starts with a score of 100. Points are deducted based on security findings: critical (-25), high (-15), medium (-8), low (-3). The final score maps to a letter grade: A (90-100), B (75-89), C (60-74), D (40-59), F (0-39). By default, only grade-A skills are shown.
Are agent skills safe to use?
Research shows 36% of agent skills in the wild have security flaws, including malware, credential theft, and prompt injection. Skills Directory scans every skill before listing it. By default, only grade-A skills (no significant issues) are shown to users.
What types of malware have been found in agent skills?
Documented attacks include the ClawHavoc campaign (341 malicious skills delivering Atomic macOS Stealer), the Snyk ToxicSkills study (1,467 skills with malicious payloads out of 3,984 audited), and ransomware deployment via Claude Skills (Cato CTRL MedusaLocker).
What is the difference between Skills Directory and ClawHub?
Skills Directory scans every skill with 120 automated detection patterns before listing. Research has found ~20% of ClawHub packages to be malicious. Skills Directory defaults to showing only grade-A skills that pass security analysis.

By default, we only show grade-A skills.