How Skills Directory scans Claude and agent skills
- Prompt injection and instruction hijacking
- Credential theft or secret exfiltration
- Suspicious shell commands and code execution
- Network access and external data transfer
- File-system writes, deletion, or persistence
- Hidden or obfuscated instructions
- Supply-chain and install-time risk signals
- Over-broad permissions or unclear approval gates
How grades work
Each skill starts from a high score. Findings reduce the score based on severity. The final score maps to a letter grade so users can quickly decide what deserves review.
The grade covers SKILL.md. Scripts and other files bundled with a skill are listed on its page but don't count toward the grade. Pro members can scan them line by line, and anyone can scan their own skill.
| Grade | Score | Meaning |
|---|---|---|
| 90-100 | Low risk signals detected; still review before install | |
| 75-89 | Some risk signals; inspect details before using | |
| 60-74 | Meaningful concerns; use only with strong source trust | |
| 40-59 | High concern; avoid unless you understand every issue | |
| 0-39 | Severe risk signals; do not install casually |
What scans can catch
Static scans are good at catching suspicious strings, risky command patterns, secret handling, hidden text, and instructions that ask agents to bypass user intent.
What scans cannot prove
Automated scans cannot guarantee intent, correctness, or future repository changes. Always review source and install only what you trust.
Trust-preserving monetization rule
Sponsors may buy clearly labeled placements, but they cannot buy a security grade, hide findings, or override organic safety signals. The directory is useful only if users can trust that grades mean what they say.
Questions
- Does a Grade A skill mean it is guaranteed safe?
- No. A Grade A result means automated scanning found fewer risk signals. It is a strong starting point, not a guarantee. Users should still review source code and install only skills they trust.
- What does Skills Directory scan for?
- Skills Directory scans each skill's SKILL.md for prompt injection, credential theft, data exfiltration, suspicious network access, unsafe shell execution, hidden or obfuscated instructions, persistence, and other risky patterns.
- Are a skill's scripts and other files scanned?
- The grade covers SKILL.md, the file that tells the agent what to do. Bundled scripts and reference files don't count toward it, because scripts that legitimately run commands would otherwise fail. Pro members can scan every file in a skill and see each finding on its line, and anyone can scan their own skill before publishing.
- Can authors pay for a better grade?
- No. Security grades should be based on scan results and review signals, not paid placement. Sponsorships must stay clearly separated from organic security grades and ranking signals.