Skip to content

Security methodology

How Skills Directory scans Claude and agent skills

Skills can shape agent behavior, suggest commands, and include supporting files. Our methodology is designed to surface risk before a user copies or installs a skill.

How grades work

Each skill starts from a high score. Findings reduce the score based on severity. The final score maps to a letter grade so users can quickly decide what deserves review.

The grade covers SKILL.md. Scripts and other files bundled with a skill are listed on its page but don't count toward the grade. Pro members can scan them line by line, and anyone can scan their own skill.

GradeScoreMeaning
A90-100Low risk signals detected; still review before install
B75-89Some risk signals; inspect details before using
C60-74Meaningful concerns; use only with strong source trust
D40-59High concern; avoid unless you understand every issue
F0-39Severe risk signals; do not install casually

What scans can catch

Static scans are good at catching suspicious strings, risky command patterns, secret handling, hidden text, and instructions that ask agents to bypass user intent.

What scans cannot prove

Automated scans cannot guarantee intent, correctness, or future repository changes. Always review source and install only what you trust.

Trust-preserving monetization rule

Sponsors may buy clearly labeled placements, but they cannot buy a security grade, hide findings, or override organic safety signals. The directory is useful only if users can trust that grades mean what they say.

Questions

Does a Grade A skill mean it is guaranteed safe?
No. A Grade A result means automated scanning found fewer risk signals. It is a strong starting point, not a guarantee. Users should still review source code and install only skills they trust.
What does Skills Directory scan for?
Skills Directory scans each skill's SKILL.md for prompt injection, credential theft, data exfiltration, suspicious network access, unsafe shell execution, hidden or obfuscated instructions, persistence, and other risky patterns.
Are a skill's scripts and other files scanned?
The grade covers SKILL.md, the file that tells the agent what to do. Bundled scripts and reference files don't count toward it, because scripts that legitimately run commands would otherwise fail. Pro members can scan every file in a skill and see each finding on its line, and anyone can scan their own skill before publishing.
Can authors pay for a better grade?
No. Security grades should be based on scan results and review signals, not paid placement. Sponsorships must stay clearly separated from organic security grades and ranking signals.