Secure Claude Skills start with security scanning
The threat landscape is real
Recent research shows that agent skills are a growing attack vector.
36%
of skills in the wild have security flaws
Snyk ToxicSkills study341
malicious skills found on ClawHub in a single campaign
Koi Security / ClawHavoc82%
of MCP servers have path traversal exposure
Adversa AI / Astrix91%
of malicious skills combine prompt injection with traditional malware
Snyk ToxicSkills study
Real-world attacks
These aren't theoretical risks. They're documented incidents.
Snyk ToxicSkills study
The largest audit of agent skills to date. Snyk scanned 3,984 skills and found 1,467 with malicious payloads: credential theft, backdoors, data exfiltration. 13.4% had critical issues that simple pattern matching missed.
Read the full reportClawHavoc campaign
A coordinated supply chain attack on ClawHub. 341 malicious skills delivered Atomic macOS Stealer through fake prerequisite instructions. A single actor uploaded 354 packages. Bitdefender found ~20% of all ClawHub packages were malicious.
Read the full reportCato CTRL MedusaLocker
Researchers weaponized a Claude Skill to deploy live ransomware. A hidden helper script ran silently alongside an approved main script: the “consent gap” between what users approve and what actually executes.
Read the full report
How we scan skills
Every skill goes through static analysis with 120 detection patterns across 11 threat categories.
Execution
Network
File system
Obfuscation
Credentials
Persistence
Prompt injection
Data exfiltration
Hidden helpers
Supply chain
Rules are weighted by confidence level. Findings inside markdown code fences receive reduced penalties to minimize false positives.
Scoring and grading
Each skill starts with a score of 100. Points are deducted based on finding severity.
Severity penalties
| Severity | Penalty |
|---|---|
| Critical | -25 points |
| High | -15 points |
| Medium | -8 points |
| Low | -3 points |
| Info | 0 points |
Grade scale
| Grade | Score | Meaning |
|---|---|---|
| 90–100 | No significant issues found | |
| 75–89 | Minor concerns, generally safe | |
| 60–74 | Some issues, review recommended | |
| 40–59 | Significant concerns | |
| 0–39 | Critical security issues detected |
Skills Directory by the numbers
Live data from our security scanning pipeline.
- 592,677
- 570,014
- 96%
- 120
Grade distribution
Questions
- How does Skills Directory scan agent skills for security issues?
- Every skill goes through automated static analysis with 120 detection patterns (36 rules) across 11 threat categories including prompt injection, credential theft, data exfiltration, code execution, network access, file system access, obfuscation, persistence, hidden helpers, and supply chain attacks.
- What is a security grade for agent skills?
- Each skill starts with a score of 100. Points are deducted based on security findings: critical (-25), high (-15), medium (-8), low (-3). The final score maps to a letter grade: A (90-100), B (75-89), C (60-74), D (40-59), F (0-39). By default, only grade-A skills are shown.
- Are agent skills safe to use?
- Research shows 36% of agent skills in the wild have security flaws, including malware, credential theft, and prompt injection. Skills Directory scans every skill before listing it. By default, only grade-A skills (no significant issues) are shown to users.
- What types of malware have been found in agent skills?
- Documented attacks include the ClawHavoc campaign (341 malicious skills delivering Atomic macOS Stealer), the Snyk ToxicSkills study (1,467 skills with malicious payloads out of 3,984 audited), and ransomware deployment via Claude Skills (Cato CTRL MedusaLocker).
- What is the difference between Skills Directory and ClawHub?
- Skills Directory scans every skill with 120 automated detection patterns before listing. Research has found ~20% of ClawHub packages to be malicious. Skills Directory defaults to showing only grade-A skills that pass security analysis.
By default, we only show grade-A skills.