BrowseFull catalogOutcomesSolve a specific problemRolesStack by teamTrustFilter by risk tier
← Back to the Claude Observatory

Skill Security Checker

Skill Security Usable
Works inClaude Code
Usable Reviewed

36% of community skills have security flaws per Snyk audit.

Security audit tool for Claude Code skills with 26 detection categories: prompt injection, data exfiltration, reverse shells, privilege escalation, runtime defense hooks, plugin manifest inspection, and Semgrep validation.

3 starsMIT (commercial OK)FreeQuick setup
Usable rating — This tool is functional but has notable gaps. Review the evaluation notes below before deploying.

36% of community skills have security flaws per Snyk audit. A purpose-built scanner for Claude Code skills addresses the exact gap this observatory exists to fill — evaluating whether skills are safe before deploying them to clients.

Enterprise consultants and IT administrators evaluating community skills before deploying them to client environments — and security teams auditing their own skill development.

Claude Code Claude Cowork Claude Chat

https://www.npmjs.com/package/claude-code-skill-security-che...

By aliksir

How to Get It

Option 1: Claude Desktop App (Code Mode)Click the + button next to the prompt box → PluginsAdd plugin. Search and click Install. Skills work in Claude Code only.
Option 2: Paste into Claude CodeCopy the command below and paste it into your conversation. Claude will install it.
Command
npx claude-code-skill-security-check

Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.

First thing to try

After installing, paste this into Claude:

Help me audit community skills for hidden security risks before installing
Time to functional5 minutesCostFree

Trust Signals Reviewed

Stars3Contributors2Last updated2026-08-06LicenseMIT (OK for commercial use)Weekly downloads29Known CVEsNone foundSources: GitHub Advisory Database + OSV.dev · Scanned 2026-08-16 · scanner v1

Community Pulse Growing

Discussed on Reddit

3 mentions across 1 sources

Reviewer notes

Reviewed review. These are observations, not a security certification.

catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 3 GitHub stars; 1 contributors; last commit 31d ago; license MIT.

2026-04-02: LIMITATION: Extremely early stage (1 star, published March 28, 2026). The 26-category scanner hasn't been community-validated and may have significant false positive/negative rates. Treat as experimental.

Things to check

  • Detection relies on pattern matching and static analysis; it won't catch sophisticated obfuscated attacks or logic-based vulnerabilities that don't match known signatures. False positives are possible depending on rule configuration.

How to evaluate tools before deploying →

Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.

Evaluation

Ease of Use
3/5
Versatility
2/5
Reliability
3/5
Security
3/5
Overall score2.75 / 5.00 UsableEvaluatedJul 2026
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 3 GitHub stars; 1 contributors; last commit 31d ago; license MIT.

Related Outcomes

This tool shows up in these problem-focused recommendations.

← Back to the Claude Observatory

Rolling Claude out in your org? Let's talk.

Start a conversation →