Skill Security Checker
36% of community skills have security flaws per Snyk audit.
Security audit tool for Claude Code skills with 26 detection categories: prompt injection, data exfiltration, reverse shells, privilege escalation, runtime defense hooks, plugin manifest inspection, and Semgrep validation.
- Audit community skills for hidden security risks before installing
- Detect prompt injection and data theft patterns in skill files
- Generate security assessment reports for client skill deployments
36% of community skills have security flaws per Snyk audit. A purpose-built scanner for Claude Code skills addresses the exact gap this observatory exists to fill — evaluating whether skills are safe before deploying them to clients.
Enterprise consultants and IT administrators evaluating community skills before deploying them to client environments — and security teams auditing their own skill development.
https://www.npmjs.com/package/claude-code-skill-security-che...
By aliksir
How to Get It
npx claude-code-skill-security-check
Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.
After installing, paste this into Claude:
Help me audit community skills for hidden security risks before installing
Trust Signals Reviewed
Community Pulse Growing
Discussed on Reddit
- I'm a software engineer with a decade of experience. I vibe code all of my side — Reddit · 1796 pts
- I've used AI to write 100% of my code for 1+ year as an engineer. 13 no-bs lesso — Reddit · 837 pts
- Nobody checks what's inside Claude Code skills before installing them. So I buil — Reddit · 77 pts
3 mentions across 1 sources
Reviewer notes
Reviewed review. These are observations, not a security certification.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 3 GitHub stars; 1 contributors; last commit 31d ago; license MIT.
2026-04-02: LIMITATION: Extremely early stage (1 star, published March 28, 2026). The 26-category scanner hasn't been community-validated and may have significant false positive/negative rates. Treat as experimental.
Things to check
- Detection relies on pattern matching and static analysis; it won't catch sophisticated obfuscated attacks or logic-based vulnerabilities that don't match known signatures. False positives are possible depending on rule configuration.
How to evaluate tools before deploying →
Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.
Evaluation
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 3 GitHub stars; 1 contributors; last commit 31d ago; license MIT.
Related Outcomes
This tool shows up in these problem-focused recommendations.